Home About
Vendor Management
Procurement
Reviews & Compare
Request Demo →
📋 Cluster 5 — Vendor Risk Management

Vendor Risk Assessment Template: Free Framework & Scoring Guide 2026

A structured risk assessment template ensures every vendor is evaluated consistently — with the right questions, the right scoring methodology, and a clear risk register that satisfies auditors and regulators. Here is the complete framework.

📅 Updated June 2026⏱ 11 min read📥 Free Download Available✅ Scoring Methodology Included

☰ Contents

  1. 5-Domain Assessment Framework
  2. Scoring Methodology
  3. Sample Questionnaire Items by Domain
  4. Vendor Risk Register Structure
  5. Risk Threshold Definitions

5-Domain Vendor Risk Assessment Framework

A rigorous vendor risk assessment evaluates five distinct risk domains. Domain weights should be adjusted based on vendor type — technology vendors receive higher cybersecurity weighting; manufacturing suppliers receive higher operational resilience weighting.

DomainDefault WeightIncrease Weight ForKey Questions
Cybersecurity & Data Privacy30%Technology, SaaS, data-access vendorsSOC 2 status, security questionnaire score, cyber risk rating, DPA execution
Financial & Operational25%Sole-source, critical-path vendorsD&B score, revenue concentration, BCP maturity, key person risk
Regulatory & Compliance20%Healthcare, financial services, governmentLicence status, enforcement history, HIPAA/FCPA compliance
Reputational & ESG15%High-profile, consumer-facing vendorsAdverse media, modern slavery, environmental policy, labour practices
Geopolitical & Concentration10%Manufacturing, direct materialsPrimary country, alternative supplier availability, geographic concentration

Scoring Methodology

Question-Level Scoring (0–3 Scale)

ScoreMeaningExample Response
3 — Low RiskBest practice; fully documented; externally verifiedSOC 2 Type II report current, issued by Big 4 auditor
2 — Moderate RiskAdequate; documented but not externally verifiedInternal security policy exists; not independently audited
1 — Elevated RiskPartial or informal; gaps identifiedNo formal policy; relies on individual judgement
0 — High RiskMissing; non-compliant; or unable to evidenceNo response provided; explicitly non-compliant

Composite Score Calculation

Composite Risk Score = Σ (Domain Score × Domain Weight). Domain Score = Average of all question scores within the domain × 33.3 (to produce a 0–100 scale). Combine the questionnaire composite score with external data scores (D&B, BitSight) using a 70/30 split: 70% questionnaire responses, 30% external data.

💡 Automation Note

Manual risk scoring from questionnaire responses takes 2–4 hours per vendor. Automated VRM platforms score questionnaire responses in real time as vendors complete the portal — reducing analyst review time to 20–30 minutes for standard assessments.

Sample Questionnaire Items by Domain

Cybersecurity Domain — Sample Questions

Financial Domain — Sample Questions

Compliance Domain — Sample Questions

🚀 Free Executive Demo

Automate Risk Assessments with Procurement VMS

Join US procurement leaders who replaced manual processes with intelligent automation. Live in 4–8 weeks.

Request Your Executive Demo → Calculate Your ROI
🔒 SOC 2 Type II ⚡ Live in 4–8 Weeks 🇺🇸 US-Based Support

Vendor Risk Register Structure

FieldDescriptionExample
Vendor NameLegal entity nameAcme Cloud Services, Inc.
Vendor IDUnique identifier in vendor masterVND-004821
Risk DomainWhich of the 5 domainsCybersecurity
Risk DescriptionSpecific risk identifiedNo SOC 2 report; self-attested security only
Inherent Risk LevelRisk before controls (High/Medium/Low)High
Mitigating ControlsControls in place that reduce inherent riskAnnual security questionnaire; contractual audit rights
Residual Risk LevelRisk after controls (High/Medium/Low)Medium
Risk OwnerNamed individual accountable for this riskJane Smith, IT Security Manager
Treatment DecisionAccept / Mitigate / Transfer / AvoidMitigate — require SOC 2 within 12 months
Treatment Due DateDeadline for treatment implementationDec 31, 2026
Next Review DateWhen risk will be formally re-assessedJan 15, 2027

Risk Threshold Definitions

Score RangeRisk LevelRequired Action
85–100Low RiskApprove; standard annual monitoring
70–84Moderate RiskApprove with documented acceptance; flag for enhanced monitoring
50–69Elevated RiskApprove only with documented treatment plan and owner assignment
30–49High RiskHold pending treatment; escalate to CPO and Legal
0–29Critical RiskDo not approve; escalate to executive team; consider relationship termination

Related Resources

→ Vendor Risk Management Complete Guide→ 50-Point Due Diligence Checklist→ Vendor Compliance Management→ Vendor Scorecard Template→ Vendor Onboarding Guide
FAQ

Frequently Asked Questions

A vendor risk assessment template is a standardised questionnaire and scoring framework used to evaluate a vendor's risk posture across multiple domains — cybersecurity, financial health, operational resilience, regulatory compliance, and ESG — and produce a composite risk score and tier classification.

Score vendor risk assessments by assigning weighted scores to questionnaire responses (0–3 per question), applying domain weights based on vendor type (cybersecurity weighted higher for technology vendors), combining with external data scores (D&B, BitSight), and calculating a composite score. Scores above a defined threshold trigger enhanced review or risk treatment planning.

A vendor risk register is a structured document or database record that captures identified risks for each vendor — the risk description, domain, inherent risk level, mitigating controls, residual risk level, risk owner, treatment decision, and review date. It is the primary evidence document for your TPRM programme.

Tier 1 (critical) vendors: annual formal reassessment plus continuous monitoring. Tier 2: annual reassessment. Tier 3: every 2–3 years. Triggered reassessment for any vendor following: a significant security incident, ownership or leadership change, material expansion of data access, or a regulatory enforcement action.

See It In Action

Join the Procurement Leaders Who Have Replaced Manual Processes With Intelligent Automation

Schedule an executive demo tailored to your industry, organizational size, and specific procurement priorities. No generic product tours — every demo is built around your use case.