Third-Party Compliance Assessment Form
Use this Third-Party Compliance Assessment Form to evaluate a vendor or partner’s compliance readiness across key risk and control areas. Please answer each section based on your assessment.
Vendor or Partner Name
*
Type of Relationship
*
Please Select
Supplier
Service Provider
Consultant
Technology Partner
Other
Overall Compliance Readiness
*
1
2
3
4
5
Compliance Assessment Matrix
*
Rows
Not Evident
Partially Evident
Fully Evident
Not Applicable
Data Protection & Privacy
1
2
3
4
Information Security Controls
5
6
7
8
Regulatory Compliance
9
10
11
12
Risk Management
13
14
15
16
Incident Response Preparedness
17
18
19
20
Does the third-party have documented compliance policies?
*
Yes
No
Unsure
How often are compliance controls reviewed or updated?
*
Please Select
Annually
Semi-Annually
Quarterly
On an ad hoc basis
Unknown
Has the third-party undergone a recent compliance audit or assessment?
*
Yes, within the past 12 months
Yes, within the past 2 years
No
Unknown
Are there any known compliance gaps or areas of concern?
*
Yes
No
Unsure
Additional Comments or Observations
Submit Assessment
Should be Empty: