Third-Party & Supplier Risk · Free Excel template

Third-Party Risk Management Questionnaire (Free Excel Vendor Security Template)

This free third-party risk management questionnaire helps you assess suppliers, SaaS providers and outsourced services in a consistent, defensible way. Send it to a supplier, review their answers and evidence, and the workbook calculates the risk for you.

It contains 60 weighted questions across 17 security domains, including questions on AI and sub-processors that most vendor questionnaires still miss. Scores, domain ratings, a residual risk rating and an onboarding recommendation are all calculated automatically.

  • 60weighted questions
  • 17security domains
  • 4risk tiers
  • Freeno sign-up
Download the free template .xlsx · 70 KB · Excel 2016+ / Microsoft 365 · Updated Oct 2026

What's inside the workbook

For: Procurement, risk, security and compliance teams assessing suppliers, cloud and SaaS providers, and outsourced service providers.

  1. 01

    Introduction🔒

    How to use the questionnaire, the scoring method and the colour legend.

  2. 02

    Supplier Profile

    Supplier details, services, data locations and sub-processors, plus the calculated inherent risk tier.

  3. 03

    Questionnaire

    60 questions with expected evidence, weights from 1 to 3, supplier responses, comments, evidence references and assessor notes.

  4. 04

    Risk Summary

    Overall score, completion, critical gaps, residual risk rating, onboarding recommendation and scores by domain with a chart.

  5. 05

    Findings & Remediation

    Register of gaps with risk rating, required remediation, supplier and internal owners, due dates, status and overdue tracking.

  • Weighted Yes, Partial and No scoring
  • Inherent risk tier from criticality and data sensitivity
  • Automatic residual risk rating
  • Onboarding recommendation
  • AI and sub-processor questions
  • Works in Microsoft Excel 2016 and later

What is a third-party risk management questionnaire?

A third-party risk management (TPRM) questionnaire, also called a vendor security questionnaire, asks suppliers to describe and evidence the security controls that protect your data and services. It is the core of supplier due diligence before onboarding, and of periodic reassessment afterwards.

The challenge is consistency. Without weighting and a clear scoring method, two assessors can reach different conclusions about the same supplier. This template fixes that with weighted questions, defined thresholds and an automatic recommendation, while still leaving room for assessor judgement.

The 17 security domains

Governance & Policy 4Certifications & Assurance 4Risk Management 4People Security 4 Identity & Access Management 4Data Protection & Privacy 4Encryption 3Vulnerability & Patch Management 4 Logging & Monitoring 3Incident Management 4Business Continuity & Resilience 4Secure Development 3 Cloud & Hosting 3Sub-processors 3AI & Emerging Technology 4Physical Security 2 Government & Regulatory 3

Each question includes the evidence you should expect to see, so assessors know what to ask for and suppliers know what to provide.

How the risk scoring works

Inherent risk tier. On the Supplier Profile you rate service criticality and data sensitivity from 1 to 4. Multiplying them gives an inherent risk score from 1 to 16: Tier 1 Critical (12 or more), Tier 2 High (6 or more), Tier 3 Moderate (3 or more) and Tier 4 Low. Higher tiers deserve deeper assurance and more frequent review.

Question scoring. Each question has a weight from 1 to 3. A Yes scores twice the weight, Partial scores the weight, and No scores zero. N/A answers are excluded from the maximum, so suppliers are not penalised for questions that do not apply.

Ratings. Each domain is rated Strong (85% or more), Adequate (70% or more), Weak (50% or more) or Poor. The overall score sets the residual risk: Low, Medium, High or Critical. A No on any weight 3 question is flagged as a critical gap.

Recommendation. The workbook recommends Approve, Approve with conditions, or Escalate, based on the residual rating and the number of critical gaps. You can change the weights to match your own risk appetite.

Why AI questions belong in every vendor assessment

Most suppliers now ship AI features, often switched on by default, and some send your data to third-party model providers. The questionnaire asks whether AI is used in the service, whether your data trains models, whether AI features can be disabled, and whether the supplier has an AI governance framework such as ISO/IEC 42001. Read more in AI supply chain risk: the AI already inside your vendors.

Aligned with Australian requirements

Alongside international good practice such as ISO/IEC 27001, the questionnaire includes questions that matter in Australia: the Privacy Act 1988 and notifiable data breaches, alignment with the ISM and IRAP for government work, Australian Government security clearances, and support for SOCI Act supply chain obligations for critical infrastructure. It also supports APRA-regulated entities managing material service providers under CPS 230.

How to use the Third-Party Risk Management Questionnaire

  1. 1

    Profile the supplier

    On Supplier Profile, record the service and rate service criticality and data sensitivity to calculate the inherent risk tier.

  2. 2

    Tune the weights

    Optionally adjust question weights from 1 (low) to 3 (critical) to reflect your risk appetite.

  3. 3

    Send to the supplier

    The supplier completes their details and answers every question with Yes, Partial, No or N/A, adding comments and evidence references.

  4. 4

    Review the evidence

    Check the evidence provided and record assessor notes where answers need challenge or clarification.

  5. 5

    Read the Risk Summary

    Review the overall score, domain ratings, critical gaps, residual risk rating and onboarding recommendation.

  6. 6

    Track remediation

    Log gaps on Findings & Remediation with owners and due dates and follow them through to closure.

Get the Third-Party Risk Management Questionnaire

Free download. No sign-up, no email required.

Download (.xlsx, 70 KB)

Frequently asked questions

What is a vendor security questionnaire used for?

It is used to assess the security controls of a supplier before you share data or depend on their service, and to reassess them periodically. It forms the evidence base for onboarding decisions and supplier risk acceptance.

How many questions are in the questionnaire?

There are 60 weighted questions across 17 security domains, from governance and access control to incident response, business continuity, sub-processors and AI. You can adjust the weights to suit your risk appetite.

How is the supplier risk score calculated?

Each answer is scored against its weight: Yes scores twice the weight, Partial scores the weight and No scores zero, with N/A excluded. The overall percentage sets the residual risk rating, and No answers on critical questions are flagged as critical gaps.

How often should suppliers be reassessed?

A common approach is to reassess Tier 1 suppliers at least annually, Tier 2 every one to two years, and lower tiers every two to three years, plus whenever the service, the data shared or the supplier changes significantly.

Does it cover AI and sub-processors?

Yes. Four questions cover AI use, training on your data, the ability to disable AI features and AI governance, and three questions cover sub-processors (fourth parties).

Can suppliers complete it directly?

Yes. Send the workbook to the supplier to complete the profile and questionnaire, then review their responses and evidence. The Introduction tab is locked so the guidance stays intact.

Muhammad Anwar

Built by

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader, ISO 27001 Lead Auditor and Certified GRC Auditor. This template is based on the approach I use in real assessments across Defence, Federal Government and critical infrastructure.

More free templates