Purpose
Not every vendor deserves the same scrutiny. This template gives you a tiered questionnaire so that a payroll processor handling sensitive financial data gets a full assessment, while a vendor that never touches personal data gets a quick record-and-move-on entry. The accompanying CSV contains a ready-to-use question set across ten domains, with one clearly labelled example completed row.
How to use this kit
- Tier the vendor before you send a single question (see criteria below).
- Copy only the questions relevant to the assigned tier — Tier 3 vendors typically only need Q001 and Q029 answered to confirm no personal data is involved.
- Send the relevant questions to the vendor, or complete them from existing documentation (SOC 2 reports, security whitepapers, existing DPAs) where available.
- Record the vendor's response, your finding, and a risk rating for every question — an unanswered question is a finding in itself, not a blank to skip.
- Where a gap is identified, log a specific action, an owner, and a due date rather than a general note to "follow up."
- Get sign-off from the accountable approver before the vendor goes live, and file the completed assessment as evidence.
Field definitions
| Column | Definition |
|---|---|
| Question ID | Unique reference, e.g. Q014. |
| Risk tier | The tier this question applies to (Tier 1 full assessment, Tier 2 short assessment, Tier 3 record-only). |
| Domain | The subject area (data handling, sub-processors, transfers, retention/deletion, security, access control, incident response, AI/model use, contracts/DPAs, exit). |
| Question | The question to put to the vendor or answer from documentation. |
| Why it matters | One-line rationale so a non-specialist reviewer understands the risk being tested. |
| Evidence requested | The specific artefact that would demonstrate the answer is true (a policy, a certificate, a contract clause), not just a verbal confirmation. |
| Owner | Who is responsible for obtaining and verifying the answer — often the vendor itself, with your security or legal lead verifying. |
| Response | The vendor's actual answer, summarised. |
| Finding | Your assessment of what the response means (adequate, partial, inadequate, needs clarification). |
| Risk rating | Low / Medium / High / Critical, based on the decision criteria below. |
| Action | The remediation or follow-up required, if any. |
| Due date | When the action must be completed. |
| Status | Open, In Progress, Closed, Accepted (risk formally accepted despite a gap). |
Tiering: decision criteria
| Tier | Criteria | Assessment depth |
|---|---|---|
| Tier 1 | Special category or highly sensitive data; large volume of individuals; critical operational dependency; data leaves your primary jurisdiction | Full questionnaire, all domains, renewed at least annually |
| Tier 2 | Ordinary personal data at moderate volume; no special category data; not a critical dependency | Shortened questionnaire (data handling, security, retention, contracts), renewed every 12–24 months |
| Tier 3 | No personal data processed, or only fully anonymised/aggregated data | Record the confirmation and the basis for the tiering decision; no full questionnaire needed |
If you are unsure which tier applies, default to the higher tier until you can confirm otherwise.
Worked example (illustrative only)
The CSV includes this completed row as a model of the level of detail expected:
| Field | Value |
|---|---|
| Question ID | EX-000 |
| Domain | Example |
| Question | EXAMPLE COMPLETED ROW — delete before use: Does the vendor encrypt personal data at rest and in transit? |
| Evidence requested | Copy of encryption policy or SOC 2 report excerpt |
| Response | Yes, AES-256 at rest, TLS 1.2+ in transit, confirmed in SOC 2 Type II report |
| Finding | Adequate control in place |
| Risk rating | Low |
| Status | Closed |
Note how the response cites a specific, checkable artefact rather than a general assurance — that is the standard to hold every real answer to.
Risk rating guidance
- Low: control is documented, evidenced, and matches your requirements.
- Medium: control exists but evidence is incomplete, outdated, or partially matches requirements.
- High: control is missing, vague, or the vendor could not provide requested evidence for a material risk area (e.g. no DPA, no breach notification commitment, undisclosed sub-processors).
- Critical: the vendor processes special category or high-volume data with no lawful transfer mechanism, no security certification, or an unwillingness to sign a data processing agreement — treat as a blocker until resolved or formally escalated.
Any High or Critical rating should be escalated for a documented risk-acceptance decision by the approver before onboarding proceeds, or should trigger remediation before go-live.
Ownership and maintenance
- Assessment owner: typically the privacy or security lead who tiers new vendors and tracks open actions to closure.
- Business sponsor: the internal team bringing on the vendor is responsible for providing context on the intended use and for engaging the vendor to answer questions promptly.
- Approver: a named role (e.g. Head of Privacy, CISO, or a joint privacy/security committee) signs off before the vendor is approved to process personal data.
- Review cadence: Tier 1 vendors — at least annually or on contract renewal, whichever is sooner. Tier 2 vendors — every 12–24 months. Tier 3 vendors — re-confirm the "no personal data" basis if the vendor's use changes. Any material change (new sub-processor, new data category, a reported breach) triggers an immediate reassessment regardless of the schedule.
- Register: keep a master list of vendors, their tier, their last assessment date and their next review date — this list feeds your overall data inventory as a source of recipients.
Where this fits in your program
Vendor assessment is one of the recurring operational disciplines covered in Practical Privacy Program Implementation. For the underlying legal concepts behind processor obligations, sub-processing and international transfers, see Global Data Privacy Fundamentals. If the vendor embeds AI or model features, also work through the AI Privacy Risk Checklist before sign-off, and consider the AI Privacy and Data Readiness course for a deeper treatment. To benchmark your current vendor risk process, take the free assessment.
Contractual and transfer requirements vary significantly by jurisdiction and sector; treat this template as a starting point and confirm specific legal requirements with qualified counsel where the assessment surfaces a material gap.
Download formats
- CSV template (.csv) — the full questionnaire with risk tier, question, evidence requested, owner, response, finding, risk rating, action, due date and status columns, plus one clearly labelled example row.
- Guidance (Markdown .md) — this page, including scoring and escalation criteria.
- Print / Save as PDF — a clean print view of the guidance.
Nothing here is emailed — each option downloads or prints directly from your browser.