Vendor Risk Assessment Matrix Form
Assess and document key risk factors for third-party vendors using this structured matrix form.
Vendor/Company Name
*
First Name
Last Name
Vendor Contact Email
*
example@example.com
Service or Product Description
*
Type of Data Accessed or Handled
*
Please Select
No data access
Public or non-sensitive data
Internal business data
Confidential or regulated data
Personal information (PII)
Other
Inherent Risk Assessment
*
Low
1
2
3
4
High
5
1 is Low, 5 is High
Control Maturity & Security Posture
*
Rows
Weak
Developing
Mature
Advanced
Access Controls
1
2
3
4
Vulnerability Management
5
6
7
8
Incident Response
9
10
11
12
Data Protection
13
14
15
16
Compliance / Certification Status
*
ISO 27001
SOC 2
GDPR
PCI DSS
None
Other
History of Security Incidents (past 3 years)
*
No known incidents
Minor incidents only
Major incident(s) reported
Prefer not to disclose
Does the vendor use subcontractors for critical services?
*
Yes
No
Unknown
Business Continuity / Disaster Recovery Capability
*
Please Select
No documented plan
Basic documented plan
Tested and updated plan
Comprehensive and audited plan
Overall Risk Assessment or Reviewer Recommendation
*
Submit Assessment
Should be Empty: