Glossary
What is a vendor risk assessment?
A vendor risk assessment evaluates the risks that come from working with a provider. It answers three questions: what does the provider claim about itself, what evidence exists for it, and which points stay open.
Leapfacto editorial · 16 September 2026
The three questions
The first question is answered by the provider. In questionnaires, certificates and contracts it describes how it works: which controls exist, who is allowed access, which subprocessors are involved and how deletion happens.
The second question is about evidence. A statement without a source is a sentence, not a basis. That is why every finding carries the place in the document it comes from, with section and page.
The third question is the uncomfortable one: what is not evidenced? A missing data point is not a verdict, but it is an open item that needs a decision: request it, accept it or stop working with the provider.
How an assessment differs from a questionnaire
A questionnaire collects answers. An assessment ties every answer to its source so it stays checkable later.
- A questionnaire ends when it is filled in. An assessment ends with an approval.
- A questionnaire depends on one person. An assessment stays available in the portfolio even when that person leaves.
- A questionnaire answers what was asked. An assessment also shows what is missing.
What belongs in it
- A review set: which providers are looked at regularly.
- Documents per provider: questionnaire, evidence, contract, policies.
- A scale: what the assessment is graded against.
- A source per finding: document, section, page.
- An approval and a log: who decided what and when.
What an assessment does not replace
- Not a vendor management system: master data, contract management and procurement stay where they are.
- Not legal advice: regulatory duties and their interpretation are for your compliance function.
- Not a certification of the provider: an assessment reads evidence, it does not issue it.
- Not an automatic decision: assessments are presented, not imposed.
Note
This article explains how we work. Regulatory duties and their interpretation are for your compliance function to settle.