๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

Third-Party Vendor Risk Assessment Checklist for Security Teams

September 19, 2026 ยท PlayCISO

A third-party vendor risk assessment checklist is the structured set of questions and evidence requests you use to evaluate a vendor's security, compliance, and operational posture before granting access to your data or systems. At minimum it should cover data handling, access controls, compliance certifications, incident history, subprocessors, and offboarding. Below is a checklist you can adapt directly, organized by the stages of a vendor relationship rather than a generic questionnaire dump.

Before you onboard: scope and classify

Not every vendor needs the same depth of review. Start by classifying the vendor based on what they touch, then match your effort to the risk.

  • Data access: What data will they store, process, or transmit? Flag anything involving PII, PHI, cardholder data, or source code.
  • System access: Will they have network, API, or admin access to your environment?
  • Criticality: If this vendor goes down, what breaks? Rank as critical, important, or low-impact.
  • Regulatory scope: Does the engagement fall under GDPR, HIPAA, PCI DSS, or contractual obligations from your own customers?

Security and compliance evidence to collect

Request evidence, not just attestations. A vendor claiming they are "secure" means nothing without documentation you can review.

  • Compliance reports: SOC 2 Type II, ISO 27001, PCI AOC, or HIPAA attestations as relevant. Read the report โ€” don't just confirm it exists.
  • Data protection: Encryption at rest and in transit, key management, data residency, and retention policies.
  • Access controls: MFA enforcement, least-privilege model, and how they manage their own privileged accounts.
  • Vulnerability management: Patch cadence, penetration test summaries, and how they handle disclosed vulnerabilities.
  • Incident response: Breach notification timelines, their IR plan, and any history of security incidents.
  • Subprocessors: A current list of their fourth parties and how they assess them. Their supply chain is now yours.

Contractual and legal controls

Technical review is only half the job. The contract is where you make security enforceable.

  • Breach notification clause with a defined maximum timeframe.
  • Right to audit or to receive updated compliance reports annually.
  • Data processing agreement covering ownership, use limits, and deletion on termination.
  • Liability and cyber insurance minimums appropriate to the data at stake.
  • Termination and data return/destruction requirements in writing.

Ongoing monitoring and offboarding

A one-time assessment goes stale fast. Vendors change ownership, add subprocessors, and drift out of compliance. Build in continuous checks.

  • Reassessment cadence: Annual for critical vendors, less often for low-impact ones.
  • Continuous signals: Track breach news, expired certifications, and changes to their subprocessor list.
  • Access reviews: Periodically confirm the vendor still needs the access they hold.
  • Offboarding checklist: Revoke credentials, confirm data deletion, retrieve or destroy shared assets, and document the closure.

If you're triaging a large vendor list and need a fast way to decide who gets the full assessment first, PlayCISO's free Vendor Risk Ranking tool helps you prioritize vendors by risk so your team spends its time where it matters most.

Ready to practise the decisions these articles describe?

Run a free War Room โ†’