Metaluxo
← Insights

vCISO

Vendor Risk Management: How to Assess a Supplier in 30 Minutes

That separate safe suppliers from dangerous ones.

Your company uses 40–50 SaaS tools. You cannot audit all of them. You cannot even read all their terms of service. But you can identify the ones that pose the greatest risk — and you can do it in 30 minutes per supplier.

At Metaluxo we run third-party risk assessments for SMEs. The process does not need to be enterprise-grade. It needs to be consistent, documented, and proportionate. This post provides the eight-question assessment we use.


The 8-question supplier risk assessment

1. What data do you process for us?

If the answer is vague — “we handle some customer information” — that is a red flag. You need to know exactly what categories of data they process: names, emails, payment details, health records, etc.

Risk indicator: The supplier cannot articulate what data they hold.

2. Where is the data stored?

Geography matters for GDPR, NIS2, and contractual obligations. You need to know the primary storage location and any backup or processing locations.

Risk indicator: Data is stored in jurisdictions without adequacy decisions or proper transfer safeguards.

3. Do you have a security certification?

ISO 27001, SOC 2, or PCI DSS are the most common. The absence of certification is not automatically disqualifying for a small supplier, but it means you need to ask more questions.

Risk indicator: No certification and no willingness to answer security questions.

4. Do you have a Data Processing Agreement?

For GDPR compliance, any supplier that processes personal data must have a signed DPA. This is non-negotiable.

Risk indicator: The supplier has never heard of a DPA or refuses to sign one.

5. What is your incident response process?

You need to know: how they detect incidents, how quickly they notify you, and what their containment process looks like.

Risk indicator: No incident response plan or no contractual obligation to notify you within 24 hours.

6. How do you handle access control?

At minimum: MFA for admin accounts, role-based access control, and immediate revocation when staff leave.

Risk indicator: No MFA, shared accounts, or no access review process.

7. What is your business continuity plan?

If the supplier goes down, how quickly can they recover? Do they have tested backups? What is their recovery time objective?

Risk indicator: No BCP, no tested backups, or RTOs that exceed your tolerance.

8. What happens if we leave?

You need a clear exit process: data return, data deletion, and transition assistance. The supplier should not hold your data hostage.

Risk indicator: No exit clause, data export fees, or vague deletion timelines.


Scoring and action

For each question, score the supplier:

  • Green (2 points): Clear, documented, and satisfactory answer
  • Amber (1 point): Partial answer or minor gaps
  • Red (0 points): No answer, refusal to answer, or serious gap

Total score:

  • 14–16: Low risk. Annual review sufficient.
  • 10–13: Medium risk. Review annually, request remediation plan for red flags.
  • 0–9: High risk. Do not use for sensitive data. If already in use, develop an exit plan.

Documentation

Keep a simple spreadsheet:

SupplierDate assessedAssessorScoreRed flagsNext review

This is your vendor risk register. It takes 30 minutes per supplier and satisfies most audit requirements.


At Metaluxo we run vendor risk assessments for SMEs, typically assessing 10–15 critical suppliers in a single engagement. If your customers or auditors are asking about third-party risk and you do not have a register, book a free 30-minute consultation and we will build one with you.

Common questions

Do we need to assess all suppliers or just the critical ones?

Assess all suppliers that process your data or have access to your systems. Prioritise critical suppliers (cloud, email, CRM, finance) for deeper review.

What makes a supplier 'critical'?

A supplier is critical if its failure would disrupt your operations or if it processes sensitive data. Typically 5–10 suppliers out of 50+ fall into this category.

How often should we reassess suppliers?

Annually for critical suppliers, biennially for non-critical. Reassess immediately after a security incident, merger, or significant service change.

Related reading

Send us a message
Message us Book now