A vendor risk assessment is a structured process for evaluating the security posture of every third-party company that accesses your business data. The Verizon DBIR found that 15 percent of all data breaches involved a third-party vendor, and compliance frameworks including PCI DSS 4.0, HIPAA, and the FTC Safeguards Rule now require formal vendor oversight. This guide provides a complete spreadsheet-based assessment template with a tiering system you can start using today — no expensive GRC platform required.
Every third-party vendor you work with is a potential doorway into your business. Your IT provider has admin access to your network. Your payroll service has every employee’s social security number. Your cloud storage provider holds your financial records. Your CRM vendor has your entire customer database. If any of them get breached, you get breached — and your customers do not care whose fault it was. They blame you.
The 2024 Verizon Data Breach Investigations Report found that 15% of all data breaches involved a third-party vendor. The MOVEit vulnerability in 2023 compromised over 2,600 organizations through a single file transfer tool. The Kaseya attack affected 1,500 businesses through one software vendor. These are not theoretical risks — they are the pattern of how modern breaches happen.
Most small businesses in Ormond Beach and across Volusia County have no formal process for evaluating vendor risk. They sign up for software, hand over access, and hope for the best. This guide gives you a complete, practical vendor risk assessment template that you can start using today — no expensive GRC platform required, just a spreadsheet and the willingness to ask your vendors direct questions. Our guide to Cybersecurity for Small Businesses: The 5 Things That Actually Matter walks through this in more detail.
Why Vendor Risk Matters for Small Businesses
Let us address the common objection: “We are too small for formal vendor risk management.” Here is why that is wrong.
Compliance requires it. PCI DSS 4.0 Requirement 12.8 explicitly requires you to maintain a list of all service providers, including a description of the service they provide, and to monitor their compliance status. HIPAA requires you to have Business Associate Agreements with any vendor that touches protected health information. The FTC Safeguards Rule requires oversight of service providers that access customer financial data. If you are subject to any of these frameworks, vendor risk management is not optional.
Insurance requires it. Cyber insurance applications increasingly ask about your third-party risk management process. “We do not have one” either raises your premium or gets your application denied.
Liability follows you. When your vendor gets breached and your customer data is exposed, the regulatory fines, lawsuits, and notification costs land on you — not the vendor. Your contract with the vendor may limit their liability to the amount you paid them. A $500/month software subscription with a $6,000 liability cap does not help when you are facing a $100,000 breach response.
The Vendor Tiering System
Not every vendor needs the same level of scrutiny. Your cloud hosting provider with access to all your data needs a more thorough assessment than the company that supplies your office paper. Here is a practical tiering system:
Tier 1 — Critical (Full Assessment Required)
Vendors that have:
- Direct access to your network or systems (IT provider, cloud host)
- Access to sensitive customer data (CRM, payment processor, healthcare records)
- Access to financial data (payroll, accounting, banking)
- Single point of failure (if they go down, you cannot operate)
Examples: IT managed service provider, cloud hosting, payroll service, payment processor, EHR/EMR vendor, banking platform, CRM with customer PII
Assessment frequency: Annual full assessment, quarterly check-ins
Tier 2 — Significant (Standard Assessment Required)
Vendors that have:
- Limited access to business data (email marketing, project management)
- Access to internal but non-sensitive data
- Substitutable (alternatives exist with manageable switching cost)
Examples: Email marketing platform, project management tool, phone system, accounting software, file sharing service
Assessment frequency: Annual assessment
Tier 3 — Low Risk (Basic Assessment)
Vendors that have:
- No access to sensitive data
- No system-level access
- Easily replaceable
Examples: Office supply vendor, janitorial service, marketing agency (without system access), insurance broker
Assessment frequency: Assessment at onboarding, review at contract renewal
The Vendor Risk Assessment Template
Here is the complete assessment template. For Tier 1 vendors, use all sections. For Tier 2, use Sections 1-4. For Tier 3, use Section 1 only.
Section 1: Vendor Profile (All Tiers)
# vendor-assessment/profile.yaml
vendor_profile:
company_name: ""
contact_name: ""
contact_email: ""
contact_phone: ""
website: ""
address: ""
year_established: ""
number_of_employees: ""
annual_revenue_range: "" # Under $1M, $1M-$10M, $10M-$100M, Over $100M
services_provided:
description: ""
data_types_accessed:
- "" # Customer PII, financial data, health records, etc.
system_access_level: "" # None, Read-only, Read-write, Admin
integration_type: "" # API, Direct access, File transfer, None
contract_details:
start_date: ""
renewal_date: ""
annual_cost: ""
liability_cap: ""
termination_notice_period: ""
data_return_clause: "" # Yes/No — does contract specify data return?
