Skip to main content
Category: Supplier and Third-Party

Supplier Risk Assessment

Also known as: Vendor Risk Assessment, Third-Party Risk Assessment, Supplier Risk Management
Simply put

A supplier risk assessment is a structured review of a supplier or vendor to understand how much risk they might bring to your organization. It looks at the supplier's controls, evidence, and business context to help decide whether to work with them and how closely to manage the relationship. The goal is to identify potential problems before they affect your business.

Formal definition

A supplier risk assessment is the systematic process of identifying, evaluating, prioritizing, and managing the risks associated with engaging third-party vendors. It typically involves reviewing a supplier's controls, supporting evidence, and business context to determine the level of risk introduced by the relationship and to inform decisions about onboarding, ongoing monitoring, and mitigation. In a SOC 2 context, supplier or vendor management activities generally support the Common Criteria addressing risk management and the oversight of third parties, while under ISO/IEC 27001 supplier relationships are addressed through the ISMS risk assessment process and applicable Annex A reference controls selected via the Statement of Applicability; the specific scope, criteria, and rigor depend on the engagement and the organization's risk appetite.

Why it matters

Modern organizations rarely operate in isolation. They depend on cloud hosting providers, payment processors, subprocessors, and countless software vendors to deliver their services. Each of these relationships extends the organization's effective attack surface and introduces risks that sit largely outside its direct control. A supplier risk assessment gives an organization a structured way to understand how much risk a given supplier introduces before entering into a relationship and throughout its lifecycle, so that problems can be identified and addressed before they affect the business.

Both SOC 2 and ISO/IEC 27001 treat third-party oversight as an integral part of a mature security program rather than an optional add-on. In a SOC 2 examination, vendor and supplier management activities generally support the Common Criteria addressing risk management and the oversight of third parties, and an auditor will typically expect to see evidence that suppliers are evaluated and monitored. Under ISO/IEC 27001, supplier relationships are addressed through the ISMS risk assessment process and through applicable Annex A reference controls selected via the Statement of Applicability. In both cases, the scope, criteria, and rigor of the assessment depend on the engagement and the organization's risk appetite rather than a single fixed formula.

It is important to recognize the limits of any supplier risk assessment. An assessment reflects the information and evidence available at the time it is performed and cannot guarantee that a supplier will not experience a failure or breach. Where a supplier provides its own SOC 2 report or ISO 27001 certificate, those artifacts speak only to the controls and scope they cover, so reviewing them is a component of, not a substitute for, an organization's own risk-based evaluation.

Who it's relevant to

GRC and Compliance Managers
These professionals own the supplier risk program and must ensure that assessments are performed consistently and documented in a way that supports both SOC 2 examinations and ISO/IEC 27001 audits. They define the risk criteria, decide how deeply each supplier is evaluated based on the risk it introduces, and maintain the evidence that demonstrates third parties are being overseen.
Security Engineers and Analysts
Technical staff often review a supplier's controls and supporting evidence, including any SOC 2 reports or ISO 27001 certificates the supplier provides. They help interpret whether the supplier's technical safeguards are appropriate for the data and functions involved, keeping in mind that such artifacts cover only the controls and scope they describe.
Auditors and Assessors
SOC 2 examiners and ISO/IEC 27001 auditors look for evidence that an organization identifies, evaluates, and monitors its suppliers. In a SOC 2 engagement this supports the Common Criteria addressing risk management and third-party oversight, while in an ISO 27001 audit it connects to the ISMS risk assessment and the Annex A controls selected in the Statement of Applicability.
Procurement and Vendor Management Teams
These teams integrate risk assessment into onboarding and ongoing supplier relationships, anticipating potential supplier failures and ensuring that risk considerations inform contracting and monitoring decisions rather than being addressed only after a problem arises.

Inside Supplier Risk Assessment

Supplier Inventory and Categorization
A maintained list of third-party suppliers and service providers, typically categorized by the criticality of the service they provide and the sensitivity of data they access, process, or store. Categorization helps prioritize the depth of assessment applied to each supplier.
Risk Assessment of the Supplier
An evaluation of the risks a supplier introduces, considering factors such as data access, service criticality, and potential impact of disruption or compromise. In an ISO 27001 context, supplier-related risks are typically informed by the organization's broader risk assessment process and can influence which Annex A reference controls are selected via the Statement of Applicability.
Evidence of Supplier Assurance
Documentation used to gain assurance over a supplier's controls, which may include a supplier's SOC 2 report (an attestation examination performed by a licensed CPA firm under SSAE 18) or an ISO/IEC 27001 certificate (issued by an accredited certification body). Reviewers should note that such evidence covers only the controls, period, or defined ISMS scope stated within it.
Contractual and Security Requirements
Agreements that define the security, confidentiality, and, depending on scope, availability or privacy expectations placed on the supplier. These requirements are typically informed by the organization's own applicable criteria and the sensitivity of the relationship.
Ongoing Monitoring and Reassessment
Periodic re-evaluation of suppliers to confirm that assurance remains current, since a SOC 2 report covers only a defined review period and an ISO 27001 certificate covers only its stated scope and validity. Monitoring cadence typically depends on supplier criticality and scoping decisions rather than a fixed universal interval.

