NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
How to Perform a Third-Party Risk Assessment
Learn

How to Perform a Third-Party Risk Assessment

·Alexander Sverdlov
The short answer
A third-party risk assessment establishes what could go wrong if a supplier fails, is breached, or handles your data badly, and what you are going to do about it. The step that decides whether the programme survives is tiering. Assessing a cleaning contractor with the same depth as your core banking host is how a queue builds up until the business routes around you, so tier by criticality first and let the depth of assessment follow the tier.
On this page
  1. What is a third-party risk assessment?
  2. Tiering: the step that makes it finishable
  3. What most guides get wrong
  4. What to assess, by tier
  5. Seven steps
  6. Scoring without inventing a methodology
  7. What the frameworks actually require
  8. Common mistakes
  9. Do this in Venvera
  10. Frequently asked questions

What is a third-party risk assessment?

A structured evaluation of the risk a supplier introduces: what they do for you, what they can reach, what happens if they stop, and whether their own security is adequate for that exposure. It is performed before onboarding and repeated on a cycle, because a supplier's risk changes without anyone telling you.

The output is a decision, not a document. Onboard, onboard with conditions, or do not onboard. A programme that produces assessments but never refuses anything is producing paperwork.

Tiering: the step that makes it finishable

Almost every stalled third-party programme has the same cause: a single assessment process applied to every supplier. The queue grows, the business starts onboarding without you, and the register drifts out of date.

Tiering suppliers by criticality so assessment depth follows the tier
Depth of assessment follows tier. This is what makes the programme completable.
TierWhat it meansAssessment depth
Tier 1Supports a critical or important function, or holds sensitive data at scaleFull assessment: evidence review, questionnaire, contract clause check, exit plan, annual re-assessment
Tier 2Material but replaceable, limited data exposureQuestionnaire plus certification check, re-assessed every two years or on change
Tier 3Low impact, no sensitive data, easily replacedRegister the supplier, screen it, review on material change

Getting the tier right is more valuable than getting the score right. A wrong tier means you spent a week on a stationery supplier and a morning on the company hosting your production database.

What most guides get wrong

They treat the questionnaire as the assessment. A questionnaire is one input, and it is self-reported. It tells you what the supplier believes about itself. Certifications, penetration test summaries, contract terms and your own knowledge of what they can reach are the other inputs, and several of them are more reliable.

They stop at onboarding. The assessment that matters is the second one, eighteen months later, when the supplier has been acquired, moved its hosting, or lost the security lead who answered your questionnaire. Programmes that only assess at onboarding are measuring the past.

What to assess, by tier

AreaWhat you are establishingApplies from
Service and dependencyWhat they do, which of your functions depend on it, what breaks if they stopAll tiers
Data exposureWhat personal or confidential data they hold, process or can reachAll tiers
AccessWhether their staff hold access to your systems, and at what levelAll tiers
Security postureCertifications held, scope of those certifications, test resultsTier 1 and 2
Sub-processorsWho they depend on, and whether that concentrates risk you already carryTier 1
Contract termsSecurity obligations, audit rights, incident notification, termination, exitTier 1, and Tier 2 where data is involved
ConcentrationWhether too much now rests on this one supplierTier 1
ExitHow you would leave, how long it would take, what you would loseTier 1
Third-party risk register showing providers scored by criticality and risk
The register is the object the assessment updates, rather than a document filed beside it.

Seven steps

Seven steps of a third-party risk assessment from inventory to re-assessment
Inventory and tiering come first. Everything downstream inherits them.

1. Inventory the suppliers you actually have

Start from accounts payable rather than from the contract folder. Every programme discovers suppliers nobody in security had heard of, and the ones bought on a card are frequently the ones holding data.

2. Tier by criticality

Ask one question per supplier: what happens to our business if they stop tomorrow? That answer, not the contract value, sets the tier.

3. Set assessment depth by tier

Decide in advance what each tier requires, and hold the line. This is the policy decision that stops the queue.

4. Gather evidence, not just answers

Request the certification and read the scope statement, because a certificate covering a different entity or a narrow scope is common and easy to miss. Send the questionnaire, sized to the tier. Pull the contract.

5. Score consistently and record the reasoning

Two people assessing the same supplier should reach a similar answer. If they do not, the model is too subjective.

6. Decide, and attach conditions

Approve, approve with conditions, or refuse. Conditions are where most of the value is: MFA on their access, a notification clause added at renewal, a named security contact.

7. Re-assess on a cycle, and on triggers

Annually for Tier 1, and out of cycle whenever the supplier is acquired, suffers an incident, changes sub-processors or materially changes what it does for you.

