Vendor Risk Checklist
A working checklist for onboarding new vendors and re-assessing existing ones. Pair this with our full Vendor Risk Assessment coverage for the underlying methodology.
Before Onboarding
- Vendor security questionnaire completed with evidence, not just self-attestation
- Vendor's own compliance certifications reviewed (SOC 2, ISO 27001, or equivalent)
- Data flow mapped — exactly what data and system access the vendor will have
- Contractual data processing terms reviewed and signed before access is granted
- Vendor risk tier assigned based on actual data/system exposure, not just spend or reputation
Ongoing Monitoring
- Vendor risk is re-scored on a recurring cycle, not just at onboarding
- Dark web and breach monitoring covers vendor-related exposure
- Vendor access is reviewed and pruned when a relationship or use case changes
- Renewal reviews include a fresh security questionnaire, not an automatic rollover
Fourth-Party Risk
- Critical vendors' own key subprocessors are identified
- Fourth-party exposure is factored into your overall risk score, not treated as out of scope
Compliance Alignment
- Vendor assessments map to the frameworks you're accountable for (SOC 2 vendor management, DPDP Act processor obligations, HIPAA BAAs, PCI DSS service provider requirements)
- Data Processing Agreements are on file for every vendor handling personal data
- Offboarding process revokes vendor access completely when a contract ends
Where Alastor InfoSec Fits
Vendor Risk Assessment turns this checklist into a continuously scored dashboard instead of a spreadsheet that goes stale the day after signing, with findings integrated into Dark Web Monitoring and your overall Alastor Shield compliance posture.
Talk to our team about setting up continuous vendor risk monitoring for your supply chain.