risk_tier: "" # Tier 1, Tier 2, Tier 3
assessed_by: ""
assessment_date: ""
Section 2: Security Controls Assessment (Tier 1 & 2)
For each question, score the vendor 0-3:
| Score | Meaning |
|---|---|
| 3 | Strong — documented, verified, exceeds requirements |
| 2 | Adequate — in place but lacks documentation or has minor gaps |
| 1 | Weak — partially implemented or not consistently applied |
| 0 | Absent — not implemented or vendor cannot answer |
2A: Access Control (8 Questions)
| # | Question | Score | Notes |
|---|---|---|---|
| 1 | Does the vendor enforce MFA for all employees who access your data? | ||
| 2 | Does the vendor use role-based access control (RBAC)? | ||
| 3 | How does the vendor manage privileged access (admin accounts)? | ||
| 4 | Does the vendor conduct regular access reviews (at least annually)? | ||
| 5 | What is the vendor’s process for revoking access when employees leave? | ||
| 6 | Does the vendor use unique credentials per client environment? | ||
| 7 | Does the vendor log all access to your data/systems? | ||
| 8 | Can the vendor provide access logs on request? | ||
| Section Score | /24 |
2B: Data Protection (7 Questions)
| # | Question | Score | Notes |
|---|---|---|---|
| 9 | Is your data encrypted at rest? What algorithm and key length? | ||
| 10 | Is your data encrypted in transit? What TLS version? | ||
| 11 | Where is your data physically stored (country, region, data center)? | ||
| 12 | Does the vendor have a data classification policy? | ||
| 13 | How does the vendor handle data deletion when you terminate the contract? | ||
| 14 | Does the vendor share your data with subcontractors or fourth parties? | ||
| 15 | Does the vendor have a data retention policy? What is the retention period? | ||
| Section Score | /21 |
2C: Incident Response (6 Questions)
| # | Question | Score | Notes |
|---|---|---|---|
| 16 | Does the vendor have a documented incident response plan? | ||
| 17 | How quickly will the vendor notify you of a breach affecting your data? | ||
| 18 | What was the vendor’s last security incident? How was it handled? | ||
| 19 | Does the vendor conduct regular incident response testing (tabletop exercises)? | ||
| 20 | Does the vendor carry cyber insurance? What is the coverage amount? | ||
| 21 | Will the vendor provide forensic investigation details if your data is involved? | ||
| Section Score | /18 |
2D: Business Continuity (5 Questions)
| # | Question | Score | Notes |
|---|---|---|---|
| 22 | Does the vendor have a documented business continuity/disaster recovery plan? | ||
| 23 | What is the vendor’s guaranteed uptime SLA? | ||
| 24 | How often does the vendor test their disaster recovery plan? | ||
| 25 | What is the vendor’s RTO (Recovery Time Objective) and RPO (Recovery Point Objective)? | ||
| 26 | Does the vendor have geographic redundancy (multiple data centers)? | ||
| Section Score | /15 |
Section 3: Compliance & Certifications (Tier 1 & 2)
3A: Certifications (5 Questions)
| # | Question | Score | Notes |
|---|---|---|---|
| 27 | Does the vendor hold SOC 2 Type II certification? (Request the report) | ||
| 28 | Does the vendor hold ISO 27001 certification? | ||
| 29 | Is the vendor PCI DSS compliant (if handling payment data)? | ||
| 30 | Is the vendor HIPAA compliant (if handling health data)? Can they provide a BAA? | ||
| 31 | Does the vendor conduct annual penetration testing? Can they share results? | ||
| Section Score | /15 |
3B: Regulatory Alignment (4 Questions)
| # | Question | Score | Notes |
|---|---|---|---|
| 32 | Does the vendor comply with applicable state privacy laws (Florida, CCPA, etc.)? | ||
| 33 | How does the vendor handle regulatory changes that affect your data? | ||
| 34 | Does the vendor provide compliance documentation on request? | ||
| 35 | Does the vendor have a dedicated security/compliance team or officer? | ||
| Section Score | /12 |
Section 4: Operational Security (Tier 1 Only)
4A: Technical Controls (6 Questions)
| # | Question | Score | Notes |
|---|---|---|---|
| 36 | Does the vendor use endpoint detection and response (EDR) on their systems? | ||
| 37 | Does the vendor have a vulnerability management program? | ||
| 38 | How quickly does the vendor apply critical security patches? | ||
| 39 | Does the vendor use network segmentation in their environment? | ||
| 40 | Does the vendor conduct security awareness training for all employees? | ||
| 41 | Does the vendor monitor for security events 24/7? | ||
| Section Score | /18 |
4B: Supply Chain (4 Questions)
| # | Question | Score | Notes |
|---|---|---|---|
| 42 | Does the vendor assess the security of their own vendors (fourth-party risk)? | ||
| 43 | Can the vendor identify all subprocessors that access your data? | ||
| 44 | Does the vendor have contractual security requirements for their subcontractors? | ||
