Glossary

Supplier Risk Assessment

Evaluation of security and compliance risks with suppliers prior to collaboration.

A

B

C

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

S

A supplier risk assessment is the process of evaluating the security, compliance and operational risks associated with engaging a third-party supplier before and during the business relationship. It typically involves reviewing the supplier's security certifications, policies, incident history, financial stability and data processing practices, often supported by questionnaires, audits or independent assessment reports such as SOC 2.

The supplier risk assessment process:

  • Build a supplier inventory: Record every third party that processes your data, connects to your systems or supports a critical process. You cannot assess what you have not written down, and an incomplete register is the most common audit finding here.
  • Tier by criticality: Rank suppliers by the sensitivity of the data they touch and the impact of them failing. Tiering decides how deep each assessment goes: a payroll processor warrants far more scrutiny than an office supplier.
  • Send a proportionate questionnaire: Ask about security controls, subprocessors, data location, breach notification and continuity. Match the depth to the tier; a 200-question form sent to every supplier gets rushed answers and tells you little.
  • Review independent evidence: Certifications such as ISO 27001, audit reports such as SOC 2 Type II, and penetration test summaries carry more weight than self-declaration, because someone external has tested the claim.
  • Decide and record: Accept, accept with conditions, or reject. Document the residual risk and who approved it. This decision trail is what an auditor asks for, not the questionnaire itself.
  • Monitor and reassess: Set a review cadence per tier, and re-run the assessment on contract renewal, after an incident, or when the service materially changes.

ISO 27001:2022 covers this in Annex A controls A.5.19 to A.5.23, spanning supplier relationships, security within supplier agreements, the ICT supply chain, monitoring of supplier services, and cloud services. NIS2 makes supply chain security an explicit obligation under Article 21(2)(d), and DORA sets detailed third-party ICT risk requirements for financial entities. In practice most auditors look for three things: a maintained supplier register, evidence that assessments happened before onboarding rather than retrospectively, and a review cycle you can demonstrate.

Looking for a tool rather than a definition? See how Tidal Control automates supplier risk assessment: a supplier database that pre-fills certifications and policies, then scores and re-checks the risk for you.

T

U

V

W

Z

Frequently asked questions

What is a supplier risk assessment?
A supplier (or vendor) risk assessment is the process of evaluating the security, compliance and operational risks a third-party supplier could introduce, before and during your work with them.
Why should a business do a supplier risk assessment?
Suppliers can access your data and systems, so assessing their risk helps protect against breaches, meet framework requirements such as ISO 27001, NIS2 and DORA, and manage supply-chain risk.
What does a supplier risk assessment involve?
It typically involves reviewing a supplier’s security controls, certifications, data handling and financial stability, then assigning a risk level and defining any required safeguards.
What is the supplier risk assessment process?
Six steps: build an inventory of every third party that touches your data or systems, tier them by criticality, send a questionnaire proportionate to that tier, review independent evidence such as an ISO 27001 certificate or SOC 2 Type II report, record the accept-or-reject decision along with the residual risk and approver, then monitor and reassess on a set cadence.
How often should you reassess a supplier?
Frequency should follow the risk tier rather than a single fixed interval — critical suppliers annually, lower-risk suppliers less often. Reassess sooner on contract renewal, after a security incident, or when the service materially changes.
Which frameworks require a supplier risk assessment?
ISO 27001:2022 covers it in Annex A controls A.5.19 to A.5.23, NIS2 makes supply chain security an explicit obligation under Article 21(2)(d), and DORA sets third-party ICT risk requirements for financial entities. GDPR also requires due diligence on processors handling personal data.