This section captures foundational information about the vendor's legal structure, business relationship parameters, and operational footprint. Accurate completion ensures proper risk tiering and contractual alignment.
Vendor Legal Entity Registered Name
DBA or Trading Name (if different)
Registered Corporate Headquarters Address
Corporate Legal Structure
Privately Held Corporation
Publicly Traded Corporation
Government Entity
Non-Profit Organization
Limited Liability Company
Partnership
Subsidiary of Larger Corporation
Joint Venture
If Subsidiary or Joint Venture, specify Parent Organization(s)
Primary Industry Vertical
Cloud Infrastructure & SaaS
Cybersecurity & Network Tools
Data Analytics & Business Intelligence
Financial Technology (FinTech)
Healthcare Technology (HealthTech)
Human Capital Management
Customer Relationship Management
Enterprise Resource Planning
Communication & Collaboration
Development Tools & DevOps
Supply Chain & Logistics
Marketing & Sales Automation
Other
Business Relationship Classification
Strategic Partner (Long-term, high integration)
Critical Supplier (Essential for operations)
Standard Vendor (Transactional)
Temporary Contractor (Project-based)
Trial/Pilot Vendor (Evaluation phase)
Sub-Processor (Processing data on our behalf)
Total Contract Value (LCY)
Contract Effective Date
Contract Expiration Date
Expected Go-Live/Integration Start Date
Primary Business Use Case & Justification
Data Classification Levels Vendor Will Access (select all that apply)
Public Information
Internal Use Only
Confidential Business Data
Restricted Sensitive Data
Highly Restricted (e.g., Trade Secrets, Core IP)
Geographic Regions Where Vendor Operates or Stores Data
North America
South America
European Union
United Kingdom
Asia-Pacific
Middle East & Africa
Eastern Europe
Global distributed infrastructure
Key Vendor Contact Points
Full Name | Role/Title | Email Address | Direct Phone | Primary Contact Type | ||
|---|---|---|---|---|---|---|
A | B | C | D | E | ||
1 | Jane Smith | Account Executive | jane.smith@vendor.com | +1-555-0100 | Commercial | |
2 | John Doe | Chief Information Security Officer | john.doe@vendor.com | +1-555-0101 | Security | |
3 | ||||||
4 | ||||||
5 | ||||||
6 | ||||||
7 | ||||||
8 | ||||||
9 | ||||||
10 |
Does vendor maintain comprehensive Cybersecurity Insurance?
Cyber Insurance Details
Coverage Limit | Insurance Provider | Policy Number | Policy Expiry Date | ||
|---|---|---|---|---|---|
A | B | C | D | ||
1 | $5,000,000.00 | Global Insurance Corp | CYB-2025-78945 | 12/31/2025 | |
2 | |||||
3 | |||||
4 | |||||
5 | |||||
6 | |||||
7 | |||||
8 | |||||
9 | |||||
10 |
Does vendor maintain Professional Liability/E&O Insurance?
Business Continuity Plan (BCP) Maturity Level
Certified to ISO 22301 standard
Formally documented and tested annually
Documented but not regularly tested
Informal or draft stage
No formal BCP exists
Disaster Recovery Site Locations & Failover Capabilities
Has vendor experienced a data breach or security incident in past 3 years?
Provide incident details: date, scope, data types affected, remediation actions, and current prevention measures
Detail the technical integration architecture, data access patterns, and network connectivity requirements. This information is critical for firewall rules, access controls, and network segmentation decisions.
Primary Integration Architecture
Cloud SaaS (public internet)
Cloud IaaS (private connectivity)
On-premises deployment
Hybrid cloud model
API-only integration (no UI access)
Site-to-Site VPN
Dedicated Direct Connect/ExpressRoute
Reverse proxy/gateway
Will vendor access enterprise network via API?
Provide API documentation URL, authentication method, rate limits, and IP ranges
Will vendor establish VPN connectivity?
Specify VPN technology (IPSec/SSL), encryption standards, tunnel endpoints, and certificate requirements
Types of Enterprise Data Vendor Will Access (select all)
Customer Personal Identifiable Information (PII)
Employee PII & HR Records
Financial & Accounting Data
Intellectual Property & Trade Secrets
Health & Medical Records
Payment Card Information (PCI)
Authentication Credentials & Secrets
System Logs & Telemetry
Contractual & Legal Documents
Other Sensitive Business Data
Estimated Volume of Data Records (per data type selected above)
Specific Enterprise Systems & Applications to be Accessed
Network Segments & Security Zones Vendor Will Access
DMZ (De-Militarized Zone)
Internal Corporate Network
Production Server Subnet
Database Tier/Data Lake
Management & Monitoring Network
Development & Test Environment
Backup & Recovery Network
Cloud Management Plane
User Authentication & Federation Method
SAML 2.0 Single Sign-On
OAuth 2.0 / OpenID Connect
LDAP/Active Directory
RADIUS with MFA
Certificate-based (PKI)
Username/Password (local accounts)
Multi-factor Authentication (MFA) required
No authentication (public access)
Is Multi-Factor Authentication (MFA) enforced for all vendor personnel?
