## Purpose

Use this questionnaire before engaging an important vendor or when periodically reviewing an existing vendor.

The questionnaire should be proportionate to risk. A vendor hosting critical customer information may require a detailed assessment, while a low-risk supplier with no access to company systems may not.

## Vendor Information

Vendor name: ____________________

Service provided: ____________________

Internal owner: ____________________

Assessment date: ____________________

Reviewer: ____________________

Contract renewal date: ____________________

## Service Criticality

Would loss of this vendor seriously disrupt the business?

- Yes / No

If yes, describe:

---

## Data Access

**Does the vendor:**

- [ ]  Store company data?
- [ ]  Store customer data?
- [ ]  Store employee data?
- [ ]  Process financial information?
- [ ]  Process credentials or authentication information?
- [ ]  Access confidential business information?
- [ ]  Transfer company information to subcontractors?

Describe the information involved:

---

Where is the information stored?

---

## System Access

**Does the vendor have:**

- [ ]  Remote access?
- [ ]  VPN access?
- [ ]  Administrator access?
- [ ]  Cloud administrator access?
- [ ]  SaaS administrator access?
- [ ]  API access?
- [ ]  Access to production systems?
- [ ]  Access to backups?
- [ ]  Access to security tools?

Describe:

---

## Identity and Access Security

**Does the vendor:**

- [ ]  Use named user accounts?
- [ ]  Require MFA?
- [ ]  Restrict privileged access?
- [ ]  Review user access periodically?
- [ ]  Remove former employee access promptly?
- [ ]  Control service accounts and API credentials?
- [ ]  Log important administrative activity?

Comments:

---

## Device and System Security

**Does the vendor:**

- [ ]  Maintain supported operating systems?
- [ ]  Apply security patches?
- [ ]  Use endpoint protection?
- [ ]  Use secure configuration standards?
- [ ]  Perform vulnerability scanning?
- [ ]  Protect administrative devices appropriately?

Comments:

---

## Data Protection

**Does the vendor:**

- [ ]  Encrypt sensitive data in transit?
- [ ]  Encrypt sensitive data at rest where appropriate?
- [ ]  Restrict employee access to customer data?
- [ ]  Control external sharing?
- [ ]  Have data retention procedures?
- [ ]  Have secure data deletion procedures?

Comments:

---

## Backup and Recovery

**Does the vendor:**

- [ ]  Back up important customer data?
- [ ]  Protect backups from deletion or ransomware?
- [ ]  Test restoration?
- [ ]  Maintain business continuity arrangements?
- [ ]  Define expected recovery times?

Recovery information:

---

## Logging and Monitoring

**Does the vendor:**

- [ ]  Maintain security logs?
- [ ]  Monitor suspicious activity?
- [ ]  Monitor privileged activity?
- [ ]  Retain logs for an appropriate period?
- [ ]  Have a process for security alert escalation?

Comments:

---

## Incident Response

**Does the vendor have:**

- [ ]  An incident response plan?
- [ ]  A security incident contact?
- [ ]  A process for notifying customers of relevant incidents?
- [ ]  Defined escalation procedures?
- [ ]  A process for preserving evidence?

Vendor security contact:

---

Incident notification method:

---

## Subcontractors

Does the vendor use subcontractors or sub-processors?

- Yes / No

If yes:

What services do they provide?

---

Can they access company data?

- Yes / No / Unknown

How are they assessed?

---

## Security Assurance

Does the vendor have any relevant independent assurance?

Examples:

- ISO 27001
- SOC 2
- PCI DSS
- Cyber Essentials
- Penetration testing
- Independent security assessment
- Other: ____________________

Evidence reviewed:

---

Certifications should support the assessment, not replace it.

## Previous Incidents

Has the vendor disclosed significant cybersecurity incidents relevant to the service?

- Yes / No / Unknown

If yes:

---

## Contractual Controls

**Does the contract address:**

- [ ]  Confidentiality?
- [ ]  Data protection?
- [ ]  Security requirements?
- [ ]  Incident notification?
- [ ]  Subcontractors?
- [ ]  Data return or deletion?
- [ ]  Termination?
- [ ]  Business continuity?
- [ ]  Access removal?

## Assessment Result

**Risk level:**

- Low / Medium / High / Critical

**Decision:**

- Approve
- Approve with conditions
- Further review required
- Reject

## Required Improvements

Action: ____________________

Owner: ____________________

Due date: ____________________

Evidence required: ____________________

## Next Review

Next review date: ____________________

Approved by: ____________________

## Practical Rule

Ask deeper questions when the vendor has deeper access to the company.
