Zurück zur Bibliothek

Vendor security risk assessment

Assesses a supplier’s security posture from questionnaires, certifications, architecture notes, and data-processing facts, then produces a scored control-coverage report and contract requirements. Use for vendor onboarding, annual reassessment, third-party security review, procurement due diligence, and supplier risk exceptions.

von adlass TemplatesVersion 1Nutzt adlass-ToolsUniversell

Veröffentlicht 21. Aug. 2026 · Aktualisiert 26. Aug. 2026

Hilfreich · 0Rohes SKILL.md ansehen

Voraussetzungen

Add the control baseline, risk matrix, and supplier questionnaire. Define data classes, criticality, residual-risk language, and contract requirements. Set evidence-validity and subprocessor review rules.

Skill-Dokument

Das vollständige SKILL.md, das dein Agent liest und befolgt.

Vendor security risk assessment

Purpose

Evaluate whether a supplier’s documented security controls match the risk created by the service, data, and access involved. Produce traceable gaps, residual risk, and requirements for a reasoned procurement decision.

Scope

One supplier assessment using the supplied questionnaire, assurance reports, certifications, architecture, subprocessors, locations, and data-processing description. Excluded: penetration testing, system access, legal approval, and supplier negotiation.

Data basis

  • Supplier questionnaire and security evidence.
  • Service description, data classification, access model, and criticality.
  • Company control baseline, risk matrix, contract checklist, and prior assessment.

Result

A vendor risk report, control-coverage sheet, and contract-requirements document with every conclusion tied to supplier evidence or an identified gap.

Quality criteria

  • Scope and validity dates are checked for each assurance document.
  • Every control row has evidence, status, citation, and limitation.
  • Risk rating follows the supplied matrix and shows its calculation.
  • Subprocessors, locations, and data flows are not omitted.

Instructions

Distinguish a control claim from evidence that demonstrates operation. Treat expired, out-of-scope, or summary-only assurance as limited evidence. Do not infer compliance from a logo or certification name. Separate inherent service risk from control gaps and residual risk. Use the company matrix; if absent, label the rating as an indicative assessment rather than a decision.

The review should make the population, calculation basis, and exception treatment understandable to a second operator. Preserve source identifiers in every working table, and state the effect of missing evidence on the decision. A reviewer must be able to reproduce each material result from the cited rows, clauses, dates, or policy rules. Where two sources disagree, show both values and explain which source was treated as authoritative.

Adapt before use

  • Add the company control baseline, risk matrix, and supplier questionnaire.
  • Define data classes, criticality levels, and acceptable residual-risk language.
  • Specify contract clauses and review cadence for high-risk suppliers.
  • Set the evidence-validity and subprocessor requirements.

Verwandte Skills

  • Access provisioning checklist

    Converts employee roles and lifecycle events into a system-by-system provisioning or deprovisioning checklist with approvals, dependencies, and audit evidence fields. Use for joiner, mover, leaver, role-change, access-request, and identity-control preparation.

  • Audit evidence pack

    Organizes audit requests into evidence tests, evaluates supplied documents for coverage and period, and produces a traceable evidence tracker with control narratives and gaps. Use for SOC, ISO, internal control, customer audit, certification, and audit-readiness preparation.

  • Backup and recovery verification

    Checks backup coverage, retention, failures, and recovery-test evidence against system criticality and recovery objectives, then produces a verification report and remediation list. Use for backup audits, disaster-recovery readiness, RTO/RPO reviews, resilience checks, and recurring IT control evidence.

  • Change release record

    Turns a proposed production change into a structured risk, test, approval, rollback, and verification record with traceable evidence. Use for change management, release readiness, deployment review, CAB preparation, rollback planning, and audit documentation.