Common questions

Answers to the questions practitioners most commonly ask about Supplier Risk Assessment.

Does passing a supplier risk assessment mean my vendor is guaranteed to be secure or free from breaches?
No. A supplier risk assessment evaluates a vendor's controls and posture at the time of review and within the defined scope of that review. It does not guarantee freedom from breaches or continued secure behavior over time. Assessments reduce and inform your understanding of risk rather than eliminate it, which is why most programs pair initial assessments with ongoing monitoring and periodic reassessment.
If a supplier provides a SOC 2 report or holds an ISO 27001 certificate, does that replace the need for my own supplier risk assessment?
Not entirely. A SOC 2 report attests only to the controls and period it covers, and an ISO 27001 certificate applies only to the defined scope of that supplier's ISMS. These artifacts are valuable inputs to your assessment, but you still need to confirm that the scope, criteria, and review period align with the services you are consuming. Neither document automatically satisfies your own risk assessment obligations, and satisfying one framework does not automatically satisfy the other.
How does supplier risk assessment relate to SOC 2 and ISO 27001 requirements?
Both frameworks address third-party and supplier risk, though through different mechanisms. Under SOC 2, vendor and subservice organization management is typically evaluated within the Common Criteria (Security), with the specific controls depending on scope. Under ISO 27001, supplier relationships are addressed through the ISMS requirements in clauses 4 through 10 and relevant Annex A reference controls selected via the Statement of Applicability. In most engagements, auditors and certification bodies will expect evidence that supplier risks are identified, assessed, and managed, but the exact expectations depend on the auditor, certification body, scope, and applicable criteria.
How often should supplier risk assessments be performed?
Cadence varies depending on scope, the criticality of the supplier, and the risk the relationship presents. Many programs perform an initial assessment during onboarding and then reassess periodically, with higher-risk or higher-criticality suppliers reviewed more frequently. The frameworks generally expect that assessment frequency be risk-informed rather than fixed, so the appropriate interval should be defined by your organization's risk assessment and documented policy rather than assumed to be universal.
What evidence should be retained to demonstrate supplier risk assessments to an auditor or certification body?
Typically, organizations retain records showing that suppliers were identified, that risks were evaluated, and that decisions were made based on that evaluation. This can include completed assessment questionnaires, reviewed third-party attestation reports or certificates, risk ratings, and documentation of any remediation or accepted risks. The specific evidence expected depends on the applicable criteria and the reviewer, so it is advisable to align retained artifacts with the controls in scope.
How should assessments differ between critical and lower-risk suppliers?
A risk-based approach generally applies more rigorous review to suppliers that handle sensitive data or support critical services, and lighter review to lower-risk relationships. In most programs, higher-risk suppliers may warrant deeper evidence review, reliance on independent attestations or certifications, and more frequent reassessment, while lower-risk suppliers may involve a lighter-touch process. The tiering criteria should be documented and informed by your organization's risk assessment.

Common misconceptions

A supplier holding a SOC 2 report or an ISO 27001 certificate guarantees the supplier will not experience a breach.
Neither outcome guarantees freedom from breaches. A SOC 2 report attests only to the controls and the period covered by the examination, and an ISO 27001 certificate covers only the defined scope of the supplier's ISMS. Assurance is bounded by what was assessed.
If a supplier has an ISO 27001 certificate, that automatically satisfies a SOC 2 requirement (or vice versa).
The two frameworks are distinct: SOC 2 is an attestation examination against the Trust Services Criteria, while ISO 27001 is a certification against a management system standard. Mapping between them is possible but partial, and satisfying one does not automatically satisfy the other.
Every supplier requires the same depth of assessment.
In most programs, the depth of assessment is risk-based and depends on scope, the criticality of the service, and the sensitivity of data involved. Assessment intensity typically varies by supplier category rather than following a single mandatory approach.

Best practices

Maintain a supplier inventory and categorize suppliers by criticality and data sensitivity so assessment effort can be prioritized based on risk.
When reviewing a supplier's SOC 2 report, confirm the report type (Type I addresses suitability of design at a point in time; Type II addresses design and operating effectiveness over a defined review period) and check the period and scope covered before relying on it.
When reviewing an ISO 27001 certificate, verify the defined scope of the supplier's ISMS and that the certificate is current, recognizing that it covers only the stated scope.
Tie supplier requirements to your own applicable criteria and, in an ISO 27001 context, reflect supplier-related risk in the risk assessment and Statement of Applicability rather than treating supplier controls as automatically in scope.
Establish a reassessment cadence appropriate to each supplier's criticality, since assurance evidence covers only a defined period or scope and can become outdated.
Avoid treating one framework's assurance as equivalent to the other; where you map SOC 2 and ISO 27001 evidence, document that the mapping is partial and note any gaps that require separate verification.