SIG-Aligned Vendor Assessment Checklist - Safe Security

TPRM Practical Resources

SIG-Aligned Vendor Assessment Checklist

23 questions for analyst-led vendor reviews, taken from the workbook questionnaire tab.

An editable 15-page checklist. Every question names the evidence to ask for and leaves space for the evidence reference, the reviewer’s notes and the follow-up action, with Yes, Partly, No and Not Applicable response options.

What’s inside

  • 23 questions across 22 domains: governance, ownership, data, access, vulnerability management, logging, incident response, notification, resilience, recovery, subcontractors, assurance, contracts, exit, asset management, personnel, physical, privacy, continuity, audit, security testing and exceptions
  • Evidence expectations such as a RACI matrix for ownership, RTO and RPO with recent test results for recovery, and a time-bound exception register
  • A six-step workflow: set the scope, decide the review depth, send the applicable questions, validate the evidence, record the answer, close the loop
  • What to do in four review situations: onboarding, renewal, a material change, and preparing an approval packet
  • What to check when validating evidence: scope, date, control owner, test coverage, exceptions, and whether it applies to the service being assessed
  • A worked example on a cloud support vendor, with five risk signals and three sample analyst notes

The last pages show the same review running on SAFE’s TPRM platform. See how SAFE handles TPRM.