Explain MFA implementation timeline and compensating controls
Will vendor require Privileged/Administrative Access?
Privileged Access Justification
System/Resource Name | Number of Privileged Accounts | Business Justification for Elevated Access | Just-in-Time Access? | ||
|---|---|---|---|---|---|
A | B | C | D | ||
1 | Production Database | 3 | Database maintenance and troubleshooting | Yes | |
2 | |||||
3 | |||||
4 | |||||
5 | |||||
6 | |||||
7 | |||||
8 | |||||
9 | |||||
10 |
Detailed Data Flow Description (how data moves between systems)
Upload Network Architecture Diagram (Visio, PDF, or PNG)
Data Residency & Sovereignty Model
Data remains within primary jurisdiction only
Regional residency (e.g., EU-only)
Multiple restricted jurisdictions
Global with approved locations
Unrestricted global distribution
Will vendor personnel access systems remotely from offshore locations?
List remote locations, workforce size per location, and device management controls
Session Timeout Setting (minutes)
Is IP Whitelisting/Restricted Network Access implemented?
List all IP ranges, CIDR blocks, and gateway endpoints
Comprehensive validation of vendor's security posture through recognized frameworks, encryption standards, and proactive security testing. Evidence must be current (within 12 months).
SOC 2 Attestation Status
SOC 2 Type II (current, within 12 months)
SOC 2 Type I (current)
SOC 2 Type II (in progress, >60% complete)
SOC 2 Type II (planned within 6 months)
Not applicable (vendor doesn't store/process data)
No current SOC 2 and no immediate plans
Can you provide the full SOC 2 report (management letter included)?
SOC 2 Report Details
Audit Period End Date | Next Audit Date | Auditor Firm Name | Upload SOC 2 Report (PDF) | ||
|---|---|---|---|---|---|
A | B | C | D | ||
1 | 12/31/2024 | 12/31/2025 | BigFour Security Auditors | ||
2 | |||||
3 | |||||
4 | |||||
5 | |||||
6 | |||||
7 | |||||
8 | |||||
9 | |||||
10 |
ISO 27001 Certification Status
Certified (current, no major non-conformances)
Certified (minor non-conformances noted)
Certification in progress (Stage 2 audit scheduled)
Certification planned (within 12 months)
Not applicable
No certification held
Can you provide ISO 27001 certificate and scope statement?
ISO 27001 Certificate Details
Certificate Issue Date | Certificate Expiry Date | Accreditation Body | Certified Scope Description | Upload Certificate | ||
|---|---|---|---|---|---|---|
A | B | C | D | E | ||
1 | 6/15/2024 | 6/14/2027 | International Standards Certifiers | Information Security Management for SaaS Platform | ||
2 | ||||||
3 | ||||||
4 | ||||||
5 | ||||||
6 | ||||||
7 | ||||||
8 | ||||||
9 | ||||||
10 |
Additional Security Frameworks & Compliances (select all applicable)
NIST Cybersecurity Framework (aligned or certified)
FedRAMP (Authorized)
CSA STAR Certification
PCI DSS (Level 1 Service Provider)
HIPAA Security Rule (BA Agreement)
ISO 27701 (Privacy)
GDPR-ready (EU data)
Other industry-specific compliance
Is all sensitive data encrypted at rest using industry-standard algorithms?
Explain which data remains unencrypted and business justification
Encryption Standard for Data at Rest
AES-256 (FIPS 140-2 validated)
AES-128 (FIPS 140-2 validated)
RSA 2048-bit or higher
ChaCha20/Poly1305
Other validated algorithm
Not applicable
Is data encrypted in transit across all network channels?
Identify unencrypted channels and migration plan
Minimum TLS Version for Data in Transit
TLS 1.3 only
TLS 1.2 or higher
TLS 1.1 (legacy support)
Mixed versions
Not enforced
Key Management & Cryptographic Key Storage
Hardware Security Module (HSM) - FIPS 140-2 Level 3
Cloud KMS (AWS KMS, Azure Key Vault, GCP KMS)
Third-party dedicated key management service
Self-managed secure vault
Basic file-based storage
No centralized key management
Certificate Management & PKI Process Description
Vulnerability Scanning Frequency
Continuous (real-time)
Daily automated scans
Weekly scans
Monthly scans
Quarterly scans
Annually
No formal scanning program
Independent Penetration Testing Frequency
Annual by qualified third party
Bi-annual (twice per year)
Quarterly
On-demand/after major changes
Performed in-house only
No penetration testing conducted
Date of Last External Penetration Test
Upload Most Recent Penetration Test Report (summary)
Does vendor operate a public Bug Bounty or Vulnerability Disclosure Program?
