What is vendor risk management?
Vendor risk management, also called third-party risk management (TPRM), is the process of assessing and controlling the risks that come from suppliers and service providers. It usually includes due diligence before signing, risk tiering, contract terms, and periodic reassessment. Security questionnaires are one of its main tools.
What the buyer is really asking
Buyers want to know how you vet your own vendors before trusting them with data. Describe how vendors are tiered by risk, what you review for each tier, and who approves a new vendor. A spreadsheet with tiers and review dates is a fine answer for a small company.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you assess and manage vendor security risk?”
- “Describe your third-party risk management program.”
- “Describe your vendor onboarding and due diligence process.”
- “How do you evaluate the security of new suppliers?”
Evidence to have ready
- A vendor management policy or procedure
- Your vendor inventory with risk tiers
- A completed vendor review for a critical supplier
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.