
Quick answer
A vendor risk assessment template is a standardised framework that applies consistent risk criteria, scoring methodology, and documentation requirements to the evaluation of every vendor or third-party supplier.
It covers financial stability, cybersecurity posture, regulatory compliance, operational resilience, and ESG conduct in one scored document. The output is a risk score, a risk tier (Critical, High, Medium, or Standard), and an evidence log that serves as an audit trail under DORA Article 28, FCA PS7/23, and OCC Bulletin 2013-29.
Key Takeaways
A vendor risk assessment evaluates the risks a specific vendor or supplier introduces to your organisation across financial, operational, cybersecurity, compliance, and reputational dimensions. It produces a risk score, a risk tier, and a documented assessment record that serves as an audit trail for regulatory examination.
The assessment is distinct from general due diligence in that it is scored, tiered, and repeatable. The same criteria apply to every vendor at the same tier, which means the output is comparable across your supplier base and defensible when a regulator asks why one vendor received enhanced monitoring and another did not.
A vendor risk assessment template standardises the criteria, the scoring methodology, and the documentation format across your team. Without a template, different assessors apply different standards to different vendors — which creates both compliance gaps and audit trail problems that regulators find during programme examination.
The Neotas vendor due diligence framework explains how the vendor risk assessment sits within the broader vendor relationship lifecycle from onboarding through to exit, and how assessment depth is calibrated by risk tier.
Blank templates from template websites give you a document structure with no scoring logic. That is not useful for a regulated organisation. A template that meets the documentation standard under DORA Article 28, OCC Bulletin 2013-29, and FCA PS7/23 requires six components.
Vendor identification and classification
Vendor legal name, registration number, jurisdiction of incorporation, primary contact, engagement type, and initial risk tier classification. Every subsequent reassessment must reference a consistent vendor identifier so the audit trail is traceable across the full relationship history.
Risk scoring criteria and category weighting
Each risk category carries a documented weight proportionate to your regulatory environment. A financial services firm subject to DORA weights cybersecurity and ICT concentration risk more heavily. A healthcare manufacturer subject to FDA QMSR weights quality and regulatory compliance more heavily. The weighting logic must be documented, not just the scores.
Assessment questionnaire by risk category
Minimum five risk categories, each with scored questions. Each question should return a score from 1 to 5 and reference the specific evidence required to validate the response. Self-reported answers without evidence validation are not sufficient for Critical and High tier vendors under any major regulatory framework.
Scoring methodology and risk tier output
The aggregate score maps to a risk tier: Critical, High, Medium, or Standard. The tier determines monitoring frequency, due diligence depth, and escalation path. The mapping must be documented so the tier assignment is reproducible and auditable, not a matter of individual assessor judgment on the day.
Evidence and documentation log
Every scored question must reference the supporting evidence: financial statements reviewed, certifications sighted, sanctions screening date and result, adverse media screening date and result, site visit report reference. Without an evidence log, the assessment is an opinion, not a documented finding that survives regulatory examination.
Review date and re-assessment triggers
The template must record the next scheduled assessment date and the conditions that trigger an unscheduled reassessment: sanctions designation, adverse media incident, financial distress signal, ownership change, data breach notification, or regulatory enforcement action against the vendor.
The Neotas enhanced due diligence checklist covers the specific evidence checks that go beyond self-reported questionnaire responses for Critical and High tier vendors, including adverse media in non-English languages and OSINT-based beneficial ownership investigation.
Use this framework as the foundation of your template. Adapt the category weights to your regulatory environment and risk appetite. The tier thresholds and weighting logic must be documented in your vendor risk assessment policy so scores are reproducible across assessors and over time.
