← Third-Party Risk
Version 2.6Updated Aug 04, 2026

Vendor Security Review Kit

Move vendor reviews from questionnaire collection to risk decisions. The kit includes scoping rules, tiered evidence requests, assessor prompts, compensating-control guidance, and a concise acceptance record that gives procurement and security a shared operating model.

vendorsassessmentevidenceprocurement
Inside the document
  1. 01Inherent-risk scoping model
  2. 02Tiered evidence request list
  3. 03Assessor interview prompts
  4. 04Finding severity and treatment rules
  5. 05Risk acceptance record

Review for the decision

The kit scales evidence requirements to the access, data, and business dependency the vendor will actually have.

Less friction, stronger records

  • Shorter reviews for low-risk suppliers
  • Deeper validation where failure matters
  • Shared thresholds for procurement and security
  • A durable record of the final risk decision