Building a Third-Party Risk Assessment Framework from Scratch
You don't need a massive GRC suite to manage vendor risk. A practical framework with clear tiering, focused questionnaires, and automated monitoring gets you 80% of the value at 20% of the cost.
Start with tiering, not questionnaires
The most common mistake in building a TPRM program is treating all vendors the same. Sending a 500-question assessment to a vendor that only provides office supplies wastes everyone's time. Risk-based tiering ensures assessment depth matches actual risk.
How to tier vendors
Score each vendor across three dimensions:
- Data sensitivity — Does the vendor access PII, PHI, financial data, or intellectual property? Higher sensitivity = higher tier.
- Business criticality — Would a 24-hour outage at this vendor disrupt your operations? Could you switch providers quickly?
- Financial exposure — What's the contract value? What would a breach at this vendor cost you in regulatory fines, remediation, and reputation?
Design tier-appropriate assessments
Each risk tier gets a different assessment depth:
- Critical (full assessment) — 200-500 questions covering encryption, access controls, incident response, business continuity, compliance certifications, subprocessor management, and penetration testing evidence
- High (focused assessment) — 80-150 questions covering core security controls, data handling, and compliance status
- Medium (lightweight assessment) — 30-50 questions covering basic security hygiene and data access scope
- Low (self-attestation) — 10-15 yes/no questions confirming minimum security standards
Evidence over assertions
Questionnaire responses are claims. Evidence is proof. For critical and high-tier vendors, require supporting documentation:
- SOC 2 Type II report (not just Type I)
- ISO 27001 certificate with scope statement
- Penetration test executive summary (last 12 months)
- Business continuity / disaster recovery test results
- Data processing agreement or DPA
Track evidence freshness — a SOC 2 report from 18 months ago is stale. Set expiry policies and get notified when evidence needs refreshing.
Scoring that drives decisions
A scoring model turns subjective assessments into objective decisions. For each question category, define:
- Weight — How important is this category? Encryption matters more than office physical security for a SaaS vendor.
- Pass criteria — What answer constitutes an acceptable risk? Define thresholds, not just pass/fail.
- Finding generation — When a vendor falls below threshold, automatically create a finding with severity, remediation guidance, and deadline.
Continuous monitoring fills the gaps
Point-in-time assessments are snapshots. Between annual reviews, continuous monitoring catches:
- Domain posture changes (DMARC/SPF/DKIM degradation)
- SSL certificate expiry or misconfiguration
- Data breach notifications involving the vendor
- News events affecting vendor stability
- Contract renewal approaching without reassessment