Third-Party Risk

Third-Party Risk Management: How to Assess Vendors Properly

A practical guide to third-party risk management: tiering vendors, security questionnaires, evidence, scoring, contracts, monitoring and AI questions.

Muhammad Anwar
· 4 min read

Third-party risk management has moved from a procurement formality to one of the most scrutinised parts of a security program. Many of the largest breaches of recent years started with a supplier: a software update, a managed service provider, a cloud platform or a contractor with too much access. Regulators have noticed. The SOCI Act’s risk management program rules, APRA’s CPS 230 and the ISM all expect organisations to understand and manage the risks their suppliers introduce.

This guide sets out a practical, proportionate approach to assessing vendors, built on how I run supplier assessments.

Why vendor risk is now your risk

When you outsource a service, you keep the accountability. If a supplier holding your customers’ data is breached, the headlines, regulator questions and notification obligations land on you. Third parties also widen your attack surface: every vendor with network access, privileged credentials or a software update channel into your environment is a potential way in.

The answer is not to assess every supplier in depth. That is impossible for most organisations. The answer is to assess in proportion to risk.

Step 1: Build and tier your supplier inventory

You cannot manage what you have not listed. Start with an inventory of suppliers that store, process or access your data, connect to your network, or deliver services your operations depend on. Then tier them by inherent risk, using two simple ratings:

  • Service criticality: how badly would you be affected if the service failed?
  • Data sensitivity: what is the most sensitive data the supplier can access?

Multiplying the two on a 1 to 4 scale gives a score from 1 to 16 and four tiers:

TierInherent riskTypical assurance
Tier 1CriticalFull questionnaire, evidence review, annual reassessment
Tier 2HighFull questionnaire, reassessment every 1 to 2 years
Tier 3ModerateShort questionnaire or certification check
Tier 4LowContract terms and periodic review

Step 2: Ask the right questions

A good vendor security questionnaire covers governance, certifications, risk management, people security, identity and access, data protection, encryption, vulnerability management, logging, incident response, business continuity, secure development, cloud hosting, sub-processors, physical security and regulatory obligations.

Two areas are missing from most questionnaires and should not be:

  • Sub-processors (fourth parties): who else touches your data, and where?
  • AI: does the service use AI, is your data used to train models, can AI features be switched off, and does the supplier govern AI under a framework such as ISO/IEC 42001? I cover this in detail in AI supply chain risk.

Step 3: Weight and score answers consistently

Not every question matters equally. Weight questions from 1 (low) to 3 (critical), so that a missing multifactor authentication control counts for far more than an out-of-date policy review. A simple, defensible scoring model:

  • Yes scores twice the weight
  • Partial scores the weight
  • No scores zero
  • N/A is excluded from the maximum

Any “No” on a weight-3 question should be flagged as a critical gap, whatever the overall score.

Step 4: Verify evidence, not just answers

Questionnaire answers are claims. For higher tiers, ask for evidence: an ISO 27001 certificate and its scope, a SOC 2 Type II report, penetration test summaries, policy extracts, or screenshots of key configurations. Check that certificates are current and that their scope actually covers the service you are buying. A certificate for a different business unit or data centre is worth very little.

Step 5: Decide, contract and remediate

Turn the assessment into a clear recommendation:

  • Approve: risk is within appetite; monitor according to tier
  • Approve with conditions: a remediation plan with dates is required
  • Escalate: do not onboard without formal risk acceptance by an accountable executive

Then put the important commitments into the contract: security requirements, breach notification timeframes, audit rights, data location, sub-processor approval and secure return or destruction of data at exit.

Step 6: Monitor continuously

A point-in-time assessment goes stale quickly. Reassess on a cadence that matches the tier, and also whenever:

  • the service, data shared or supplier ownership changes
  • the supplier has a breach or a significant incident
  • threat intelligence shows the supplier or its products being targeted

Track remediation actions to closure, and report third-party risk alongside your other key risks to leadership.

Using the ISM and SOCI as a lens

For Australian government entities, the ISM, published by the Australian Signals Directorate, includes supply chain controls covering supplier assessments, contractual security requirements and the use of outsourced cloud services. Critical infrastructure entities must address supply chain hazards in their SOCI Act CIRMP. A tiered, evidence-based process like the one above satisfies the intent of both.

Get the questionnaire

My free third-party risk questionnaire template puts this approach into one Excel workbook: inherent risk tiering, 60 weighted questions across 17 domains including AI and sub-processors, automatic scoring, a residual risk rating, an onboarding recommendation and a remediation tracker.

Frequently asked questions

What is third-party risk management?

Third-party risk management (TPRM) is the process of identifying, assessing and controlling the risks that suppliers, vendors and service providers introduce, from security and privacy to operational resilience and compliance.

How often should vendors be reassessed?

A common approach is annually for Tier 1 suppliers, every one to two years for Tier 2 and every two to three years for lower tiers, plus whenever the service, data or supplier changes significantly.

Is an ISO 27001 certificate enough to approve a vendor?

It is strong evidence, but check the certificate is current and that its scope covers the service you are buying. For critical suppliers, combine it with a questionnaire and targeted evidence.

What should be in a vendor security contract?

Security requirements, breach notification timeframes, audit and assessment rights, data location, sub-processor approval, and secure return or destruction of data when the contract ends.


Building or uplifting a supplier assurance program? See third-party risk services or download the free questionnaire.

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader specialising in the ISM, PSPF, NIST SP 800-53, SOCI Act and AI governance (ISO 42001). Views are my own.