Third-Party Risk Assessment Checklist
Use this form to evaluate a vendor or other third party for risk, controls, and follow-up actions.
Third-Party Profile
Organization Name
*
Primary Contact Name
*
First Name
Middle Name
Last Name
Contact Email
*
example@example.com
Contact Phone
*
Please enter a valid phone number.
Format: (000) 000-0000.
Service/Product Description
*
Requesting Business Unit / Department
*
Risk Assessment Checklist
Data Access Level
*
Please Select
No access
Limited access to non-sensitive data
Access to internal business data
Access to sensitive data
Other
Type of Services Provided
*
Please Select
Software/SaaS
Professional services
Managed services
Data processing
Cloud infrastructure
Logistics/Operations
Other
Are subcontractors used?
*
No
Yes
Unknown
Security incidents in the past 12 months?
*
No
Yes
Unknown
Business continuity/disaster recovery plan exists?
*
Yes
No
In progress
Unknown
Security Controls Maturity
*
Ad hoc
1
2
3
4
Optimized
5
1 is Ad hoc, 5 is Optimized
Privacy and Data Handling Maturity
*
Ad hoc
1
2
3
4
Optimized
5
1 is Ad hoc, 5 is Optimized
Overall Risk Level
*
1
2
3
4
5
Control Domain Assessment
Rows
Status
Access management
1
Encryption
2
Vulnerability management
3
Incident response
4
Backup/recovery
5
Review and Decision
Reviewer Name
*
First Name
Middle Name
Last Name
Decision Status
*
Please Select
Approved
Approved with Conditions
Rejected
Pending
Follow-Up Actions / Remediation Items
Target Review Date
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Final Comments
Submit Assessment
Should be Empty: