Vendor risk · 11 min read · Updated 2026-07-06
Vendor security review template
A vendor security review template for supplier intake, evidence requests, risk scoring, approval and reassessment.
Direct answer
A vendor security review template captures what the vendor does, what data it touches, how critical it is, which security evidence has been reviewed, whether a DPA or subprocessor review is needed, what risks were accepted and when the vendor must be reassessed.
For small SaaS teams, the template needs to be lightweight enough to use before buying a tool, renewing a contract or connecting a vendor to production data. General information only; this is not legal advice.
When to run a vendor security review
- Before adopting a vendor that touches customer, employee or production data.
- Before renewing critical suppliers.
- After a material incident, ownership change or service change.
- When a customer asks how suppliers are reviewed.
Vendor intake questions
- What service does the vendor provide?
- Which data or systems will it access?
- Who owns the relationship internally?
- Is the vendor critical to service delivery?
- Will the vendor process personal data?
Data classification
- Classify customer data, personal data, credentials, source code and financial data.
- Record whether data is stored, processed or only viewed.
- Note hosting region and cross-border transfer assumptions.
Criticality and risk tiering
- Tier 1: production, identity, hosting, payment or high-volume personal data.
- Tier 2: important business tools with limited sensitive data.
- Tier 3: low-risk tools with little or no sensitive access.
Security evidence to request
- Security overview or whitepaper.
- SOC 2, ISO 27001 or equivalent report where available.
- Penetration test summary if relevant.
- Incident response and vulnerability disclosure process.
- Access control, encryption and backup summaries.
DPA and subprocessor review
- Confirm whether the vendor is a processor.
- Keep DPA terms or signed agreement.
- Review subprocessor list and notification terms.
- Record transfer mechanism notes where relevant.
Risk scoring
- Score likelihood and impact based on data, criticality and control evidence.
- Record accepted issues and compensating controls.
- Avoid score-only records with no explanation.
Approval and exceptions
- Name the approver.
- Record conditions for approval.
- Track remediation tasks or accepted risks.
- Set reassessment date based on risk tier.
Reassessment schedule
- Tier 1 vendors: at least annually.
- Tier 2 vendors: annually or on material change.
- Tier 3 vendors: every two years or on renewal.
- Review immediately after incidents or major scope changes.
Vendor review template table
| Area | What to check | Evidence to keep | Owner | Review frequency | Status |
|---|---|---|---|---|---|
| Intake | Service and data use are documented | Intake form | Vendor owner | Before approval | Not started |
| Data | Data category and region are known | Data classification note | Privacy owner | Before approval | Not started |
| Security | Evidence matches risk tier | SOC report, security overview | Security lead | Annually | Not started |
| Privacy | DPA and subprocessors reviewed | DPA, subprocessor list | Privacy owner | Annually | Not started |
| Risk | Risk tier and decision recorded | Risk score, approval note | Approver | Annually | Not started |
| Reassessment | Next review date is scheduled | Vendor register | Vendor owner | Per tier | Not started |
Managing the review record in Trustega
Trustega keeps supplier owner, data exposure, evidence, risk decision, DPA notes and reassessment dates together so vendor work can support ISO 27001, GDPR and customer reviews.
Common questions
Is this guide legal or certification advice?
No. This guide is for general information and is not legal advice. Use qualified legal, privacy or audit advisers for formal interpretation and assurance decisions.
Can a small SaaS team use this without a GRC team?
Yes. The workflows are designed for lean teams, but each record still needs a named owner, a review date and evidence that matches the actual scope.