Vendor risk management

Know which vendors can hurt you,
and prove you checked.

Every SaaS company runs on other companies' software. Auditors, regulators and enterprise customers all ask the same question: which of those suppliers touch your data or your service, and how do you know they are safe? This guide covers the process, and what each regime in the US, EU, UK, Australia and the UAE expects.

SOC 2 CC9.2ISO 27001 A.5.19 to A.5.23GDPR Art. 28DORANIS2APRA CPS 230UAE PDPL

Last updated Published by TryTrustableNot legal advice

Short answer

Vendor risk management is the process of knowing which suppliers can affect your data or your service, how much each one can hurt you, and whether the controls and contracts you rely on are actually in place. In practice it is a register of vendors, a tier for each based on the data and access it has, evidence collected in proportion to that tier (a security questionnaire, a SOC 2 report or ISO 27001 certificate, a data processing agreement), reviews on a schedule, and a clean exit when the relationship ends.

01

What is vendor risk management?

Vendor risk management, often called third-party risk management (TPRM), is how a company finds out which outside suppliers can affect its data, its customers or its ability to keep running, and keeps that risk at a level it has decided to accept. The two names are used for the same work; third-party risk is sometimes used more broadly to include partners, resellers and contractors as well as software vendors.

It matters because most breaches and outages that reach a SaaS company's customers start somewhere else: a compromised support tool, a misconfigured storage bucket at a processor, an identity provider outage. Your customers and regulators hold you responsible either way.

02

The vendor risk lifecycle

  1. Find every vendor. Finance records, SSO and expense tools, and your code's dependencies show what is actually in use, which is usually more than anyone listed.
  2. Tier each one by the data and access it has, not by what it costs.
  3. Assess in proportion. A critical vendor gets a full review; a low one gets a line in the register.
  4. Contract for it. Security terms, breach notice, audit rights, sub-processors and, where personal data is involved, a data processing agreement.
  5. Review on a schedule and after any incident at the vendor.
  6. Offboard cleanly: remove access, get data returned or deleted, and record the date.
03

How to tier vendors, and what to collect

TierTypical vendorWhat to collectReview
CriticalHosts your production data or runs your service: cloud provider, database, identity provider, paymentsSOC 2 Type 2 report or ISO 27001 certificate, full security questionnaire, data processing agreement, sub-processor list, breach notice terms, exit planAt least yearly, and on any incident
HighProcesses customer personal data: CRM, support desk, email delivery, analyticsSOC 2 or ISO 27001 evidence, a shorter questionnaire, data processing agreementYearly
MediumInternal data or limited access: HR tools, design tools, project managementSecurity page or trust center review, contract terms on confidentialityEvery two years
LowNo access to sensitive data or systemsA record that it exists and who owns itOn renewal

A common starting point, not a rule. Tier by the data and access a vendor has, not by spend.

04

What regulators and frameworks ask, by market

The detail differs, but every regime below asks for the same core: know your vendors, assess them before you rely on them, put the obligations in a contract, and keep checking.

MarketRuleWhat it asks about vendors
GlobalSOC 2, CC9.2Assess and manage risks from vendors and business partners, and monitor them
GlobalISO 27001:2022, Annex A 5.19 to 5.23Security in supplier relationships and agreements, the ICT supply chain, monitoring of supplier services, and use of cloud services
EU and UKGDPR, Article 28Use only processors that give sufficient guarantees, under a written contract with the terms Article 28(3) lists, including sub-processor approval
EUDORA (financial entities, from 17 January 2025)A register of information on every contract with an ICT third-party provider, risk assessment before contracting, and exit strategies
EUNIS2, Article 21(2)(d)Supply chain security, including the security of relationships with direct suppliers
USHIPAAA business associate agreement with every vendor that handles protected health information
USCCPA and CPRAA written contract with each service provider and contractor that limits how it may use personal information
AustraliaAPRA CPS 230 (from 1 July 2025)Manage material service providers, with a register, risk assessment and formal agreements
AustraliaAPRA CPS 234Assess the information security capability of third parties that manage your information assets
AustraliaPrivacy Act 1988, APP 8 and APP 11Take reasonable steps before disclosing personal information overseas, and protect it, including when a vendor holds it
UAEFederal Decree-Law 45 of 2021 (PDPL)Use processors that provide adequate safeguards and process only on the controller's instructions
UAE (Dubai)DIFC Data Protection Law 2020A written contract with each processor, with the processor bound to the controller's instructions
IndiaDPDP Act, section 8(2)Engage a Data Processor only under a valid contract; the Fiduciary stays responsible

