Frameworks

Building a Third-Party Risk Assessment Framework from Scratch

You don't need a massive GRC suite to manage vendor risk. A practical framework with clear tiering, focused questionnaires, and automated monitoring gets you 80% of the value at 20% of the cost.

April 2, 202616 min read

Start with tiering, not questionnaires

The most common mistake in building a TPRM program is treating all vendors the same. Sending a 500-question assessment to a vendor that only provides office supplies wastes everyone's time. Risk-based tiering ensures assessment depth matches actual risk.

Critical~5% of vendorsCore infrastructure,PII/PHI accessHigh~15% of vendorsBusiness-critical,sensitive dataMedium~30% of vendorsOperational tools,limited dataLow~50% of vendorsCommodity services,no data accessAssessment depth increases with risk tier

How to tier vendors

Score each vendor across three dimensions:

  1. Data sensitivity — Does the vendor access PII, PHI, financial data, or intellectual property? Higher sensitivity = higher tier.
  2. Business criticality — Would a 24-hour outage at this vendor disrupt your operations? Could you switch providers quickly?
  3. Financial exposure — What's the contract value? What would a breach at this vendor cost you in regulatory fines, remediation, and reputation?

Design tier-appropriate assessments

Each risk tier gets a different assessment depth:

  • Critical (full assessment) — 200-500 questions covering encryption, access controls, incident response, business continuity, compliance certifications, subprocessor management, and penetration testing evidence
  • High (focused assessment) — 80-150 questions covering core security controls, data handling, and compliance status
  • Medium (lightweight assessment) — 30-50 questions covering basic security hygiene and data access scope
  • Low (self-attestation) — 10-15 yes/no questions confirming minimum security standards

Evidence over assertions

Questionnaire responses are claims. Evidence is proof. For critical and high-tier vendors, require supporting documentation:

  • SOC 2 Type II report (not just Type I)
  • ISO 27001 certificate with scope statement
  • Penetration test executive summary (last 12 months)
  • Business continuity / disaster recovery test results
  • Data processing agreement or DPA

Track evidence freshness — a SOC 2 report from 18 months ago is stale. Set expiry policies and get notified when evidence needs refreshing.

Scoring that drives decisions

A scoring model turns subjective assessments into objective decisions. For each question category, define:

  • Weight — How important is this category? Encryption matters more than office physical security for a SaaS vendor.
  • Pass criteria — What answer constitutes an acceptable risk? Define thresholds, not just pass/fail.
  • Finding generation — When a vendor falls below threshold, automatically create a finding with severity, remediation guidance, and deadline.

Continuous monitoring fills the gaps

Point-in-time assessments are snapshots. Between annual reviews, continuous monitoring catches:

  • Domain posture changes (DMARC/SPF/DKIM degradation)
  • SSL certificate expiry or misconfiguration
  • Data breach notifications involving the vendor
  • News events affecting vendor stability
  • Contract renewal approaching without reassessment
Building a Third-Party Risk Assessment Framework from Scratch | RiskReply | RiskReply