Bug Bounty Program Details
Platform (HackerOne, Bugcrowd, etc.) | Program Scope & Asset Coverage | Average Bounty Reward Range | ||
|---|---|---|---|---|
A | B | C | ||
1 | HackerOne | API endpoints and web applications | $500 - $5000 | |
2 | ||||
3 | ||||
4 | ||||
5 | ||||
6 | ||||
7 | ||||
8 | ||||
9 | ||||
10 |
Is a formal Security Incident Response Plan documented and tested?
Describe informal incident response capabilities
Security Operations Center (SOC) Availability
24/7/365 dedicated SOC
Follow-the-sun model
Business hours only
On-call rotation
No formal SOC
Evaluate downstream dependencies, sub-processor governance, and supply chain concentration risks. Transparency into the vendor's ecosystem is critical for comprehensive risk assessment.
Does vendor utilize sub-processors or fourth-party vendors to deliver services?
Total number of active sub-processors
Sub-Processor Notification & Approval Process
Automatic notification with 60-day opt-out
Prior written consent required
Annual sub-processor list review
Notification only, no approval rights
No formal notification process
Not applicable (no sub-processors)
Sub-Processor Due Diligence Standard
Same security standards as primary vendor (contractual)
Lightweight review for low-risk subs
No due diligence performed
Not applicable
Sub-Processor Inventory & Risk Profile
Sub-Processor Legal Name | Service Provided (e.g., hosting, AI model, support) | Primary Data Center Location(s) | Data Types Accessed | Certifications Held | Contractual Safeguards in Place | ||
|---|---|---|---|---|---|---|---|
A | B | C | D | E | F | ||
1 | Amazon Web Services | Cloud hosting infrastructure | US-East-1, EU-West-1 | PII,Logs | SOC 2,ISO 27001 | Yes | |
2 | AI Analytics Corp | Machine learning model processing | US-West-2 | Financial,Other | SOC 2 | Yes | |
3 | |||||||
4 | |||||||
5 | |||||||
6 | |||||||
7 | |||||||
8 | |||||||
9 | |||||||
10 |
Does vendor rely on fourth-party vendors (sub-processors of sub-processors)?
Describe fourth-party relationships and data flows
Supply Chain Concentration Risk Assessment
High Risk - Single point of failure (critical sub-processor)
Medium Risk - Few alternative providers available
Low Risk - Many comparable alternatives exist
Not assessed
Geographic & Political Risk Factors (select all applicable)
Operations in sanctions-countries
Jurisdictions with weak data protection laws
Regions with political instability
Natural disaster-prone areas
No specific geographic risks identified
Cross-Border Data Transfer Mechanism
Standard Contractual Clauses (SCCs)
Binding Corporate Rules (BCRs)
Certification under data protection framework
Direct contractual obligations
Data never transferred across borders
Not yet determined
Do we retain right to approve new sub-processors?
Do we retain audit rights over sub-processors?
Can we terminate for cause if sub-processor fails security standards?
Describe Sub-Processor Change Management & Communication Process
Final risk assessment, approval workflow, and executive attestation. This section consolidates findings and captures formal authorization for vendor onboarding.
Procurement Lead Full Name
Procurement Lead Corporate Email
Has a comprehensive risk assessment been completed?
Final Risk Rating
Critical Risk (requires monthly review)
High Risk (requires quarterly review)
Medium Risk (requires annual review)
Low Risk (standard review cycle)
Upload Risk Assessment Report & Supporting Evidence
Were any compliance gaps or security deficiencies identified?
Detail each gap, remediation plan, target date, and risk acceptance rationale
Has vendor completed enterprise security questionnaire?
Has vendor presented to security architecture review board?
Recommended Approval Decision
Approve - Meets all security requirements
Approve with Conditions - Minor gaps accepted
Defer - Requires remediation before approval
Reject - Fails to meet minimum security threshold
If Approved with Conditions, specify all conditions and monitoring requirements
Is CISO review and approval required for this vendor tier?
CISO Full Name
If yes, CISO Corporate Email
Required Security Controls to be Contractually Mandated
Network segmentation and micro-segmentation
Data Loss Prevention (DLP) monitoring
Enhanced logging and SIEM integration
Privileged Access Management (PAM)
Endpoint Detection & Response (EDR)
Data encryption key escrow
Annual penetration testing by our team
No additional controls required
Are all security requirements included in master service agreement?
Security Review & Re-assessment Frequency
Annual comprehensive review
Bi-annual review
Quarterly review (for critical vendors)
On-change trigger only
One-time assessment only
Is renewal review required at contract expiration?
Scheduled Renewal Review Date
Procurement Lead Digital Signature & Approval
Chief Information Security Officer (CISO) Digital Signature & Approval
Final Approval Date
Additional Comments & Risk Acceptance Justification
To configure an element, select it on the form.