Vendor risk is the risk an organization inherits or creates through suppliers, SaaS providers, contractors, infrastructure providers, and other external services.
Vendor risk review should be proportionate to the service. Useful questions include:
- What data or access does the vendor receive?
- Which business process depends on the service?
- How does the vendor protect, restore, and delete data?
- What happens when the vendor has an incident?
- Which evidence, contractual terms, and review cadence apply?
The assessment should continue after onboarding. Material changes, incidents, renewals, and service changes can alter the risk.