75–100
Critical
Continuous monitoring, enhanced due diligence, board-level escalation, documented exit strategy required (DORA Art. 28(7))
50–74
High
Quarterly monitoring, enhanced due diligence, senior management review required
25–49
Medium
Bi-annual review, standard due diligence, questionnaire-based assessment acceptable
0–24
Standard
Annual review, questionnaire-based assessment, light-touch monitoring
| Risk Category | Weight | What it covers | Regulatory relevance |
|---|---|---|---|
| Financial stability | 20% | Credit rating, audited accounts, ownership changes, insolvency proceedings, financial restatements | OCC 2013-29 concentration risk; FCA PS7/23 financial viability |
| Cybersecurity and IT security | 25% | ISO 27001, SOC 2, breach history, incident response, data storage locations, sub-processors, pen testing frequency | DORA Arts. 28-30 (ICT vendors); NIST SP 800-161 Rev. 1 |
| Regulatory and compliance standing | 25% | Sanctions screening (OFAC, HMT, EU), adverse media, PEP status, licence standing, UFLPA Entity List, active investigations | UFLPA; UK Modern Slavery Act; DORA; ECCTA 2023 |
| Operational and quality resilience | 15% | BCP tested, key person dependencies, sub-contractor mapping, service disruption history, geographic concentration | FDA QMSR (healthcare); DORA Art. 26 scenario testing |
| ESG and reputational conduct | 15% | Modern slavery statement, labour rights violations, environmental enforcement, director misconduct, supply chain transparency | CS3D; German LkSG; UK Modern Slavery Act s.54 |
Scoring rule for Critical and High tier vendors: Self-reported answers without independently reviewed evidence cap at a score of 3 out of 5. Only independently verified answers score 5. This rule must be stated in the policy and enforced in the template, not left to assessor discretion.
This is a complete vendor risk assessment questionnaire template you can use directly. Each section maps to the scoring categories above. For Critical and High-risk vendors, each answer requires documented evidence. For Standard-tier vendors, self-reported responses are acceptable for initial screening only.
Section A: Financial Stability (10 questions — weight 20%)
Section B: Cybersecurity and Information Security (12 questions — weight 25%)
Section C: Regulatory and Compliance Standing (13 questions — weight 25%)
Section D: Operational and Quality Resilience (8 questions — weight 15%)
Section E: ESG and Reputational Conduct (7 questions — weight 15%)
Question 50 exposes the core gap in questionnaire-only programmes: A vendor with adverse media coverage in local-language press will answer “no” and the questionnaire will score it clean. Independent OSINT screening across 200+ languages is what surfaces what the vendor chooses not to disclose. The Neotas enhanced due diligence platform runs this as part of the standard vendor assessment workflow.
Neotas — Rated Chartis FCC50
Neotas combines the 50-question template above with OSINT-enhanced due diligence across 200+ languages, continuous monitoring, and a full regulatory audit trail. A FTSE 250 client using this approach found 27 material risk indicators where their questionnaire-only programme had flagged 3.
See how it worksThe template above is designed for export to Excel (.xlsx), Google Sheets, or XLS format. When building your working file, structure the spreadsheet across five tabs. Each tab serves a distinct function in the audit trail.
Tab 1: Vendor Register
One row per vendor. Columns: vendor ID, legal name, tier classification, last assessment date, next assessment date, assigned assessor, overall risk score, risk tier, and open remediation actions. This is the programme-level view regulators request first.
Tab 2: Assessment Form
The 50-question questionnaire with dropdown scoring (1, 3, 5), evidence reference fields, and auto-calculated category and overall scores. Lock the scoring logic and category weights on a protected sheet so assessors cannot modify the methodology mid-assessment.
Tab 3: Scoring Methodology
The weighting table, tier thresholds, and methodology rationale. This tab is your audit trail for the scoring design itself. Regulators under DORA and OCC Bulletin 2013-29 expect evidence that the scoring methodology was designed deliberately, not arrived at ad hoc.
Tab 4: Evidence Log
Linked to Tab 2. One row per piece of evidence per vendor: document type, date reviewed, reviewed by, storage location, and expiry or re-review date. This is the specific tab regulators examine when verifying that assessment scores are backed by reviewed evidence, not self-reported claims.
