What is a third-party risk assessment?
A structured evaluation of the risk a supplier introduces: what they do for you, what they can reach, what happens if they stop, and whether their own security is adequate for that exposure. It is performed before onboarding and repeated on a cycle, because a supplier's risk changes without anyone telling you.
The output is a decision, not a document. Onboard, onboard with conditions, or do not onboard. A programme that produces assessments but never refuses anything is producing paperwork.
Tiering: the step that makes it finishable
Almost every stalled third-party programme has the same cause: a single assessment process applied to every supplier. The queue grows, the business starts onboarding without you, and the register drifts out of date.

| Tier | What it means | Assessment depth |
|---|---|---|
| Tier 1 | Supports a critical or important function, or holds sensitive data at scale | Full assessment: evidence review, questionnaire, contract clause check, exit plan, annual re-assessment |
| Tier 2 | Material but replaceable, limited data exposure | Questionnaire plus certification check, re-assessed every two years or on change |
| Tier 3 | Low impact, no sensitive data, easily replaced | Register the supplier, screen it, review on material change |
Getting the tier right is more valuable than getting the score right. A wrong tier means you spent a week on a stationery supplier and a morning on the company hosting your production database.
What most guides get wrong
They treat the questionnaire as the assessment. A questionnaire is one input, and it is self-reported. It tells you what the supplier believes about itself. Certifications, penetration test summaries, contract terms and your own knowledge of what they can reach are the other inputs, and several of them are more reliable.
They stop at onboarding. The assessment that matters is the second one, eighteen months later, when the supplier has been acquired, moved its hosting, or lost the security lead who answered your questionnaire. Programmes that only assess at onboarding are measuring the past.
What to assess, by tier
| Area | What you are establishing | Applies from |
|---|---|---|
| Service and dependency | What they do, which of your functions depend on it, what breaks if they stop | All tiers |
| Data exposure | What personal or confidential data they hold, process or can reach | All tiers |
| Access | Whether their staff hold access to your systems, and at what level | All tiers |
| Security posture | Certifications held, scope of those certifications, test results | Tier 1 and 2 |
| Sub-processors | Who they depend on, and whether that concentrates risk you already carry | Tier 1 |
| Contract terms | Security obligations, audit rights, incident notification, termination, exit | Tier 1, and Tier 2 where data is involved |
| Concentration | Whether too much now rests on this one supplier | Tier 1 |
| Exit | How you would leave, how long it would take, what you would lose | Tier 1 |

Seven steps

1. Inventory the suppliers you actually have
Start from accounts payable rather than from the contract folder. Every programme discovers suppliers nobody in security had heard of, and the ones bought on a card are frequently the ones holding data.
2. Tier by criticality
Ask one question per supplier: what happens to our business if they stop tomorrow? That answer, not the contract value, sets the tier.
3. Set assessment depth by tier
Decide in advance what each tier requires, and hold the line. This is the policy decision that stops the queue.
4. Gather evidence, not just answers
Request the certification and read the scope statement, because a certificate covering a different entity or a narrow scope is common and easy to miss. Send the questionnaire, sized to the tier. Pull the contract.
5. Score consistently and record the reasoning
Two people assessing the same supplier should reach a similar answer. If they do not, the model is too subjective.
6. Decide, and attach conditions
Approve, approve with conditions, or refuse. Conditions are where most of the value is: MFA on their access, a notification clause added at renewal, a named security contact.
7. Re-assess on a cycle, and on triggers
Annually for Tier 1, and out of cycle whenever the supplier is acquired, suffers an incident, changes sub-processors or materially changes what it does for you.
Book a 30 minute session. Bring your supplier list and we will tier it live, set the depth per tier, and score your top ten together. You keep the output either way.
Book a walkthrough
Scoring without inventing a methodology
You do not need a bespoke model. You need a small number of signals, applied consistently, with the reasoning recorded. Venvera scores each ICT provider on five: criticality, geographic risk, concentration, contract health and data sensitivity, weighted, and re-scores automatically when the underlying data changes.
The property that matters is not sophistication, it is that the score moves when reality moves. A score computed once during onboarding and never recomputed is a historical artefact.

