Vendor Risk Assessment Self-Assessment Tool
Free vendor risk assessment tool for reviewing third-party security, data access, contracts, SOC 2 evidence, and ongoing risk.

Built for audit and compliance decisions
OC Security Audit focuses on independent assessment, cybersecurity audit, compliance readiness, control validation, and executive-level risk communication. This page does not duplicate ITperfection managed IT services. If remediation or implementation is needed after validation, that work can be handled separately through ITperfection.
Assessment items with audit guidance
Open each item to review what it means, how to check it, why it matters, the likely risk level, the business impact, and trusted reference links.
Vendor data access and classificationRisk: HighImpact: High
Description
Vendor data access and classification should be reviewed as an evidence-based audit area for third-party risk. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.
How to check
Review vendor questionnaires, SOC reports or equivalent evidence, contracts, data access, breach notification terms, and the owner assigned to ongoing review.
Why it is important
Third parties can create risk even when internal controls are strong, especially when they access sensitive data or critical systems.
Trusted reference links
NIST Cybersecurity Supply Chain Risk ManagementCISA ICT Supply ChainFTC Data Security
Security questionnaire completenessRisk: HighImpact: High
Description
Security questionnaire completeness should be reviewed as an evidence-based audit area for third-party risk. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.
How to check
Review the related admin console, screenshots, policies, logs, reports, tickets, exception records, and owner accountability evidence. Validate the control by evidence, not by memory.
Why it is important
This control supports audit readiness, risk reduction, executive visibility, and practical remediation planning.
Trusted reference links
NIST Cybersecurity Supply Chain Risk ManagementCISA ICT Supply ChainFTC Data Security
SOC 2 or independent audit evidenceRisk: HighImpact: High
Description
SOC 2 or independent audit evidence should be reviewed as an evidence-based audit area for third-party risk. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.
How to check
Confirm audit logs are enabled, retained long enough for investigation, protected from tampering, and reviewed through alerts, reports, or SIEM workflows.
Why it is important
Without reliable logs, the organization may not be able to investigate incidents, support insurance claims, or prove control operation during an audit.
Trusted reference links
NIST Cybersecurity Supply Chain Risk ManagementCISA ICT Supply ChainFTC Data Security
Breach notification and contract termsRisk: MediumImpact: Medium
Description
Breach notification and contract terms should be reviewed as an evidence-based audit area for third-party risk. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.
How to check
Review the related admin console, screenshots, policies, logs, reports, tickets, exception records, and owner accountability evidence. Validate the control by evidence, not by memory.
Why it is important
This control supports audit readiness, risk reduction, executive visibility, and practical remediation planning.
Trusted reference links
NIST Cybersecurity Supply Chain Risk ManagementCISA ICT Supply ChainFTC Data Security
MFA and identity controls for vendor accessRisk: HighImpact: Medium
Description
MFA and identity controls for vendor access should be reviewed as an evidence-based audit area for third-party risk. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.
How to check
Check administrator portals, identity policies, privileged role assignments, conditional access or MFA reports, and recent sign-in logs. Confirm both ordinary users and administrators are covered.
Why it is important
Identity compromise is one of the fastest paths to ransomware, data theft, cloud compromise, and unauthorized administrative change.
Trusted reference links
NIST Cybersecurity Supply Chain Risk ManagementCISA ICT Supply ChainFTC Data Security
Subprocessor and fourth-party visibilityRisk: MediumImpact: High
Description
Subprocessor and fourth-party visibility should be reviewed as an evidence-based audit area for third-party risk. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.
How to check
Review vendor questionnaires, SOC reports or equivalent evidence, contracts, data access, breach notification terms, and the owner assigned to ongoing review.
Why it is important
This control supports audit readiness, risk reduction, executive visibility, and practical remediation planning.
Trusted reference links
NIST Cybersecurity Supply Chain Risk ManagementCISA ICT Supply ChainFTC Data Security
Offboarding and access removal processRisk: MediumImpact: Medium
Description
Offboarding and access removal process should be reviewed as an evidence-based audit area for third-party risk. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.
How to check
Review approved policies, risk registers, board or leadership reporting, exception approvals, remediation tracking, and evidence that risk owners understand their responsibilities.
Why it is important
This control supports audit readiness, risk reduction, executive visibility, and practical remediation planning.
Trusted reference links
NIST Cybersecurity Supply Chain Risk ManagementCISA ICT Supply ChainFTC Data Security
Ongoing review cadence and risk ownershipRisk: MediumImpact: Medium
Description
Ongoing review cadence and risk ownership should be reviewed as an evidence-based audit area for third-party risk. The goal is to determine whether the organization can prove the control exists, works consistently, and has an accountable owner.
How to check
Review the related admin console, screenshots, policies, logs, reports, tickets, exception records, and owner accountability evidence. Validate the control by evidence, not by memory.
Why it is important
This control supports audit readiness, risk reduction, executive visibility, and practical remediation planning.
Trusted reference links
NIST Cybersecurity Supply Chain Risk ManagementCISA ICT Supply ChainFTC Data Security
Quick self-score
Use this scoring panel after reviewing the detail sections above. Score based on evidence: screenshots, policies, logs, reports, tickets, and owner accountability.
Select each control area to see the readiness level.
Priority remediation roadmap
1. Validate
Confirm the real control state with evidence and identify gaps that could affect audit, insurance, compliance, or executive risk decisions.
2. Prioritize
Rank findings by business impact, likelihood, compliance exposure, and operational dependency.
3. Track
Create a remediation roadmap with owners, dates, evidence requirements, and follow-up validation.

Created by Ali Hassani, CISO
Ali Hassani brings 25+ years of IT, cybersecurity, compliance, Microsoft infrastructure, cloud security, network security, firewall, vulnerability management, and executive advisory experience. OC Security Audit uses this experience to help organizations understand risk clearly before making remediation, compliance, or insurance decisions.
CISSPCCISOvCISO25+ Years Experience


View Ali Hassani’s profile for professional background, certifications, and consulting focus.
Request a professional review from OC Security Audit
Use the self-score as a starting point. For audit-ready evidence, executive reporting, and professional validation, schedule a focused review with OC Security Audit.