Third-Party Vendor Risk Assessment Policy Template

This template establishes a repeatable process for assessing the security risk a new vendor introduces before, and after, they’re onboarded.

Format: Ready to copy into your own documentCustomize: Replace bracketed placeholders with your organization’s details

1. Purpose

This policy establishes a consistent process for assessing and monitoring the security risk introduced by third-party vendors with access to [Organization Name] systems or data.

2. Vendor Risk Tiers

  • High Risk: Vendors with access to Restricted data or critical systems
  • Medium Risk: Vendors with access to Confidential data or limited system access
  • Low Risk: Vendors with no access to sensitive data or systems

3. Pre-Onboarding Due Diligence

Before contracting with a High or Medium Risk vendor, [Security/Procurement] will require evidence of the vendor’s security posture, such as a SOC 2 report, security questionnaire responses, or equivalent documentation.

4. Contractual Requirements

Contracts with High and Medium Risk vendors must include data protection terms, breach notification obligations within [timeframe], and the right to audit where appropriate.

5. Ongoing Monitoring

High Risk vendors are reassessed at minimum [annually]; Medium Risk vendors at minimum [every two years]. Any material change in a vendor’s service or a public security incident affecting the vendor triggers an off-cycle review.

6. Vendor Inventory

[Owner/team] maintains a current inventory of all active vendors, their risk tier, and their data access scope.

7. Offboarding

Upon contract termination, vendor access to systems and data is revoked within [timeframe], and the vendor must confirm secure deletion or return of any organizational data in their possession.

Want this built and implemented for your organization?

A template is a starting point. Cyberix builds, customizes, and maintains policies like this as part of a full GRC engagement.

See Cyber Risk Assessments →