TPRM Practical Resources
SIG-Aligned Vendor Assessment Checklist
23 questions for analyst-led vendor reviews, taken from the workbook questionnaire tab.
An editable 15-page checklist. Every question names the evidence to ask for and leaves space for the evidence reference, the reviewer’s notes and the follow-up action, with Yes, Partly, No and Not Applicable response options.
What’s inside
- 23 questions across 22 domains: governance, ownership, data, access, vulnerability management, logging, incident response, notification, resilience, recovery, subcontractors, assurance, contracts, exit, asset management, personnel, physical, privacy, continuity, audit, security testing and exceptions
- Evidence expectations such as a RACI matrix for ownership, RTO and RPO with recent test results for recovery, and a time-bound exception register
- A six-step workflow: set the scope, decide the review depth, send the applicable questions, validate the evidence, record the answer, close the loop
- What to do in four review situations: onboarding, renewal, a material change, and preparing an approval packet
- What to check when validating evidence: scope, date, control owner, test coverage, exceptions, and whether it applies to the service being assessed
- A worked example on a cloud support vendor, with five risk signals and three sample analyst notes
The last pages show the same review running on SAFE’s TPRM platform. See how SAFE handles TPRM.