Vendor Risk Assessment
Definition
Vendor Risk Assessment
A vendor risk assessment is a structured review of one supplier’s exposure across financial, operational, security, regulatory and concentration lines. It looks at one supplier at a time — the wider programme that covers all of them is a different job entirely.
Depth should follow criticality — assessing a payroll processor and a stationery supplier to the same standard wastes effort on one and under-protects the other.
The assessment happens more than once. An initial evaluation informs selection, and periodic reassessment catches the changes that occur after the contract is signed.
The common failure is treating it as a questionnaire exercise. Answers collected and filed without verification produce a document rather than an assessment.
Key takeaways
- The assessment covers one supplier; third-party risk management covers the portfolio.
- Depth should be proportionate to how critical the supplier actually is.
- Reassessment matters more than the initial review, because circumstances change.
- Unverified questionnaire responses are evidence of nothing without independent testing.
How it works
The assessor scopes what the supplier does, identifies the risk categories that apply, gathers evidence, tests the material answers and records a rating with the actions required to accept it.
Regulators are explicit that one size does not fit all. Interagency guidance “clarifies that not all third-party relationships present the same level of risk or criticality” to an organisation’s operations.
| Dimension | What it examines | Evidence that counts |
|---|---|---|
| Financial | Solvency, revenue concentration | Audited accounts, filings |
| Operational | Capacity, attrition, continuity | Site visits, performance history |
| Security | Controls, incidents, certification | Audit reports, test results |
| Regulatory | Licences, sanctions, screening | Registers, adverse media checks |
| Concentration | Your share of their revenue | Disclosed figures, honest discussion |
The concentration row is the one buyers skip — a supplier drawing most of its revenue from a single client is fragile, and so is a client who is a trivial account to a large supplier.
Supply chain exposure needs its own attention. Published guidance on cybersecurity in the supply chain addresses “identifying, assessing, and mitigating cybersecurity risks throughout the supply chain” at every level of an organisation.
The baseline is often lower than assumed. National cyber guidance observes that “very few UK businesses set minimum security standards for their suppliers”, which makes a structured assessment unusually valuable.
Findings have to reach the contract. An assessment that identifies a continuity gap and does not produce a contractual obligation to close it has documented a risk rather than managed one.
Examples
Assessments range from a half-day review to a multi-week exercise with site visits. The four cases below show depth being matched to what the supplier actually does.
A buyer assesses a payroll provider over four weeks, including a site visit and a review of its continuity testing. The business continuity clause is drafted from what the assessment found.
A buyer accepts a completed questionnaire from a data provider without verification. An incident two years later shows the security answers had never been true.
A procurement outsourcing team tiers its suppliers and applies three assessment depths. The heaviest process runs on 12 suppliers rather than 400.
A buyer reassesses annually and detects that a provider’s largest client has left. The concentration risk has inverted, and the contract is repriced accordingly.
Related terms
Assessing one supplier sits inside a wider set of disciplines that are frequently merged. The entries below separate the single evaluation from the programme and from the verification tools.
- Vendor management outsourcing: the ongoing function that commissions and acts on assessments.
- Risk outsourcing: the broader allocation question the assessment feeds into.
- OCC third-party guidance: the supervisory expectations that shaped modern assessment practice.
- Right to audit clause: the contractual right that makes verification possible at all.
- AI vendor evaluation: a specialised assessment for suppliers deploying automated decision systems.
FAQ
When should an assessment be run?
Before contracting, then periodically according to criticality. Annual for critical suppliers and every two or three years for the rest is a common cadence.
Is a questionnaire enough?
Only as a starting point. Material answers need independent evidence such as audit reports, certifications or direct testing before they can be relied on.
How is depth decided?
By criticality and data sensitivity. Suppliers whose failure would stop a core process, or who handle regulated data, get the deepest treatment.
What is concentration risk?
Dependence in either direction. It covers both a supplier relying heavily on one client and a client being too small to matter to a large supplier.
Who should carry out the assessment?
A function independent of the people buying the service. Procurement or risk teams are usual, with security and legal contributing specialist sections.
How does this differ from third-party risk management?
This assesses one supplier at a point in time. Third-party risk management is the continuing programme covering the whole portfolio across its lifecycle.
Compare suppliers before you assess them in the Outsource Accelerator directory.







Independent




