VND-001 Vendor Risk Assessment and Due Diligence
Description
A documented risk assessment is conducted for all third-party vendors, suppliers and service providers before engagement and periodically thereafter. The assessment evaluates security posture, privacy practices, regulatory compliance, financial stability and operational resilience. A register of all suppliers and supply chain relationships records each one's assessment status, a contact point for each direct supplier and service provider and the ICT products, services and processes each one provides. For suppliers of ICT products and components the assessment covers provenance and the supplier's controls against tampering, counterfeit components and malicious code insertion. A named cross-functional group owns the supply chain risk activity, with its members, their responsibilities and the activities it leads recorded. Findings are documented and inform the decision to engage or continue the relationship.
Rationale
Vendors with access to systems or data extend the organisation's attack surface, and formal due diligence creates a defensible record of proportionate risk management. Naming a group rather than a single owner reflects where the decisions actually sit: the security view, the contractual position, the commercial relationship and the operational dependency are held by different people, and an assessment owned by one of them alone tends to stop at that one dimension.
Applicability (9 profiles)
RTS 2024/1773 Art. 6(1) is the diligence a financial entity runs on the provider. Two of its criteria have no counterpart in the library: exposure to restrictive measures including embargos and sanctions under point (d) and ethical conduct, human rights, the prohibition of child labour, environmental protection and working conditions under point (f).
Annex point 5.1.1 requires a supply chain security policy as a named artefact in which the entity identifies its own role in the supply chain and communicates it to its direct suppliers. Point 5.1.2 adds the supplier secure development procedures and the ability to diversify sources and limit vendor lock-in as selection criteria. Point 5.2 adds two fields to the register, a contact point per supplier and the list of ICT products, services and processes each provides. Point 5.1.3 and Art. 21(3) require the results of an Art. 22 coordinated assessment to be taken into account once one is published.
Framework Mappings (42)
| STA-01 | Supply Chain Risk Management Policies and Procedures | partial |
| STA-08 | Supply Chain Inventory | full |
| STA-09 | Service Bill of Material (BOM) | partial |
| STA-10 | Supply Chain Risk Management | full |
| STA-16 | Supply Chain Data Security Assessment | full |
| STA-01 | Supply Chain Risk Management Policies and Procedures | partial |
| STA-08 | Supply Chain Inventory | full |
| STA-09 | Service Bill of Material (BOM) | partial |
| STA-10 | Supply Chain Risk Management | full |
| STA-16 | Supply Chain Data Security Assessment | full |
| DORA-Art.28.3 | Register of information on contractual arrangements | informative |
| DORA-Art.28.4 | Assessments before entering a contractual arrangement | informative |
| DORA-Art.29 | Preliminary assessment of ICT concentration risk at entity level | informative |
| DORA-RTS-2024/1773-Art.6.1 | Due diligence assessment of the prospective provider | informative |
| DORA-RTS-2024/1773-Art.6.2 | Required level of assurance on the provider's risk management | informative |
| GDPR-Art.28.1 | Processor Selection Due Diligence | full |
| HIPAA-164.308.b.2 | Subcontractor Assurances | full |
| HIPAA-164.314.a.2.i.B | Business Associate Contract Subcontractor Term | informative |
| 5.19 | Information security in supplier relationships | full |
| 5.21 | Managing information security in the ICT supply chain | partial |
| NIS2-Art.21.2.d | Supply Chain Security | partial |
| NIS2-Art.21.3 | Supplier-Specific Risk Factors in Supply Chain Measures | partial |
| NIS2-Art.22 | Union Level Coordinated Security Risk Assessments of Critical Supply Chains | informative |
| NIS2-CIR-5.1 | Supply Chain Security Policy | partial |
| NIS2-CIR-5.2 | Directory of Suppliers and Service Providers | full |
| NIS2-CIR-6.1 | Security in Acquisition of ICT Services or ICT Products | informative |
| PM-30 | Supply Chain Risk Management Strategy | partial |
| RA-3(1) | Risk Assessment | Supply Chain Risk Assessment | full |
| SA-1 | Policy and Procedures | partial |
| SA-9(1) | External System Services | Risk Assessments and Organizational Approvals | partial |
| SR-1 | Policy and Procedures | partial |
| SR-2 | Supply Chain Risk Management Plan | partial |
| SR-2(1) | Supply Chain Risk Management Plan | Establish SCRM Team | full |
| SR-3 | Supply Chain Controls and Processes | partial |
| SR-5 | Acquisition Strategies, Tools, and Methods | partial |
| SR-6 | Supplier Assessments and Reviews | full |
| SR-9 | Tamper Resistance and Detection | partial |
| GV-6.1-005 | Third-Party AI Risk Policies | GV-6.1-005 | partial |
| GV-6.1-007 | Third-Party AI Risk Policies | GV-6.1-007 | partial |
| MG-3.1-002 | Third-Party AI Risk Monitoring and Controls | MG-3.1-002 | partial |
| GOVERN 6.1 | Third-Party AI Risk Policies | partial |
| CC9.2 | Vendor and Business Partner Risk Management | full |
Evidence (4)
Completed vendor risk assessment reports for all in-scope third-party vendors, documenting security posture, privacy practices, and engagement decision.
