Third-party risk

How to build a vendor risk management program

Every framework requires it, most small companies do it once in a spreadsheet, and auditors notice. Here is a program that fits a team without a GRC hire and holds up in fieldwork.
7 min read · Certifyi compliance team · Updated September 2026
Short answer. Inventory every vendor, tier them by the data and access they hold, assess each tier proportionately (a questionnaire and evidence for high tiers, a certification check for low tiers), record the decision, put the right contract terms in place, and re-assess on a schedule. Keep all of it in one record so the auditor can trace a vendor from inventory to decision.

Step 1: build the inventory from where money and access already flow

The two most reliable sources are finance (who you pay) and identity (which SaaS apps have SSO or API access). Pull both, merge, and you have ninety percent of the list. Add the vendors engineering uses on free tiers; they hold data too. Record the business owner, what data the vendor touches and how access works.

Step 2: tier by data and access, not by spend

TierDefinitionAssessmentRe-assess
CriticalHolds customer data, production access or is essential to service deliveryFull questionnaire, SOC 2 or ISO 27001 report, contract review, DPAAnnually and on incident
HighHolds internal confidential data or employee personal dataShort questionnaire, certification check, DPA where personal dataAnnually
MediumBusiness tools with limited dataCertification check, terms reviewEvery two years
LowNo meaningful data or accessInventory entry onlyOn change

Step 3: assess proportionately

The most common failure is sending a 200-question spreadsheet to every vendor and getting nothing back. Critical vendors get a real questionnaire and a request for their SOC 2 or ISO report. High-tier vendors get twenty questions. Everyone else gets a check that they hold a current certification. If a vendor answers in their own workspace, as they do in Certifyi’s Supplier Workspace, their attestation is recorded in their name, on a date, and reused for every client who assesses them.

Step 4: record the decision

Auditors do not fail you for using a vendor with a gap; they fail you for having no record that you knew and decided. For each critical and high vendor record the assessment result, the residual risk, who accepted it and any compensating controls. Link the vendor to the risks and controls it affects.

Step 5: contracts

Contract terms to check

Step 6: re-assess on a schedule and on change

Set the cadence per tier and put it in the calendar. Trigger a re-assessment when a vendor has an incident, changes ownership, or starts handling a new data type. A program that assesses once and never again is the pattern every auditor recognises and most flag.

Frequently asked questions

Between sixty and one hundred and twenty, of which five to fifteen are critical. Tiering is what makes the program manageable.

Only from critical vendors. For the rest, a current certification check and the right contract terms are proportionate and defensible.

Record the refusal, assess with whatever public assurance they publish, decide whether to accept the risk with compensating controls, and document who decided. That record is what the auditor wants to see.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top