Third-Party & Supplier Risk · Free Excel template
Third-Party Risk Management Questionnaire (Free Excel Vendor Security Template)
This free third-party risk management questionnaire helps you assess suppliers, SaaS providers and outsourced services in a consistent, defensible way. Send it to a supplier, review their answers and evidence, and the workbook calculates the risk for you.
It contains 60 weighted questions across 17 security domains, including questions on AI and sub-processors that most vendor questionnaires still miss. Scores, domain ratings, a residual risk rating and an onboarding recommendation are all calculated automatically.
- 60weighted questions
- 17security domains
- 4risk tiers
- Freeno sign-up
What's inside the workbook
For: Procurement, risk, security and compliance teams assessing suppliers, cloud and SaaS providers, and outsourced service providers.
- 01
Introduction🔒
How to use the questionnaire, the scoring method and the colour legend.
- 02
Supplier Profile
Supplier details, services, data locations and sub-processors, plus the calculated inherent risk tier.
- 03
Questionnaire
60 questions with expected evidence, weights from 1 to 3, supplier responses, comments, evidence references and assessor notes.
- 04
Risk Summary
Overall score, completion, critical gaps, residual risk rating, onboarding recommendation and scores by domain with a chart.
- 05
Findings & Remediation
Register of gaps with risk rating, required remediation, supplier and internal owners, due dates, status and overdue tracking.
- Weighted Yes, Partial and No scoring
- Inherent risk tier from criticality and data sensitivity
- Automatic residual risk rating
- Onboarding recommendation
- AI and sub-processor questions
- Works in Microsoft Excel 2016 and later
What is a third-party risk management questionnaire?
A third-party risk management (TPRM) questionnaire, also called a vendor security questionnaire, asks suppliers to describe and evidence the security controls that protect your data and services. It is the core of supplier due diligence before onboarding, and of periodic reassessment afterwards.
The challenge is consistency. Without weighting and a clear scoring method, two assessors can reach different conclusions about the same supplier. This template fixes that with weighted questions, defined thresholds and an automatic recommendation, while still leaving room for assessor judgement.
The 17 security domains
Each question includes the evidence you should expect to see, so assessors know what to ask for and suppliers know what to provide.
How the risk scoring works
Inherent risk tier. On the Supplier Profile you rate service criticality and data sensitivity from 1 to 4. Multiplying them gives an inherent risk score from 1 to 16: Tier 1 Critical (12 or more), Tier 2 High (6 or more), Tier 3 Moderate (3 or more) and Tier 4 Low. Higher tiers deserve deeper assurance and more frequent review.
Question scoring. Each question has a weight from 1 to 3. A Yes scores twice the weight, Partial scores the weight, and No scores zero. N/A answers are excluded from the maximum, so suppliers are not penalised for questions that do not apply.
Ratings. Each domain is rated Strong (85% or more), Adequate (70% or more), Weak (50% or more) or Poor. The overall score sets the residual risk: Low, Medium, High or Critical. A No on any weight 3 question is flagged as a critical gap.
Recommendation. The workbook recommends Approve, Approve with conditions, or Escalate, based on the residual rating and the number of critical gaps. You can change the weights to match your own risk appetite.
Why AI questions belong in every vendor assessment
Most suppliers now ship AI features, often switched on by default, and some send your data to third-party model providers. The questionnaire asks whether AI is used in the service, whether your data trains models, whether AI features can be disabled, and whether the supplier has an AI governance framework such as ISO/IEC 42001. Read more in AI supply chain risk: the AI already inside your vendors.
Aligned with Australian requirements
Alongside international good practice such as ISO/IEC 27001, the questionnaire includes questions that matter in Australia: the Privacy Act 1988 and notifiable data breaches, alignment with the ISM and IRAP for government work, Australian Government security clearances, and support for SOCI Act supply chain obligations for critical infrastructure. It also supports APRA-regulated entities managing material service providers under CPS 230.
How to use the Third-Party Risk Management Questionnaire
- 1
Profile the supplier
On Supplier Profile, record the service and rate service criticality and data sensitivity to calculate the inherent risk tier.
- 2
Tune the weights
Optionally adjust question weights from 1 (low) to 3 (critical) to reflect your risk appetite.
- 3
Send to the supplier
The supplier completes their details and answers every question with Yes, Partial, No or N/A, adding comments and evidence references.
- 4
Review the evidence
Check the evidence provided and record assessor notes where answers need challenge or clarification.
- 5
Read the Risk Summary
Review the overall score, domain ratings, critical gaps, residual risk rating and onboarding recommendation.
- 6
Track remediation
Log gaps on Findings & Remediation with owners and due dates and follow them through to closure.
Get the Third-Party Risk Management Questionnaire
Free download. No sign-up, no email required.
Frequently asked questions
What is a vendor security questionnaire used for?
It is used to assess the security controls of a supplier before you share data or depend on their service, and to reassess them periodically. It forms the evidence base for onboarding decisions and supplier risk acceptance.
How many questions are in the questionnaire?
There are 60 weighted questions across 17 security domains, from governance and access control to incident response, business continuity, sub-processors and AI. You can adjust the weights to suit your risk appetite.
How is the supplier risk score calculated?
Each answer is scored against its weight: Yes scores twice the weight, Partial scores the weight and No scores zero, with N/A excluded. The overall percentage sets the residual risk rating, and No answers on critical questions are flagged as critical gaps.
How often should suppliers be reassessed?
A common approach is to reassess Tier 1 suppliers at least annually, Tier 2 every one to two years, and lower tiers every two to three years, plus whenever the service, the data shared or the supplier changes significantly.
Does it cover AI and sub-processors?
Yes. Four questions cover AI use, training on your data, the ability to disable AI features and AI governance, and three questions cover sub-processors (fourth parties).
Can suppliers complete it directly?
Yes. Send the workbook to the supplier to complete the profile and questionnaire, then review their responses and evidence. The Introduction tab is locked so the guidance stays intact.
More free templates
Audit & Certification
ISO 27001 Internal Audit Workbook
Plan and run ISO/IEC 27001:2022 internal audits end to end: clauses 4 to 10, all 93 Annex A controls, findings and corrective actions, with a live dashboard.
View template →US Defense · CMMC 2.0
CMMC Level 1 & 2 Readiness Workbook
Self-assess against the official CMMC 2.0 requirements: 15 for Level 1 and all 110 NIST SP 800-171 Rev 2 requirements for Level 2, with automatic SPRS scoring and POA&M eligibility.
View template →Risk Assessment · NIST SP 800-30
Cyber Security Risk Assessment Workbook
Identify, analyse and treat cyber risks with the NIST SP 800-30 method, a 5x5 matrix, a 25-risk starter library, a live heat map and treatment mapped to NIST SP 800-53.
View template →Templates
Browse all templates
Expert-built Excel tools for audits, assessments and supplier reviews.
See all →