Example: Vendor Risk Assessment reports (SecurityScorecard / internal questionnaire) for top-tier vendors, each covering: security posture score, privacy compliance assessment (GDPR DPA status), regulatory certifications (SOC 2 / ISO 27001), data handling practices, incident history, and risk-based engagement decision with DPO and CISO sign-off
Test: Request completed risk assessment reports for a sample of 5 critical vendors. Verify: (1) a risk assessment was completed before the vendor was engaged, (2) each assessment covers security, privacy, regulatory, and operational dimensions, (3) findings are documented with a risk rating, (4) decision to engage (or not) is signed off by an appropriate authority, (5) critical vendors have been reassessed within the last 12 months.
Current third-party security certifications (SOC 2 Type II, ISO 27001) obtained from key vendors as evidence of their security posture during due diligence.
Example: SOC 2 Type II reports or ISO 27001 certificates for critical vendors (e.g. cloud provider, CRM, payment processor), filed in the vendor management system with issuance dates confirming they were current at the time of the due diligence review
Test: Request vendor certification files for the 5 most critical vendors. Verify: (1) each critical vendor has provided a current SOC 2 Type II or ISO 27001 certificate (issued within 12 months), (2) the SOC 2 bridge letter is available where the report is more than 9 months old, (3) certificates are filed in the vendor management system with the associated vendor record.
Terms of reference and meeting records for the group that owns supply chain risk, naming its members, their functions and the activities it leads.
Example: Supply chain risk group terms of reference v2, minutes for 2026 H1
Test: Request the terms of reference and the meeting records. Verify: (1) the terms name the members by role and cover at least the security, legal, procurement and business-owner functions, (2) the activities the group leads are listed with an owner against each, (3) the group met at the interval its terms set and the minutes record decisions rather than attendance alone, (4) assessments completed during the period resolve to a decision the group recorded, (5) a vendor engaged during the period without the group's involvement is identified as an exception rather than passing unnoticed.
Export of the supplier register showing, for each direct supplier and service provider, its assessment status, a contact point and the ICT products, services and processes it provides.
Example: Supplier register export from the vendor management system, 2026-09-01, 212 entries
Test: Export the supplier register. Verify: (1) every supplier and service provider engaged during the period appears in the export, reconciled against accounts payable or the contract repository, (2) each entry carries an assessment status, a named contact point and the ICT products, services and processes it provides, (3) a sample of five entries reconciles to the executed contract or order for the products and services listed, (4) an entry with an empty contact point or product list is recorded as an exception with an owner rather than left blank, (5) the export date is within the register's documented refresh interval.
Questions (3)
Is a documented risk assessment conducted for each third-party vendor before engagement?
The assessment should be completed before the vendor is engaged and produce a documented risk rating and engagement decision signed off by an appropriate authority (e.g. CISO, DPO). Critical vendors should be reassessed at least annually.
What does the vendor risk assessment and supplier register cover?
A comprehensive pre-engagement assessment should cover at minimum: security posture, privacy compliance, certifications and incident history. Financial and operational resilience assessment is important for critical suppliers.
Is there a named cross-functional group that owns supply chain risk activity, with its members and their responsibilities recorded?
Answer yes only where the membership and the activities the group leads are written down rather than understood informally. A standing meeting with no terms of reference, or a group that exists on a slide and has not met, does not count.