Tab 5: Monitoring Dashboard
Auto-populated from Tab 1. Shows vendors overdue for reassessment, open alerts, and tier distribution across the portfolio. For teams managing more than 50 vendors, this tab is where manual spreadsheet programmes begin to break down — version control, methodology drift, and audit trail gaps accumulate faster than most teams track.
Scaling consideration: The Neotas platform replaces the manual spreadsheet tabs above with a workflow that enforces the methodology, generates the audit trail automatically, and triggers real-time monitoring alerts. For teams managing more than 50 critical or high-risk vendors, a spreadsheet template creates version control, methodology drift, and audit trail gaps that a purpose-built platform resolves. The Neotas TPRM guide explains how the platform works.
A vendor risk assessment policy is the governance document that mandates the template, scoring methodology, and programme design across the organisation. Without it, the template is optional. With it, deviating from the template requires a documented exception with rationale and approval.
A policy aligned to DORA Article 28, FCA PS7/23, and OCC Bulletin 2013-29 must cover the following elements. Missing any one of them creates a documented gap that regulators identify during programme examination.
| Policy element | What it must cover | Regulatory mandate |
|---|---|---|
| Scope definition | Which vendors are in scope, defined by engagement type, data access, revenue dependency, and regulatory classification. Specific enough that any relationship is unambiguously in-scope or out-of-scope. | DORA Art. 28 (ICT providers); OCC 2013-29 (all third parties) |
| Risk tiering methodology | Criteria for classifying vendors as Critical, High, Medium, or Standard. Must be documented at policy level, not left to assessor discretion. Tier classification determines assessment depth and monitoring cadence. | FCA PS7/23; OCC 2013-29; DORA Art. 28 |
| Due diligence standards by tier | What specific checks are required at each tier. Critical and High vendors require independent screening, not just questionnaire responses. Standard vendors may use questionnaire alone for initial screening with periodic independent validation. | DORA Art. 28 (enhanced for critical); FCA PS7/23 |
| Monitoring cadence | Continuous for Critical (DORA requirement for designated ICT providers), quarterly for High, bi-annual for Medium, annual for Standard. Event-triggered reassessment conditions explicitly listed. | DORA Art. 28 (continuous for critical ICT); FCA PS7/23 |
| Escalation paths | What score or finding triggers senior management review, what triggers board notification, what triggers vendor exit recommendation. These thresholds must be documented before an incident forces the process. | FCA PS7/23; PRA SS2/21; DORA Art. 28 |
| Exit strategy requirements | For Critical vendors, a documented exit plan is required. The policy must mandate that no vendor is classified Critical without an exit plan in place. A contractual termination clause is not an exit plan. | DORA Art. 28(7); OCC 2013-29; FCA PS7/23 |
| Review cycle | Annual policy review at minimum, with immediate update required following any regulatory change affecting scope or standards. Policy version number and board approval date must be documented. | ISO 31000:2018; DORA Art. 28; all major frameworks |
See how to build a TPRM policy that meets DORA, FCA, and OCC requirements — the same governance document that mandates your vendor risk assessment template across the organisation.
Most vendor risk assessment templates cover the point-in-time assessment only. The process surrounding the template is what determines whether it produces managed risk or documented risk. These are the six stages of a complete vendor risk assessment process.
Initiation and pre-screening
Before the full template is completed, run a rapid pre-screen: sanctions list check, adverse media check, PEP check on beneficial owners, and a basic financial health signal. This filters out vendors that should never reach the full assessment stage, preventing teams from investing full assessment time on relationships that would be immediately disqualified.
Template completion and evidence collection
The 50-question template completed by the vendor and validated by an independent assessor. For Critical and High tier vendors, each answer must be backed by reviewed evidence logged in the evidence tab. Self-reported answers without evidence validation cap at a score of 3 regardless of what the vendor claims.
Independent intelligence validation
Adverse media screening across non-English sources, OSINT investigation of beneficial ownership structures, cross-referencing with regulatory enforcement databases, and financial health monitoring. This is the stage where the gap between questionnaire score and actual risk emerges. A FTSE 250 manufacturer found 27 vendors with material risk indicators where their questionnaire-only process had flagged three.