| 45 | Will the vendor notify you before changing subprocessors? | ||
| Section Score | /12 |
Scoring and Risk Rating
For Tier 1 Vendors (All Sections, 45 Questions, Max 135)
| Score Range | Risk Rating | Action Required |
|---|---|---|
| 108-135 (80%+) | Low Risk | Approve. Annual reassessment. |
| 81-107 (60-79%) | Medium Risk | Approve with conditions. Document gaps. 90-day remediation plan. Reassess in 6 months. |
| 54-80 (40-59%) | High Risk | Conditional approval only. Written remediation plan required. Reassess in 90 days. Consider alternatives. |
| Below 54 (<40%) | Critical Risk | Do not approve or begin exit planning. Significant security gaps that endanger your data. |
For Tier 2 Vendors (Sections 1-3, 35 Questions, Max 105)
| Score Range | Risk Rating | Action Required |
|---|---|---|
| 84-105 (80%+) | Low Risk | Approve. Annual reassessment. |
| 63-83 (60-79%) | Medium Risk | Approve with documented gaps. Annual reassessment. |
| 42-62 (40-59%) | High Risk | Review necessity. Require remediation plan. |
| Below 42 (<40%) | Critical Risk | Seek alternatives. |
The Assessment Spreadsheet
For practical use, create a spreadsheet with these columns for your vendor inventory:
| Vendor Name | Tier | Service | Data Access | Last Assessment | Score | Risk Rating | Next Review | Owner | Notes |
Track every vendor in one place. Sort by risk rating so you always know where your highest risks are. Assign an owner to each vendor relationship — someone responsible for conducting assessments, tracking remediation, and managing the contract.
Here is a starter inventory for a typical small business:
| Vendor | Tier | Service | Data Access | Risk Focus |
|---|---|---|---|---|
| IT Provider (MSP) | 1 | Network management | Full admin | Highest risk — see IT provider evaluation guide |
| Cloud Hosting (AWS/Azure) | 1 | Infrastructure | All business data | Platform security, data residency |
| Payment Processor (Stripe/Square) | 1 | Payment processing | Card data | PCI compliance |
| Payroll (ADP/Gusto) | 1 | Payroll | SSN, bank accounts | Financial data protection |
| CRM (Salesforce/HubSpot) | 1 | Customer management | Customer PII | Access controls, data export |
| Email (M365/Google) | 1 | Communication | All email content | Account security, DLP |
| Accounting (QuickBooks) | 2 | Financials | Financial records | Access controls |
| Project Management (Asana) | 2 | Workflow | Internal projects | Limited data exposure |
| Phone System (RingCentral) | 2 | Communications | Call records | Moderate risk |
| Marketing (Mailchimp) | 2 | Email marketing | Customer emails | List security |
| Website Hosting | 2 | Web presence | Public content | Availability |
| Office Supplies | 3 | Procurement | Billing info only | Low risk |
| Cleaning Service | 3 | Facilities | Physical access only | Physical security |
Handling Vendor Pushback
Some vendors will resist answering your assessment questions. Here is how to handle the common objections:
“We cannot share that information for security reasons.” Counter: “We are not asking for technical implementation details. We are asking whether controls exist. A SOC 2 report is specifically designed to answer these questions — can you provide one?” If they have no SOC 2, no ISO 27001, and refuse to answer basic security questions, that is your answer about their security posture.
“No other customer has ever asked us this.” Counter: “Compliance frameworks require us to assess our vendors. This is standard practice. We are happy to use a standardized questionnaire format like SIG Lite if that is easier for your team.” If you are truly the first customer asking about security, consider what that says about their customer base.
“We are too small for formal security certifications.” Counter: “We understand — we are a small business too. We are not requiring SOC 2 certification. We just need to document that basic security controls are in place. Can you walk us through how you handle access control, encryption, and incident response?” Reasonable vendors will appreciate the collaborative approach.
“Just trust us.” Counter: Start looking for an alternative vendor.
Contract Provisions to Include
When the assessment is complete and you decide to proceed, make sure your contract includes these provisions:
-
Security requirements clause: Vendor must maintain security controls consistent with industry standards (reference SOC 2, ISO 27001, or specific controls you require).
-
Breach notification requirement: Vendor must notify you within 24-72 hours of discovering a breach affecting your data (align with your regulatory requirements).
-
Right to audit: You (or your designated third party) can audit the vendor’s security controls with reasonable notice.
-
Data return/destruction: Upon termination, vendor must return or certify destruction of your data within 30 days.
