---
name: vendor-security-risk-assessment
description: Assesses a supplier’s security posture from questionnaires, certifications, architecture notes, and data-processing facts, then produces a scored control-coverage report and contract requirements. Use for vendor onboarding, annual reassessment, third-party security review, procurement due diligence, and supplier risk exceptions.
license: Apache-2.0
metadata:
  adlass.categories: "it-security/vendor-risk, it-security/audit-evidence"
  adlass.industries: ""
  adlass.tags: "vendor-risk, supplier-security, due-diligence, controls, certifications, procurement"
  adlass.adaptation: "reference-doc"
  adlass.source: "original"
  adlass.version: "1"
---

# Vendor security risk assessment

## Purpose

Evaluate whether a supplier’s documented security controls match the risk created by the service, data, and access involved. Produce traceable gaps, residual risk, and requirements for a reasoned procurement decision.

## Scope

One supplier assessment using the supplied questionnaire, assurance reports, certifications, architecture, subprocessors, locations, and data-processing description. **Excluded:** penetration testing, system access, legal approval, and supplier negotiation.

## Data basis

- Supplier questionnaire and security evidence.
- Service description, data classification, access model, and criticality.
- Company control baseline, risk matrix, contract checklist, and prior assessment.

## Result

A vendor risk report, control-coverage sheet, and contract-requirements document with every conclusion tied to supplier evidence or an identified gap.

## Quality criteria

- Scope and validity dates are checked for each assurance document.
- Every control row has evidence, status, citation, and limitation.
- Risk rating follows the supplied matrix and shows its calculation.
- Subprocessors, locations, and data flows are not omitted.

## Instructions

Distinguish a control claim from evidence that demonstrates operation. Treat expired, out-of-scope, or summary-only assurance as limited evidence. Do not infer compliance from a logo or certification name. Separate inherent service risk from control gaps and residual risk. Use the company matrix; if absent, label the rating as an indicative assessment rather than a decision.

The review should make the population, calculation basis, and exception treatment understandable to a second operator. Preserve source identifiers in every working table, and state the effect of missing evidence on the decision. A reviewer must be able to reproduce each material result from the cited rows, clauses, dates, or policy rules. Where two sources disagree, show both values and explain which source was treated as authoritative.

## Adapt before use

- Add the company control baseline, risk matrix, and supplier questionnaire.
- Define data classes, criticality levels, and acceptable residual-risk language.
- Specify contract clauses and review cadence for high-risk suppliers.
- Set the evidence-validity and subprocessor requirements.