Scoring, tiering, and risk register update
Apply the scoring methodology, calculate category scores and overall score, assign the risk tier, and update the vendor register. Document the tier rationale, not just the score. The rationale is what survives regulatory examination when a regulator asks why a vendor received a particular tier classification.
Ongoing monitoring by tier
For Critical vendors: continuous real-time monitoring for sanctions designations, adverse media, financial distress signals, and ESG incidents. For High: quarterly re-screening. For Medium: bi-annual. For Standard: annual. A UK-regulated financial institution using Neotas continuous monitoring across 180 critical third parties generated 14 material alerts in the first 90 days — three required immediate board escalation and none had appeared in the prior annual review cycle.
Event-triggered reassessment
Certain events require immediate reassessment regardless of the scheduled cadence: ownership change, sanctions designation of the vendor or a beneficial owner, material adverse media incident, regulatory enforcement action, financial distress signal, or notification of a data breach or security incident affecting your data or service continuity.
The TPRM lifecycle guide covers how the vendor risk assessment process sits within the full vendor relationship from onboarding through to exit, including contract provisions and exit strategy requirements.
For organisations subject to NIST SP 800-161 Rev. 1 — mandatory for US federal contractors and widely adopted across critical infrastructure sectors including financial services, energy, healthcare, and defence — the vendor risk assessment questionnaire must align to the C-SCRM practice areas.
| NIST C-SCRM Practice | What it requires | Template coverage above |
|---|---|---|
| C-SCRM-1: Establish a programme | Board-approved policy, defined roles, documented risk appetite, review cycle | VRA Policy section above |
| C-SCRM-2: Identify and assess supply chain risks | Supplier categorisation, risk identification across categories, scored assessment | Scoring Framework + Sections A through E |
| C-SCRM-3: Establish controls | Control selection matched to risk tier, documented rationale, evidence of implementation | Scoring methodology + tier thresholds + evidence log (Tab 4) |
| C-SCRM-6: Manage supply chain risks | Ongoing monitoring, event-triggered reassessment, escalation to appropriate level | Process Stage 5 (monitoring) and Stage 6 (event-triggered reassessment) |
For federal contractors, the evidence log (Tab 4 of the Excel template) is the primary document during an assessment review. It must show that independent validation was conducted for each scored answer, not just that the vendor submitted documentation.
For technology vendors, software providers, cloud services, and ICT third parties subject to DORA designation, extend the standard 50-question template with these additional cyber-specific questions. Each one maps to a specific DORA or NIST SP 800-161 requirement.
Section F: Extended Cyber and ICT Questions (for technology vendors and DORA-designated providers)
See how the Neotas TPRM guide covers the full programme — risk tiering, governance, and regulatory alignment across DORA Arts. 28-30, FCA PS7/23, and OCC Bulletin 2013-29 — that the vendor risk assessment template sits within.
These are the specific gaps regulators find during examination of vendor risk assessment programmes. They appear in post-examination feedback from FCA, OCC, and DORA competent authority reviews.
Mistake 1: No evidence log behind the scores
A vendor risk assessment template that produces a score without an evidence log is an opinion document. Regulators ask: “What evidence did you review to assign this score?” If the answer is “the vendor completed the questionnaire,” that is not satisfactory for a Critical or High tier vendor. The evidence log is what converts a score into a documented, auditable finding.
Mistake 2: Screening conducted at onboarding only
A vendor that cleared sanctions screening in January can be designated on the OFAC SDN list in September. An annual assessment does not catch this. For Critical vendors, real-time or near-real-time sanctions monitoring is the current regulatory expectation under DORA Article 28 and FCA PS7/23. The template must specify the monitoring cadence and the tooling that enforces it between full assessments.
