A vendor questionnaire is not the assessment. Useful due diligence starts with what the service will do, which data and systems it can access, how much the business depends on it, and what could go wrong. Evidence and contract terms should match that risk rather than applying the same checklist to every supplier.
Decision snapshot
| Decision | Practical approach | Watch for |
|---|---|---|
| Tier by inherent risk | Assess data sensitivity, privilege, connectivity, criticality, replaceability, and audience before selecting questions. | A newsletter tool and an identity provider do not deserve identical review depth. |
| Ask for evidence | Prefer current reports, architecture facts, test summaries, policies, and contract commitments over yes or no assurances. | Marketing claims may be broad, stale, or outside the purchased service scope. |
| Plan exit before entry | Define data export, deletion, transition assistance, credential revocation, and dependency replacement. | Vendor lock-in becomes a security and continuity problem during an incident. |
Describe the proposed use
Record service owner, business purpose, data categories and subjects, access level, integrations, regions, users, decision deadline, alternatives, and critical operations affected.
Assign risk tier and required evidence
Use confidentiality, integrity, availability, legal, safety, financial, and concentration impact to choose a light, standard, or enhanced review and approval level.
Evaluate control domains
Review governance, secure development, identity, encryption, tenant isolation, logging, vulnerability handling, workforce access, data lifecycle, subcontractors, resilience, and independent assurance.
Test incident and contract readiness
Clarify notification timing and content, cooperation, audit rights, liability, availability commitments, backup and recovery, data location, change notice, return and deletion, and termination support with qualified counsel.
Record and monitor the decision
List gaps, compensating controls, residual risk, approver, renewal date, evidence expiration, integration inventory, incidents, material service changes, and an exit trigger.
Action checklist
- Use case, owner, data flow, privilege, users, integrations, and criticality are documented
- Review depth is tied to inherent risk
- Claims are supported by current relevant evidence
- Contract addresses data use, incidents, continuity, subcontractors, and exit
- Gaps have mitigation, due date, accountable owner, and residual-risk approval
- Renewal includes evidence refresh, access review, performance, incidents, and alternatives
Working worksheet
Record these fields in the same working document so the decision can be reviewed and handed off:
- Vendor, service, owner, purpose, users, and alternatives
- Data, system access, integration, geography, and critical dependency
- Risk tier, control question, evidence, finding, and confidence
- Contract requirement, gap, compensating control, and approver
- Review date, renewal trigger, incident contact, export, deletion, and exit plan
Common failure patterns
- Accepting a certification logo without checking scope, date, and exceptions
- Letting procurement finish before security, privacy, operations, and legal review understand the use case
- Renewing automatically while old accounts, integrations, and data exports remain unexamined
Connect this work
Third-party copies belong in the data lifecycle. Read define vendor retention and deletion requirements.
Critical suppliers can be both incident source and response dependency. Read include vendors in escalation and evidence plans.
Vendor controls do not replace your own access and monitoring. Read fit supplier risk into the broader program.