Know which vendors can hurt you,
and prove you checked.
Every SaaS company runs on other companies' software. Auditors, regulators and enterprise customers all ask the same question: which of those suppliers touch your data or your service, and how do you know they are safe? This guide covers the process, and what each regime in the US, EU, UK, Australia and the UAE expects.
Last updated Published by TryTrustableNot legal advice
Vendor risk management is the process of knowing which suppliers can affect your data or your service, how much each one can hurt you, and whether the controls and contracts you rely on are actually in place. In practice it is a register of vendors, a tier for each based on the data and access it has, evidence collected in proportion to that tier (a security questionnaire, a SOC 2 report or ISO 27001 certificate, a data processing agreement), reviews on a schedule, and a clean exit when the relationship ends.
What is vendor risk management?
Vendor risk management, often called third-party risk management (TPRM), is how a company finds out which outside suppliers can affect its data, its customers or its ability to keep running, and keeps that risk at a level it has decided to accept. The two names are used for the same work; third-party risk is sometimes used more broadly to include partners, resellers and contractors as well as software vendors.
It matters because most breaches and outages that reach a SaaS company's customers start somewhere else: a compromised support tool, a misconfigured storage bucket at a processor, an identity provider outage. Your customers and regulators hold you responsible either way.
The vendor risk lifecycle
- Find every vendor. Finance records, SSO and expense tools, and your code's dependencies show what is actually in use, which is usually more than anyone listed.
- Tier each one by the data and access it has, not by what it costs.
- Assess in proportion. A critical vendor gets a full review; a low one gets a line in the register.
- Contract for it. Security terms, breach notice, audit rights, sub-processors and, where personal data is involved, a data processing agreement.
- Review on a schedule and after any incident at the vendor.
- Offboard cleanly: remove access, get data returned or deleted, and record the date.
How to tier vendors, and what to collect
| Tier | Typical vendor | What to collect | Review |
|---|---|---|---|
| Critical | Hosts your production data or runs your service: cloud provider, database, identity provider, payments | SOC 2 Type 2 report or ISO 27001 certificate, full security questionnaire, data processing agreement, sub-processor list, breach notice terms, exit plan | At least yearly, and on any incident |
| High | Processes customer personal data: CRM, support desk, email delivery, analytics | SOC 2 or ISO 27001 evidence, a shorter questionnaire, data processing agreement | Yearly |
| Medium | Internal data or limited access: HR tools, design tools, project management | Security page or trust center review, contract terms on confidentiality | Every two years |
| Low | No access to sensitive data or systems | A record that it exists and who owns it | On renewal |
A common starting point, not a rule. Tier by the data and access a vendor has, not by spend.
What regulators and frameworks ask, by market
The detail differs, but every regime below asks for the same core: know your vendors, assess them before you rely on them, put the obligations in a contract, and keep checking.
| Market | Rule | What it asks about vendors |
|---|---|---|
| Global | SOC 2, CC9.2 | Assess and manage risks from vendors and business partners, and monitor them |
| Global | ISO 27001:2022, Annex A 5.19 to 5.23 | Security in supplier relationships and agreements, the ICT supply chain, monitoring of supplier services, and use of cloud services |
| EU and UK | GDPR, Article 28 | Use only processors that give sufficient guarantees, under a written contract with the terms Article 28(3) lists, including sub-processor approval |
| EU | DORA (financial entities, from 17 January 2025) | A register of information on every contract with an ICT third-party provider, risk assessment before contracting, and exit strategies |
| EU | NIS2, Article 21(2)(d) | Supply chain security, including the security of relationships with direct suppliers |
| US | HIPAA | A business associate agreement with every vendor that handles protected health information |
| US | CCPA and CPRA | A written contract with each service provider and contractor that limits how it may use personal information |
| Australia | APRA CPS 230 (from 1 July 2025) | Manage material service providers, with a register, risk assessment and formal agreements |
| Australia | APRA CPS 234 | Assess the information security capability of third parties that manage your information assets |
| Australia | Privacy Act 1988, APP 8 and APP 11 | Take reasonable steps before disclosing personal information overseas, and protect it, including when a vendor holds it |
| UAE | Federal Decree-Law 45 of 2021 (PDPL) | Use processors that provide adequate safeguards and process only on the controller's instructions |
| UAE (Dubai) | DIFC Data Protection Law 2020 | A written contract with each processor, with the processor bound to the controller's instructions |
| India | DPDP Act, section 8(2) | Engage a Data Processor only under a valid contract; the Fiduciary stays responsible |
A summary to plan with, not legal advice. Check the current text with your counsel.
The vendor security questionnaire
A questionnaire is how you assess a vendor that has no independent report, and how you fill gaps in one that does. Keep it in proportion to the tier: a critical vendor with a current SOC 2 Type 2 report needs a short set of follow-up questions, not two hundred. Ask for evidence, not just yes or no, on the points that matter most: access control and MFA, encryption, logging, incident response and breach notice, sub-processors, and where data is stored. Our free vendor security questionnaire is a starting point.
How TryTrustable handles vendor risk
Vendor risk sits in the same platform as your controls, evidence and privacy records, so a vendor review counts toward every framework that asks for it. Here is what it does today.
| In the platform | What it does |
|---|---|
| Vendor register | Every vendor with an owner, a tier from critical to low, the data and access it has, spend and renewal date |
| Evidence on file | Whether you hold its SOC 2 report, ISO 27001 certificate, insurance certificate and a signed DPA |
| Reviews | A next review date for each vendor, with the reviews due this quarter and those overdue counted on the dashboard |
| Questionnaire tracking | Where each vendor's security questionnaire stands: not sent, sent, received or reviewed |
| Offboarding | Marks a vendor offboarded with the date, so the register shows who still has access |
| Processor register (privacy) | Contract reference and validity for each processor, its country checked against restricted destinations, and consent withdrawals sent to each processor with every delivery logged |
| AI vendors | A separate register for AI and model providers with an explainable 0 to 100 supply-chain risk score |
| Controls | Vendor controls mapped to SOC 2, ISO 27001, GDPR, DPDP and the other frameworks you run, so one review counts for all |
Questionnaires are tracked, not sent or scored automatically. Use the free template to send your own.
The things people ask us
What is the difference between vendor risk management and third-party risk management?
They are usually used for the same thing. Third-party risk management is sometimes used more broadly to cover partners, resellers and contractors as well as software and service vendors.
Does SOC 2 require vendor risk management?
Yes. Criterion CC9.2 asks you to assess and manage risks from vendors and business partners. Auditors look for a vendor list, a risk assessment of the important ones, contracts with security terms and evidence that you review them.
What does GDPR require when we use a vendor?
If the vendor processes personal data for you, Article 28 requires a processor that gives sufficient guarantees and a written contract with the terms the Article lists, including how sub-processors are approved.
What does DORA require for third-party risk?
Financial entities in the EU must keep a register of information on all contracts with ICT third-party service providers, assess risk before contracting, include required terms in the contracts and plan how to exit. DORA has applied since 17 January 2025.
What is APRA CPS 230?
An Australian prudential standard on operational risk for APRA-regulated entities, in force since 1 July 2025. It requires them to manage material service providers, with a register, risk assessment and formal agreements.
Does TryTrustable send and score vendor questionnaires automatically?
No. The platform tracks where each vendor's questionnaire stands and what evidence you hold, and gives you a free questionnaire template. Sending and reviewing the questionnaire is done by your team.
See your vendors, tiers and reviews in one register.
Thirty minutes on your vendor list and the frameworks you answer to: SOC 2, ISO 27001, GDPR, DORA, CPS 230 or the UAE PDPL.