GlossaryGlossary

Vendor risk

Vendor risk is the security, privacy, resilience, and operational risk introduced by suppliers and service providers that support a business.

August 31, 2026Updated August 2026
Supplier securityThird-party riskSecurity governance

Vendor risk is the risk an organization inherits or creates through suppliers, SaaS providers, contractors, infrastructure providers, and other external services.

Vendor risk review should be proportionate to the service. Useful questions include:

  • What data or access does the vendor receive?
  • Which business process depends on the service?
  • How does the vendor protect, restore, and delete data?
  • What happens when the vendor has an incident?
  • Which evidence, contractual terms, and review cadence apply?

The assessment should continue after onboarding. Material changes, incidents, renewals, and service changes can alter the risk.

Read Supplier Security Policy: What SMBs Often Miss.