Template
Vendor Risk Assessment Questionnaire
A seven-step assessment across four parts, from inherent and control scores to residual risk, treatment, a FAIR-lite estimate and sign-off.
An editable 16-page form for turning due-diligence evidence into a residual-risk decision. Every step names its goal, the actions, the common mistake to avoid, and what done looks like.
What’s inside
- A readiness page capturing vendor, product or service, risk tier, assessment owner, business owner, target decision date and risk-register ID, plus the inputs, stakeholders and systems to line up first
- A seven-step workflow from scoring inherent risk with no controls assumed, through control effectiveness and residual risk, to treatment, FAIR-lite quantification, the register entry and sign-off
- A risk scoring worksheet across six domains (Security, Privacy, Operational, Financial, Concentration and Regulatory) with 1 to 5 impact and control-effectiveness scales
- A treatment decision record for Accept, Mitigate, Transfer or Avoid, and a FAIR-lite calculator for annualised loss expectancy
- A risk-register entry with a worked example, evidence and reviewer checklists, a red-flag table and the final sign-off block
The arithmetic is written down so two analysts get the same answer: residual equals inherent × (1 − control ÷ 5), banded Low to Critical, and the worst domain sets the overall result. Sign-off scales with the band, from the TPRM Analyst for Low up to the CISO, CRO and business owner for Critical, with board notification for DORA Critical ICT vendors.