Assess your first ten suppliers with us

Book a 30 minute session. Bring your supplier list and we will tier it live, set the depth per tier, and score your top ten together. You keep the output either way.

Book a walkthrough
Questionnaire campaign showing response status per supplier
The questionnaire is one input into the assessment, sized to the tier rather than sent identically to everyone.

Scoring without inventing a methodology

You do not need a bespoke model. You need a small number of signals, applied consistently, with the reasoning recorded. Venvera scores each ICT provider on five: criticality, geographic risk, concentration, contract health and data sensitivity, weighted, and re-scores automatically when the underlying data changes.

The property that matters is not sophistication, it is that the score moves when reality moves. A score computed once during onboarding and never recomputed is a historical artefact.

Concentration risk analysis showing exposure by provider and by service
Concentration is the risk that only appears when you look across suppliers rather than at one.

What the frameworks actually require

FrameworkThe obligation
DORAArticle 28 requires ICT third-party risk management as part of the risk framework, with a register of information and preliminary assessment of concentration risk under Article 29
NIS2Article 21(d) requires supply chain security, taking account of the vulnerabilities and security practices of each direct supplier
ISO 27001Annex A supplier relationship controls, covering security in agreements and monitoring of supplier service delivery
SOC 2Common criteria covering vendor and business partner risk management
GDPRArticle 28 requires processors to provide sufficient guarantees, which is a due diligence obligation on you

The overlap is large, so a single assessment properly evidenced can answer all of them. Doing a separate exercise per framework is the most expensive way to reach the same position. For the DORA-specific detail, see building a compliant vendor register from scratch.

Common mistakes

  • Assessing everyone identically. The cause of most stalled programmes.
  • Accepting a certificate without reading its scope. A certificate for another group entity, or covering one product line, is not coverage of your service.
  • Never refusing anything. If nothing is ever refused or conditioned, the assessment is not influencing decisions.
  • Ignoring sub-processors. Two suppliers depending on the same sub-processor is concentration you did not know you had.
  • Assessing at onboarding only. The risk profile you captured is the one from the day you signed.
  • Sending a 300-question form to a four-person vendor. Covered in vendor security questionnaires.

Do this in Venvera

Venvera holds the supplier register with five-signal scoring that recalculates when the data changes, concentration analysis across providers and sub-processors, contract clause tracking, questionnaire campaigns, and the evidence mapped to the DORA, NIS2, ISO 27001, SOC 2 and GDPR obligations above. See third-party risk management, or download the free vendor risk assessment template if you would rather start in a spreadsheet.

Bring your supplier list

We will tier it with you in 30 minutes, set the assessment depth per tier, and show you where your concentration actually sits.

Book a working session

Frequently asked questions

How do you perform a third-party risk assessment?

Inventory your suppliers from accounts payable rather than the contract folder, tier them by what breaks if they stop, set the assessment depth per tier in advance, gather evidence rather than only questionnaire answers, score consistently, decide with conditions attached, and re-assess on a cycle and on triggers.

What is the difference between a vendor risk assessment and a third-party risk assessment?

In practice they are used interchangeably. Third-party is the broader term, covering any external party including partners and intra-group providers, while vendor usually implies a purchased service. The process is the same.

How often should suppliers be re-assessed?

Annually for suppliers supporting a critical or important function, every two years or on change for material ones, and on material change for the rest. Re-assess out of cycle after an acquisition, an incident, a change of sub-processor, or a material change to what they do for you.

What should a third-party risk assessment cover?

Service and dependency, data exposure, access to your systems, security posture and the scope of any certifications, sub-processors, contract terms including incident notification and audit rights, concentration, and how you would exit.

Is a questionnaire enough?

No. A questionnaire is self-reported and tells you what the supplier believes about itself. Read certification scope statements, pull the contract, and consider what the supplier can actually reach in your systems.

How do you score supplier risk?

Use a small set of consistent signals rather than a bespoke methodology. Venvera uses criticality, geographic risk, concentration, contract health and data sensitivity, weighted and recalculated automatically when the data changes. What matters is that the score moves when reality moves.

Which regulations require third-party risk assessment?

DORA Articles 28 and 29, NIS2 Article 21(d) on supply chain security, ISO 27001 supplier relationship controls, SOC 2 vendor risk criteria, and GDPR Article 28 due diligence on processors. One assessment can evidence all of them.

Do we need to assess every supplier?

Every supplier should be in the register. Not every supplier needs a full assessment. That distinction is what tiering exists to make.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING