Vendor Risk

Third-party risk assessment questionnaire: 12 supplier review questions

GovernSafe Team
Published
Last reviewed
7 min read

Use this worksheet to start a cybersecurity review of a technology or service supplier. Choose the questions and evidence that fit your scope. A named review owner makes the decision.

GovernSafe

It is a point-in-time working aid, not a complete procurement control set or a universal requirement. A short review can still be useful if it records what is known, what remains open and who will follow up.

How to use the worksheet

  1. Name the supplier, the service and the business process that depends on it.
  2. Choose the questions that fit the service, its access and its importance to your organisation.
  3. Request or locate evidence. Record what was supplied, its date and the limits of its scope.
  4. Give each open question a reviewer and a next action. Set a review date that fits your own process.
  5. Have the named decision owner assess the evidence and unresolved gaps. Revisit the record when material facts change.

Start with a blank review record. Keep supplier evidence in your organisation's approved location, then refer to it from the working file.

Review fieldYour entry
Supplier or service
Review purpose
Internal business owner
Reviewer
Assessment date
Evidence as of date
Scope note

The 12 supplier review questions

Q1. What product or service will this supplier provide, and which business process depends on it?

Why ask: Set the review boundary and priority.

Evidence to request: Service description, proposed use, internal owner.

Q2. What data or systems will the supplier access, process, store or support?

Why ask: Identify exposure before asking detailed controls.

Evidence to request: Data-flow summary, system and data categories, access description.

Q3. Where will that data be stored or accessed, and which subcontractors help deliver the service?

Why ask: Make location and downstream dependencies visible.

Evidence to request: Location statement, named subprocessors or subcontractor roles.

Q4. Which access is privileged or persistent, and how will it be approved, limited and removed?

Why ask: Focus the review on access that could affect customer systems or data.

Evidence to request: Access model, privileged-role list, joiner and exit procedure.

Q5. Who owns the supplier's security practices, and what policies or independent assessments can be shared?

Why ask: Identify accountability and the limits of assurance evidence.

Evidence to request: Policy summary, dated assessment or report with scope and exclusions.

Q6. How does the supplier find, prioritise and fix vulnerabilities in the service?

Why ask: Understand maintenance and unresolved exposure.

Evidence to request: Vulnerability process, patch policy, recent attestation or summary.

Q7. How does the supplier detect and report a security incident that affects this service?

Why ask: Establish notification and investigation expectations.

Evidence to request: Incident process, contact route, contractual notification terms.

Q8. For activity affecting this service, what audit information could the supplier provide under agreed terms?

Why ask: Identify what a later investigation or review could verify and where sharing is limited.

Evidence to request: Audit-information scope, retention summary and applicable contract or information-sharing terms. Do not presume access to a log sample.

Q9. If this service is disrupted, what continuity arrangements apply, and what testing is appropriate for its criticality?

Why ask: Check recovery dependencies in proportion to the service's importance.

Evidence to request: Continuity-plan summary and, for a critical service where shareable, a dated test or exercise summary with stated limits.

Q10. What security requirements can the contract state, and how are exceptions handled?

Why ask: Move unresolved promises into accountable terms and follow-up.

Evidence to request: Relevant contract clauses, exception owner and target date.

Q11. What evidence is missing, out of date or outside the assessment's scope?

Why ask: Prevent an unanswered request from being treated as a failed control or a clean bill of health.

Evidence to request: Source date, scope limits, missing-item list and supplier reply.

Q12. Who will make the decision, what remains open, and when will the record be revisited?

Why ask: Keep the human decision, rationale and next review visible.

Evidence to request: Internal decision record, named reviewer, follow-up date.

Record the answer and the gap

For each question, record its ID, the response status, an evidence reference or date, the accountable reviewer, any gap or next action, and the next review date. Keep the question, why it matters and the requested evidence beside that record. The blank CSV has these columns.

Use one of these response labels: Not asked, Requested, Received, Needs clarification, or Not applicable. They describe collection status, not supplier risk, compliance or approval. If a question is not applicable, record why. If evidence is missing, note the request and its limits; missing public evidence does not prove that a control is absent. A dated report supports only what its scope covers.

For direct teams and MSP advisers

If you are reviewing a supplier for your own organisation: Keep the business owner, evidence reviewer and decision owner clear. Decide what evidence is proportionate to the service and record the rationale for any open item.

If you advise several clients: Make one record per client and service. Name the client's decision owner, separate supplier-provided evidence from your assessment, and store each completed file through that client's approved process. Your advice does not become a decision for the client.

Download the blank worksheet

Use this worksheet to start a cybersecurity review of a technology or service supplier. Choose the questions and evidence that fit your scope. A named review owner makes the decision. It is a point-in-time aid, not a complete procurement control set.

Download the blank supplier review worksheet (CSV)

The download is ungated. Using the page or downloading the CSV does not submit supplier answers or evidence to GovernSafe. Keep any completed copy in your organisation's approved process.

Where GovernSafe fits

The GovernSafe vendor-risk workflow keeps available vendor evidence, visible gaps, accountable follow-up and human review together. GovernSafe can prepare findings and evidence context for people to review. People make vendor decisions. This worksheet is a separate working aid; it does not send questions to suppliers, score them or approve them in GovernSafe.

Source notes

Tags:Third-party riskSupplier reviewCybersecurity questionnaireHuman review

Talk to GovernSafe

Ready to see it on your stack?

Show us the cloud problem. We will walk through the GovernSafe workflow that fits it.