-
Insurance requirements: Vendor must maintain cyber insurance and E&O insurance at specified minimums.
-
Subcontractor disclosure: Vendor must disclose and get your approval for any subcontractors that will access your data.
-
Compliance obligations: Vendor must comply with applicable regulations (PCI DSS, HIPAA, etc.) relevant to the data they handle.
-
Indemnification: Vendor indemnifies you for losses arising from their negligence or breach of the security requirements. We cover this in more detail in Automating Windows Server Compliance Checks with PowerShell.
Many small businesses skip these contract provisions because “it is just a standard SaaS agreement.” That standard agreement typically limits the vendor’s liability to whatever you paid them in the last 12 months. For a $100/month SaaS tool holding your customer database, that means $1,200 in liability for a breach that costs you $100,000+. Negotiate better terms, or at least understand what you are accepting.
Ongoing Monitoring
The assessment is not a one-time event. Vendor risk changes over time — they get acquired, they change their infrastructure, they have staff turnover, they get breached. Here is a practical monitoring cadence:
Quarterly (Tier 1 vendors):
- Review vendor security news (search “[vendor name] breach” or “[vendor name] vulnerability”)
- Check vendor status page for uptime and incidents
- Review any vendor-provided security bulletins
Annually (All active vendors):
- Conduct full reassessment using the template
- Request updated SOC 2 reports (if applicable)
- Review and renegotiate contract terms
- Update your vendor inventory spreadsheet
Trigger-based (Any vendor, any time):
- Vendor announces a data breach
- Vendor is acquired or merges with another company
- Vendor announces major infrastructure changes
- Your regulatory requirements change
- Contract is up for renewal
The Bottom Line
Every vendor with access to your data is a potential breach vector. The assessment template and scoring system in this guide give you a structured way to evaluate vendor risk, prioritize remediation, and maintain ongoing monitoring. Start with your highest-access vendors and work through the list. The assessment that catches a vendor security gap before it becomes your breach is worth every minute you spend on it.
FAQ
How long does a vendor risk assessment take?
For Tier 3 vendors (basic profile only), about 15 minutes. For Tier 2 (35 questions), plan for 1-2 hours including the vendor’s response time. For Tier 1 (full 45-question assessment), expect 2-4 hours total between sending the questionnaire, reviewing responses, and scoring. The first assessment takes the longest — subsequent annual reviews are faster because you are checking for changes rather than starting from scratch.
What if a critical vendor scores poorly but we cannot switch providers?
This happens more often than you would think — sometimes the vendor with the best product has mediocre security, and there is no viable alternative. Document the risk formally. Create a risk acceptance memo that identifies the specific gaps, the potential impact, and any compensating controls you can implement on your side (like additional monitoring, restricted data sharing, or more frequent backups). Have business ownership sign the risk acceptance. This is not ideal, but it is better than pretending the risk does not exist.
Should I use a standardized questionnaire like SIG or CAIQ instead?
The Standardized Information Gathering (SIG) questionnaire and the Consensus Assessment Initiative Questionnaire (CAIQ) are industry-standard options. SIG Lite has about 200 questions and is good for mid-sized vendor assessments. CAIQ is focused on cloud providers. For most small businesses, these are overkill. Our 45-question template covers the essential areas without overwhelming either you or your vendors. If you grow to the point where you are managing 50+ vendor relationships, consider graduating to SIG.
Do I need vendor risk assessment software?
Not at first. A spreadsheet (Excel or Google Sheets) tracking your vendor inventory and assessment scores works perfectly for businesses with fewer than 30 active vendors. When you outgrow the spreadsheet — meaning you are spending more time managing the spreadsheet than doing assessments — tools like Vanta, Drata, or SecurityScorecard automate evidence collection and continuous monitoring. But that is a $5,000-25,000/year investment that most small businesses do not need yet.
How do I assess vendors that refuse to answer my questions?
Check for publicly available information first: their website’s security page, their trust center (many SaaS companies publish one), SOC 2 reports posted on their site, and their privacy policy. You can also use external scanning tools like SecurityScorecard’s free tier to get a basic security rating. If a vendor has no public security information and refuses to answer questions, document that refusal as part of your assessment — it is itself a significant risk indicator.
What is a Business Associate Agreement (BAA) and do I need one?
A BAA is a legally required contract under HIPAA between a covered entity (you, if you handle health data) and any vendor (business associate) that accesses protected health information (PHI). If you are a healthcare provider, health plan, or healthcare clearinghouse, you need a BAA with every vendor that touches patient data — your EHR vendor, your cloud storage provider, your billing service, even your shredding company. Without a BAA, you are in HIPAA violation regardless of how good the vendor’s security is.