Executive self-assessment

Vendor Risk Management Maturity Assessment

Measure whether vendor reviews are proportionate, decision-oriented, and connected to critical business dependencies.

Result logic

What this tool evaluates

Evaluates vendor inventory, tiering, due diligence, evidence, contracts, exceptions, monitoring, concentration, and exit.

Inventory & ownership 18%
Risk tiering 20%
Due diligence 24%
Contract & exceptions 18%
Monitoring & resilience 20%
0 / 10
0%
01 Is there a current vendor inventory with service, business owner, data/access, and criticality?
02 Are new vendors routed through a defined security/privacy review before material use?
03 Are vendors risk-tiered before deciding questionnaire depth and evidence requirements?
04 Do tiering criteria consider sensitive data, privileged access, criticality, connectivity, regulatory impact, and substitutability?
05 Are security claims validated using proportionate evidence rather than questionnaire answers alone?
06 Are material findings assigned to an owner with remediation, acceptance, escalation, or rejection decisions?
07 Are critical security, incident, privacy, resilience, subcontractor, audit, and deletion terms addressed contractually?
08 Do vendor-risk exceptions have an accountable approver, rationale, compensating controls, and expiry date?
09 Are critical vendors re-reviewed based on risk and material change triggers?
10 Are concentration, business continuity, recovery, and exit dependencies understood for critical suppliers?