Risk & policies

How do I do a vendor security assessment?

A vendor security assessment checks whether a third party protects the data you would share with it. Tier the vendor by the data and access it needs, gather evidence (a SOC 2 report, an ISO 27001 certificate, or a completed security questionnaire), review the gaps, record a risk rating with an owner and a decision, and set a re-assessment date so it happens on a cadence.

Step by step

  1. Tier by data access. Rank the vendor by the sensitivity of the data and the access it needs. A tool with access to customer data warrants far more scrutiny than one with none.
  2. Request evidence. Ask for a current SOC 2 Type II report or ISO 27001 certificate; if there is none, send a security questionnaire and ask for supporting documents.
  3. Review controls and gaps. Check access control, encryption, incident response, and business continuity, and note where the vendor falls short of what the data requires.
  4. Record a risk decision and owner. Assign a risk rating, decide to accept, mitigate, or avoid, and give the vendor an accountable owner.
  5. Set a review cadence. Schedule a re-assessment (at least annually for important vendors, and after any material change or incident).

Prioritize by data access, not spend

A small, inexpensive tool with access to customer records can carry more risk than a costly vendor that never touches sensitive data. Tier your effort accordingly.

What evidence to accept

A current SOC 2 Type II report or ISO 27001 certificate is the strongest evidence. Absent that, a completed questionnaire plus artifacts (policies, a recent penetration test summary) is the fallback.

Make it a cadence, not a one-off

Vendor risk changes over time. Track review dates and reassess on a schedule so your inventory stays current between audits.

FAQ

What evidence should I ask for?

A current SOC 2 Type II report or an ISO 27001 certificate is strongest. Otherwise, a completed security questionnaire plus supporting documents.

How often should I reassess a vendor?

At least annually for important vendors, and sooner after a material change (new data access, an acquisition) or a security incident.

Related

What is vendor risk management? → What is a security questionnaire? → Vendor risk in Keel →

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free