Vendor Risk Assessment
A vendor risk assessment is the process an organization uses to identify and evaluate the risks that come from working with an outside vendor, supplier, or service provider. It typically looks at issues such as cybersecurity exposure and other risks a third-party relationship may introduce, so the organization can decide how to manage or reduce them. It is an evaluation activity, not a certification or a guarantee that a vendor is risk-free.
A vendor risk assessment is a systematized process for identifying, scoring, prioritizing, and monitoring the risks associated with a third-party vendor, supplier, or service provider relationship, commonly including the cyber risk posed by that relationship. It is generally conducted as part of a broader third-party risk management (TPRM) program and may draw on questionnaires, evidence review, and ongoing monitoring to inform onboarding and continuity decisions. As an assessment, it is distinct from an audit and from formal certification: it produces an internal evaluation of risk rather than an attestation against a defined standard. The specific scope, methodology, and frequency are organization-defined and vary by vendor criticality, data category, and applicable contractual or regulatory obligations; practitioners should align a given VRA with the framework or requirements relevant to their sector and jurisdiction and verify against current authoritative sources.
Why it matters
Organizations increasingly depend on outside vendors, suppliers, and service providers for functions that touch sensitive data, critical systems, and core operations. Each of these relationships can introduce risk that the organization does not directly control, including cybersecurity exposure arising from the vendor's own practices. A vendor risk assessment gives an organization a structured way to identify and evaluate that exposure before onboarding a vendor and throughout the relationship, so decisions about whether and how to engage are informed by an understanding of the risks involved rather than by assumption.
Who it's relevant to
Inside VRA
Common questions
Answers to the questions practitioners most commonly ask about VRA.

