Vendor Risk Assessment
What is Vendor Risk Assessment?
A formal evaluation of the risks associated with using a specific third-party vendor, including security, compliance, operational, and reputational considerations.
Frameworks that govern vendor risk assessment
What the standards actually require on vendor risk assessment
Requirements naming vendor risk assessment across 3 standards, quoted from the control text.
HKMA C-RAF Domain 3 PROTECTION + Domain 4 DETECTION. DOMAIN 3 PROTECTION (6 sub-areas): (1) ACCESS CONTROL - identity + access management + privileged access (PAM) + MFA + zero trust + just-in-time access + role-based access + access reviews + offboarding;
HKMA-CRAF-Domain3-4-Protection-Detection · HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel →Manage supply chain risk for DER components, including vendor risk assessments, contract requirements, and ongoing monitoring of vendor security postures.
DER-GV-02 · Supply Chain Risk Management for DER →Per SIG (Shared Assessments) Standardized Information Gathering: vendor risk assessment. Requirements include (a) governance + risk management of vendors + (b) information security policies + (c) risk identification + treatment + (d) maintain SIG questionnaire...
SHAREASSESS-1 · Information Governance and Risk →Questions people ask about vendor risk assessment
What is Vendor Risk Assessment?
Why is Vendor Risk Assessment important for compliance?
Which compliance frameworks address Vendor Risk Assessment?
Where can I learn more about Vendor Risk Assessment?
See how Vendor Risk Assessment applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.