VendorVigilance - Clinical Trial Vendor Management
All posts

Vendor Risk

Vendor Risk Assessment: Beyond the Questionnaire

Dejan Murko

At a glance

  • A vendor risk assessment is not a questionnaire you send. It is tiering, evidence, verification, scoring, and monitoring, of which the questionnaire is one input.
  • Tier first: not every vendor warrants the same depth, so segment by criticality and the sensitivity of what the vendor touches before assessing.
  • A vendor’s self-attestation is a single data point. Verification against evidence and independent signals is what makes the assessment trustworthy.
  • Due diligence should be commensurate with the risk and complexity of the relationship, the principle the recognised guidance repeats.
  • Assessment is continuous, not a one-time gate. Reassess on a cadence and when the relationship or the vendor changes.

This article is part of the vendor risk management cluster built on the vendor risk management framework; it covers the assessment step in depth.

What a vendor risk assessment actually is

Ask many teams to “do a vendor risk assessment” and they reach for a questionnaire: a long list of security and compliance questions, sent to the vendor, returned, and filed. The questionnaire has its place, but treating it as the assessment is the central mistake in third-party risk. An assessment is the whole judgement about how much risk a vendor creates and what to do about it, and the questionnaire is one input to that judgement, not the judgement itself.

The stakes are why the distinction matters. A weak assessment is not a paperwork failure; it is the reason an organisation ends up exposed to a vendor it never really understood. When a third party causes an outage, a breach, or a compliance failure, the first question asked, internally and externally, is what the organisation knew about that vendor’s risk and what it did about it. A genuine assessment answers that question with evidence. A filed questionnaire answers it with a document that, in hindsight, asked the right questions and verified none of the answers, which is a worse position than having done nothing, because it shows you looked and did not see.

A complete assessment does five things. It tiers the vendor by risk so the depth of work is proportionate. It gathers evidence, of which the vendor’s own responses are one source. It verifies that evidence rather than taking it at face value. It scores the result into a risk rating that drives a decision. And it monitors the vendor over time, because a point-in-time assessment goes stale. Skip any of these and you have an activity that looks like assessment without the assurance it is supposed to provide.

Tier before you assess

Not every vendor deserves the same scrutiny, and pretending otherwise wastes effort on low-risk providers while under-assessing the ones that matter. The recognised guidance is consistent on this. The 2023 Interagency Guidance on Third-Party Relationships states that due diligence should be commensurate with the level of risk and complexity of the third-party relationship, and NIST SP 800-161 frames supply-chain risk management as a risk-based activity rather than a uniform one. So the first step is to segment vendors, typically by how critical the service is and how sensitive the data or access involved is, into tiers that determine the depth of the assessment. A high-criticality vendor with access to sensitive data earns a deep assessment; a low-criticality vendor with none earns a light one. Tiering is what makes the rest of the process affordable and focused.

In practice tiering uses a small number of factors, and two do most of the work: how critical the service is to the business (could you operate without it, and for how long?), and how sensitive the data or access the vendor holds (regulated data, production systems, customer information). A vendor high on both is a top-tier assessment; one low on both is a light-touch review; the mixed cases fall in between. The tier then sets everything downstream, the depth of due diligence, whether verification beyond the questionnaire is required, and how often the vendor is reassessed. Getting tiering right is what lets a small team assess a large vendor population without either drowning in work or cutting corners on the vendors that actually matter.

Due diligence and the limits of self-attestation

With the tier set, due diligence gathers the evidence. For a high-tier vendor that includes far more than a questionnaire: financial-stability checks, review of certifications and audit reports, references, and examination of the vendor’s own controls against the requirements that matter. ISO/IEC 27036-2 frames this as assessing a supplier against defined requirements through its supplier selection and agreement processes, so the diligence is structured rather than ad hoc.

The crucial discipline is verification. A questionnaire is a vendor’s self-attestation, and a self-attestation is one data point, not proof. Mature assessment confirms key claims against evidence: a certification is checked, not just asserted; a control claim is supported by an audit report or a demonstration; questionnaire answers are compared against independent signals where available. The aim is not to assume bad faith but to recognise that an unverified claim carries little assurance, and that the assessment’s job is to produce assurance. Where a claim cannot be verified, that gap is itself a finding to be weighed.

A concrete example sharpens the point. A vendor’s questionnaire states that it encrypts data at rest and holds a current security certification. Verification means obtaining and reading the certification rather than trusting the checkbox, confirming that its scope actually covers the service you are buying (certifications are often scoped more narrowly than the buyer assumes), and, for a high-tier vendor, asking for supporting evidence such as a recent independent audit report. The questionnaire said the right things; verification establishes whether they are true and relevant. The difference is not paranoia. A breach traced to a vendor whose unverified attestation you relied on is still your incident to manage and explain.

Scoring and the risk decision

Evidence has to resolve into a decision. Scoring converts the gathered and verified evidence into a risk rating against criteria set in advance, so that the outcome, accept, accept with conditions or added controls, or do not proceed, is measured against a standard rather than a feeling. Defining the scoring method beforehand keeps assessments consistent across vendors and across the people who run them, and it makes the decision defensible. It also operationalises the guidance’s core instruction that diligence and decisions track the risk and complexity of the relationship: the score is how “commensurate with risk” becomes a concrete, repeatable judgement rather than a slogan. The output of the assessment is not a filed questionnaire; it is a rated risk and a documented decision about it.

Assessment is continuous

A vendor assessed once and never revisited is assessed against a world that has moved on. The lifecycle view in the Interagency Guidance is explicit that ongoing monitoring runs throughout the relationship, not just at onboarding. Reassessment should be triggered by time, on a cadence set by the vendor’s tier, and by change: a new service, a merger, a security incident, a shift in the data the vendor handles, or a degradation in performance. Continuous monitoring signals, where available, feed this directly, so that a vendor whose risk profile worsens is reassessed before the next scheduled review rather than after the next incident.

The practical reassessment model is the same one good programmes use elsewhere: a tiered interval plus event triggers, owned by a named person. The interval keeps top-tier vendors under regular re-examination; the triggers catch the changes that make a prior rating stale before its interval is up. Without an owner and a reminder, the calendar trigger is the one that silently fails, and an assessment that has quietly expired offers the same false comfort as no assessment at all.

Where vendor risk assessments go wrong

  • Questionnaire as the assessment. Treating the returned questionnaire as the finished product rather than one input.
  • No tiering. Assessing every vendor to the same depth, which over-spends on the harmless and under-assesses the critical.
  • No verification. Accepting self-attestation at face value, so the assessment records claims rather than assurance.
  • No scoring standard. Rating risk without pre-set criteria, so decisions are inconsistent and hard to defend.
  • One and done. Assessing at onboarding and never revisiting, so the rating ages out of usefulness.

The bottom line

A vendor risk assessment is a judgement, not a form. Tier the vendor so the effort is proportionate, gather evidence with the questionnaire as one input, verify the claims that matter, score against criteria set in advance, and reassess as the relationship changes. Do that and the assessment produces what it is for: a defensible, current view of how much risk a vendor carries and what you have decided to do about it. Treat it as a questionnaire to file and you will have documentation without assurance, which is the one thing an assessment exists to provide.

Sources

Dejan Murko

Dejan Murko

Dejan is the co-founder of Mayet, building software for biotech and pharma teams.