---
title: "Vendor Risk Checklist"
description: "A practical checklist for assessing and monitoring third-party vendor risk — questionnaires, access mapping, fourth-party exposure, and continuous re-scoring."
keywords:
  - vendor risk checklist
  - third-party risk checklist
  - TPRM checklist
  - vendor security assessment checklist
---

# Vendor Risk Checklist

A working checklist for onboarding new vendors and re-assessing existing ones. Pair this with our full [Vendor Risk Assessment](/features/vendor-risk-assessment) coverage for the underlying methodology.

## Before Onboarding

- [ ] Vendor security questionnaire completed with evidence, not just self-attestation
- [ ] Vendor's own compliance certifications reviewed (SOC 2, ISO 27001, or equivalent)
- [ ] Data flow mapped — exactly what data and system access the vendor will have
- [ ] Contractual data processing terms reviewed and signed before access is granted
- [ ] Vendor risk tier assigned based on actual data/system exposure, not just spend or reputation

## Ongoing Monitoring

- [ ] Vendor risk is re-scored on a recurring cycle, not just at onboarding
- [ ] Dark web and breach monitoring covers vendor-related exposure
- [ ] Vendor access is reviewed and pruned when a relationship or use case changes
- [ ] Renewal reviews include a fresh security questionnaire, not an automatic rollover

## Fourth-Party Risk

- [ ] Critical vendors' own key subprocessors are identified
- [ ] Fourth-party exposure is factored into your overall risk score, not treated as out of scope

## Compliance Alignment

- [ ] Vendor assessments map to the frameworks you're accountable for (SOC 2 vendor management, DPDP Act processor obligations, HIPAA BAAs, PCI DSS service provider requirements)
- [ ] Data Processing Agreements are on file for every vendor handling personal data
- [ ] Offboarding process revokes vendor access completely when a contract ends

## Where Alastor InfoSec Fits

[Vendor Risk Assessment](/features/vendor-risk-assessment) turns this checklist into a continuously scored dashboard instead of a spreadsheet that goes stale the day after signing, with findings integrated into [Dark Web Monitoring](/features/dark-web-monitoring) and your overall [Alastor Shield](/products/alastor-shield) compliance posture.

[Talk to our team](/about-us) about setting up continuous vendor risk monitoring for your supply chain.