What the frameworks actually require
| Framework | The obligation |
|---|---|
| DORA | Article 28 requires ICT third-party risk management as part of the risk framework, with a register of information and preliminary assessment of concentration risk under Article 29 |
| NIS2 | Article 21(d) requires supply chain security, taking account of the vulnerabilities and security practices of each direct supplier |
| ISO 27001 | Annex A supplier relationship controls, covering security in agreements and monitoring of supplier service delivery |
| SOC 2 | Common criteria covering vendor and business partner risk management |
| GDPR | Article 28 requires processors to provide sufficient guarantees, which is a due diligence obligation on you |
The overlap is large, so a single assessment properly evidenced can answer all of them. Doing a separate exercise per framework is the most expensive way to reach the same position. For the DORA-specific detail, see building a compliant vendor register from scratch.
Common mistakes
- Assessing everyone identically. The cause of most stalled programmes.
- Accepting a certificate without reading its scope. A certificate for another group entity, or covering one product line, is not coverage of your service.
- Never refusing anything. If nothing is ever refused or conditioned, the assessment is not influencing decisions.
- Ignoring sub-processors. Two suppliers depending on the same sub-processor is concentration you did not know you had.
- Assessing at onboarding only. The risk profile you captured is the one from the day you signed.
- Sending a 300-question form to a four-person vendor. Covered in vendor security questionnaires.
Do this in Venvera
Venvera holds the supplier register with five-signal scoring that recalculates when the data changes, concentration analysis across providers and sub-processors, contract clause tracking, questionnaire campaigns, and the evidence mapped to the DORA, NIS2, ISO 27001, SOC 2 and GDPR obligations above. See third-party risk management, or download the free vendor risk assessment template if you would rather start in a spreadsheet.
We will tier it with you in 30 minutes, set the assessment depth per tier, and show you where your concentration actually sits.
Book a working sessionFrequently asked questions
How do you perform a third-party risk assessment?
Inventory your suppliers from accounts payable rather than the contract folder, tier them by what breaks if they stop, set the assessment depth per tier in advance, gather evidence rather than only questionnaire answers, score consistently, decide with conditions attached, and re-assess on a cycle and on triggers.
What is the difference between a vendor risk assessment and a third-party risk assessment?
In practice they are used interchangeably. Third-party is the broader term, covering any external party including partners and intra-group providers, while vendor usually implies a purchased service. The process is the same.
How often should suppliers be re-assessed?
Annually for suppliers supporting a critical or important function, every two years or on change for material ones, and on material change for the rest. Re-assess out of cycle after an acquisition, an incident, a change of sub-processor, or a material change to what they do for you.
What should a third-party risk assessment cover?
Service and dependency, data exposure, access to your systems, security posture and the scope of any certifications, sub-processors, contract terms including incident notification and audit rights, concentration, and how you would exit.
Is a questionnaire enough?
No. A questionnaire is self-reported and tells you what the supplier believes about itself. Read certification scope statements, pull the contract, and consider what the supplier can actually reach in your systems.
How do you score supplier risk?
Use a small set of consistent signals rather than a bespoke methodology. Venvera uses criticality, geographic risk, concentration, contract health and data sensitivity, weighted and recalculated automatically when the data changes. What matters is that the score moves when reality moves.
Which regulations require third-party risk assessment?
DORA Articles 28 and 29, NIS2 Article 21(d) on supply chain security, ISO 27001 supplier relationship controls, SOC 2 vendor risk criteria, and GDPR Article 28 due diligence on processors. One assessment can evidence all of them.
Do we need to assess every supplier?
Every supplier should be in the register. Not every supplier needs a full assessment. That distinction is what tiering exists to make.





