Third-party risk
How to build a vendor risk management program
Every framework requires it, most small companies do it once in a spreadsheet, and auditors notice. Here is a program that fits a team without a GRC hire and holds up in fieldwork.
7 min read · Certifyi compliance team · Updated September 2026
Short answer. Inventory every vendor, tier them by the data and access they hold, assess each tier proportionately (a questionnaire and evidence for high tiers, a certification check for low tiers), record the decision, put the right contract terms in place, and re-assess on a schedule. Keep all of it in one record so the auditor can trace a vendor from inventory to decision.
Step 1: build the inventory from where money and access already flow
The two most reliable sources are finance (who you pay) and identity (which SaaS apps have SSO or API access). Pull both, merge, and you have ninety percent of the list. Add the vendors engineering uses on free tiers; they hold data too. Record the business owner, what data the vendor touches and how access works.
Step 2: tier by data and access, not by spend
| Tier | Definition | Assessment | Re-assess |
|---|---|---|---|
| Critical | Holds customer data, production access or is essential to service delivery | Full questionnaire, SOC 2 or ISO 27001 report, contract review, DPA | Annually and on incident |
| High | Holds internal confidential data or employee personal data | Short questionnaire, certification check, DPA where personal data | Annually |
| Medium | Business tools with limited data | Certification check, terms review | Every two years |
| Low | No meaningful data or access | Inventory entry only | On change |
Step 3: assess proportionately
The most common failure is sending a 200-question spreadsheet to every vendor and getting nothing back. Critical vendors get a real questionnaire and a request for their SOC 2 or ISO report. High-tier vendors get twenty questions. Everyone else gets a check that they hold a current certification. If a vendor answers in their own workspace, as they do in Certifyi’s Supplier Workspace, their attestation is recorded in their name, on a date, and reused for every client who assesses them.
Step 4: record the decision
Auditors do not fail you for using a vendor with a gap; they fail you for having no record that you knew and decided. For each critical and high vendor record the assessment result, the residual risk, who accepted it and any compensating controls. Link the vendor to the risks and controls it affects.
Step 5: contracts
Contract terms to check
- A data processing agreement where personal data is involved (GDPR) and a business associate agreement where PHI is involved (HIPAA).
- Security obligations and the right to audit or to receive assurance reports.
- Breach notification timelines that let you meet your own obligations.
- Data return and deletion at termination.
- Sub-processor disclosure and change notification.
Step 6: re-assess on a schedule and on change
Set the cadence per tier and put it in the calendar. Trigger a re-assessment when a vendor has an incident, changes ownership, or starts handling a new data type. A program that assesses once and never again is the pattern every auditor recognises and most flag.
Frequently asked questions
How many vendors does a typical 50-person SaaS company have?
Between sixty and one hundred and twenty, of which five to fifteen are critical. Tiering is what makes the program manageable.
Do we need a SOC 2 report from every vendor?
Only from critical vendors. For the rest, a current certification check and the right contract terms are proportionate and defensible.
What if a critical vendor refuses to answer a questionnaire?
Record the refusal, assess with whatever public assurance they publish, decide whether to accept the risk with compensating controls, and document who decided. That record is what the auditor wants to see.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.