A summary to plan with, not legal advice. Check the current text with your counsel.

05

The vendor security questionnaire

A questionnaire is how you assess a vendor that has no independent report, and how you fill gaps in one that does. Keep it in proportion to the tier: a critical vendor with a current SOC 2 Type 2 report needs a short set of follow-up questions, not two hundred. Ask for evidence, not just yes or no, on the points that matter most: access control and MFA, encryption, logging, incident response and breach notice, sub-processors, and where data is stored. Our free vendor security questionnaire is a starting point.

06

How TryTrustable handles vendor risk

Vendor risk sits in the same platform as your controls, evidence and privacy records, so a vendor review counts toward every framework that asks for it. Here is what it does today.

In the platformWhat it does
Vendor registerEvery vendor with an owner, a tier from critical to low, the data and access it has, spend and renewal date
Evidence on fileWhether you hold its SOC 2 report, ISO 27001 certificate, insurance certificate and a signed DPA
ReviewsA next review date for each vendor, with the reviews due this quarter and those overdue counted on the dashboard
Questionnaire trackingWhere each vendor's security questionnaire stands: not sent, sent, received or reviewed
OffboardingMarks a vendor offboarded with the date, so the register shows who still has access
Processor register (privacy)Contract reference and validity for each processor, its country checked against restricted destinations, and consent withdrawals sent to each processor with every delivery logged
AI vendorsA separate register for AI and model providers with an explainable 0 to 100 supply-chain risk score
ControlsVendor controls mapped to SOC 2, ISO 27001, GDPR, DPDP and the other frameworks you run, so one review counts for all

Questionnaires are tracked, not sent or scored automatically. Use the free template to send your own.

Questions

The things people ask us

What is the difference between vendor risk management and third-party risk management?

They are usually used for the same thing. Third-party risk management is sometimes used more broadly to cover partners, resellers and contractors as well as software and service vendors.

Does SOC 2 require vendor risk management?

Yes. Criterion CC9.2 asks you to assess and manage risks from vendors and business partners. Auditors look for a vendor list, a risk assessment of the important ones, contracts with security terms and evidence that you review them.

What does GDPR require when we use a vendor?

If the vendor processes personal data for you, Article 28 requires a processor that gives sufficient guarantees and a written contract with the terms the Article lists, including how sub-processors are approved.

What does DORA require for third-party risk?

Financial entities in the EU must keep a register of information on all contracts with ICT third-party service providers, assess risk before contracting, include required terms in the contracts and plan how to exit. DORA has applied since 17 January 2025.

What is APRA CPS 230?

An Australian prudential standard on operational risk for APRA-regulated entities, in force since 1 July 2025. It requires them to manage material service providers, with a register, risk assessment and formal agreements.

Does TryTrustable send and score vendor questionnaires automatically?

No. The platform tracks where each vendor's questionnaire stands and what evidence you hold, and gives you a free questionnaire template. Sending and reviewing the questionnaire is done by your team.

Book a walkthrough

See your vendors, tiers and reviews in one register.

Thirty minutes on your vendor list and the frameworks you answer to: SOC 2, ISO 27001, GDPR, DORA, CPS 230 or the UAE PDPL.