Vendor NameExtract the vendor/third-party company name...
Assessment DateExtract the assessment or report date. Return in Y...
Assessment TypeIdentify assessment type: Initial Onboarding, Annu...
Vendor CategoryClassify vendor type: Technology/SaaS, Professiona...
Criticality TierAssess vendor criticality: Tier 1 (Critical), Tier...
Data Access LevelWhat data does vendor access? No Data, Public Data...
Data Types AccessedList specific data types accessed: Customer PII, E...
Geographic PresenceList countries/regions where vendor operates or st...
Geographic RiskRate geographic risk based on data residency and o...
SOC 2 StatusSOC 2 certification status: Type II Current, Type ...
SOC 2 ExpirationExtract SOC 2 report expiration date. Return in YY...
ISO 27001 CertifiedIs the vendor ISO 27001 certified? Yes or No...
Other CertificationsList other certifications: PCI DSS, HIPAA, FedRAMP...
Security Controls ScoreRate security controls maturity 1-5: 1=Ad Hoc, 2=D...
Security GapsList identified security gaps or control weaknesse...
Data EncryptionData encryption status: At Rest and Transit, Trans...
Incident HistoryHas vendor disclosed any security incidents in the...
Incident DetailsIf incidents disclosed, summarize. Return N/A if n...
Financial StabilityAssess financial stability: Strong, Stable, Modera...
Business Continuity PlanDoes vendor have a documented BCP/DR plan? Yes or ...
BCP Test DateWhen was BCP/DR last tested? Return in YYYY-MM-DD ...
Insurance CoverageDoes vendor maintain cyber liability insurance? Ye...
SubprocessorsList any fourth-party subprocessors or subcontract...
Subprocessor RiskRate fourth-party/subprocessor risk: Low, Medium, ...
Regulatory ComplianceList regulatory frameworks vendor claims complianc...
Contract ExpirationExtract contract or agreement expiration date. Ret...
SLA ComplianceAssess SLA compliance: Exceeds, Meets, Below, Crit...
Overall Risk ScoreCalculate overall risk score 1-100 (100=highest ri...
Risk RatingFinal risk rating: Low, Medium, High, Critical...
Recommended ActionsList recommended risk mitigation actions or remedi...
Next Review DateRecommended next review date based on risk level. ...