[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-vendor-risk-assessment::en":3,"gloss-cluster-vendor-risk-assessment::en":26,"gloss-next-vendor-risk-assessment::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"vendor-risk-assessment","security","Vendor Risk Assessment","Vendor risk assessment is the process a buying organisation runs to decide whether a third-party tool may be used, what data it may touch, and under what conditions. It exists because outsourcing a capability does not outsource the consequences: when a supplier loses data, the customer whose data it was still has the regulatory duty, the disclosure obligation and the reputational damage.\n\nThe first useful move is tiering. Treating a diagramming tool and a system that reads the entire support inbox with the same review is a way of doing a lot of work badly — the light review is too heavy for one and far too thin for the other. Tier by what the tool would actually reach: the sensitivity of the data, whether access is read or write, whether it is scoped to a workspace or granted at the organisation level, and how much damage a compromise of that access would do.\n\nWhat the review examines is fairly stable across programmes. Where data goes and where it is stored. Which subprocessors sit behind the vendor, because a supplier's suppliers are also in scope. Retention: what is kept, for how long, and whether it can be shortened. Whether inputs are used to improve the vendor's models, and whether opting out is a contract term or a settings toggle that can change. The access model — how staff at the vendor reach customer data and what is logged when they do. Certifications, read for what they actually cover rather than for the logo. And the exit: how data comes back, in what format, and what happens on termination.\n\nAI tools add a few questions that older reviews do not ask. Model providers behind the product are subprocessors and belong on the list. Prompts and outputs are data, so retention applies to them, and a zero-retention arrangement upstream is a meaningfully different posture from one with default logging. If the product acts rather than only answers, the permissions it holds matter more than the data it reads, because a write-capable integration can do damage that no amount of encryption prevents.\n\nQuestionnaires carry more weight than they deserve. They are self-attested and point-in-time, they are frequently filled in by someone reading the last completed copy, and they measure whether a vendor can answer questions rather than whether a control works. Use them as a filter and a paper trail, then verify the few answers that actually matter — the ones about data location, retention and access — against evidence.\n\nFinally, the assessment is not finished when the contract is signed. Reassess at renewal and on material change: a new subprocessor, a new region, an acquisition, a product that quietly grew from reading data to acting on it. From the vendor's side, the whole exercise is a cost the buyer wants to reduce, which is why a published trust page and a pre-filled questionnaire shorten sales cycles more reliably than any additional certification.","Vendor risk assessment is the buyer-side review that decides whether a tool may touch company data, and how much of it, before any contract is signed.",null,[11,14,17,20,23],{"slug":12,"name":13},"right-to-audit","Right to Audit",{"slug":15,"name":16},"security-questionnaire","Security Questionnaire",{"slug":18,"name":19},"soc-2","SOC 2",{"slug":21,"name":22},"sub-processor","Sub-processor",{"slug":24,"name":25},"trust-center","Trust Center",[27,31,35,39,42,45,48,51,54,57,60,63],{"slug":28,"category":5,"name":29,"updated_at":30},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":32,"category":5,"name":33,"updated_at":34},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":36,"category":5,"name":37,"updated_at":38},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":40,"category":5,"name":41,"updated_at":38},"bridge-letter","Bridge Letter",{"slug":43,"category":5,"name":44,"updated_at":38},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":46,"category":5,"name":47,"updated_at":30},"byok","Bring Your Own Key (BYOK)",{"slug":49,"category":5,"name":50,"updated_at":38},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":52,"category":5,"name":53,"updated_at":34},"data-classification","Data Classification",{"slug":55,"category":5,"name":56,"updated_at":38},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":58,"category":5,"name":59,"updated_at":38},"data-minimization","Data Minimization",{"slug":61,"category":5,"name":62,"updated_at":38},"data-poisoning","Data Poisoning",{"slug":64,"category":5,"name":65,"updated_at":38},"data-processing-agreement","Data Processing Agreement (DPA)"]