Mistake 3: Category weights not documented
If the template produces a composite score but the category weights are not recorded, the score is not reproducible. A different assessor applying different implicit weights produces a different score for the same vendor. Regulators test for methodological consistency across assessors and over time. The weight table must be in the policy or on a protected tab of the Excel template.
Mistake 4: No escalation threshold defined in the policy
A template that produces a High risk score with no documented process for what happens next is a documentation exercise. At what score does the result escalate to senior management? At what score does it go to the board? At what score does it trigger a vendor exit recommendation? These thresholds must be in the policy and must have been tested before an incident forces them into use.
Mistake 5: Template covers only the vendor’s self-reported view
Every question in a questionnaire-only template is answered by the team with the most incentive to present the vendor favourably. Independent screening of sanctions, adverse media, financial health, and PEP status is not a supplement to the template for Critical and High vendors. It is a required component of the template. Without it, the assessment scores a vendor’s willingness to disclose, not its actual risk profile.
The Neotas enhanced due diligence checklist covers the specific independent checks — beyond questionnaires — that surface the risks structured databases and self-assessments consistently miss, including OSINT across 200+ languages.
Free programme review
DORA Article 28, FCA PS7/23, and OCC 2013-29 have raised the documentation standard significantly since 2023. A 30-minute call with a Neotas specialist will identify the specific gaps in your current template and programme design before a regulator does.
Different stakeholders in a vendor risk assessment programme face different primary exposures. This section addresses each directly.
Compliance Director / Head of Compliance
Your exposure is a regulatory examination that finds programme gaps: missing evidence logs, undocumented scoring methodology, absent exit strategies, or annual reviews replacing continuous monitoring for Critical vendors. The specific artefacts regulators request are the evidence log, the policy version with approval date, and the methodology rationale. Most programmes cannot produce all three on demand.
General Counsel / Legal
Your exposure sits in three places: UFLPA rebuttable presumption if you import goods with potential Xinjiang supply chain inputs; CS3D and LkSG ESG obligations if you are a large EU company; and DORA ICT supplier obligations if you are an in-scope financial entity. The due diligence standard these regulations require is not satisfied by questionnaires. Independent verification, documentary traceability, and a maintained risk register are each required.
Procurement Director / Head of Vendor Management
Your operational exposure is a critical vendor failure with no fallback and no documented exit plan. Your strategic exposure is an ESG or sanctions controversy that forces a rapid vendor exit your contracts and operations are unprepared to execute. Continuous monitoring for Critical vendors and documented exit strategies for sole-source relationships are the two capabilities that most directly reduce your exposure.
Chief Risk Officer / Head of Operational Risk
The investment case for a mature vendor risk assessment programme is not difficult to make: companies without one experience 3.7 times higher revenue impact from third-party disruptions than companies with one (Deloitte, 2024). The cost of building a programme that passes examination is consistently lower than the cost of one significant incident or one regulatory enforcement action it prevents.
Ready to build a vendor risk assessment programme that holds up under examination?
Whether you need the template adapted to your regulatory environment, your scoring methodology reviewed against DORA and OCC standards, or your programme upgraded from questionnaire-only to OSINT-enhanced, a 30-minute conversation will tell you exactly where to start.
Rated Chartis FCC50 · US, UK and EU enterprise clients · 200+ languages, 190+ jurisdictions
Download the Vendor Risk Assessment Template and turn vendor risk into a controlled, repeatable process today.
The vendor due diligence process from initial screening through enhanced investigation — what questionnaires miss, how OSINT supplements structured data, and what regulators expect to see in a complete audit trail.
How to build a full TPRM programme aligned to DORA, FCA PS7/23, and OCC Bulletin 2013-29, covering risk tiering, due diligence depth by tier, governance structure, and critical third-party exit planning.
When standard vendor assessment is insufficient and enhanced investigation is required — OSINT techniques used in EDD, escalation triggers, and how Neotas delivers analyst-led reports for high-risk third parties and Critical tier vendors.
The specific checks beyond questionnaire responses that surface risks structured databases miss — adverse media in non-English languages, OSINT-based beneficial ownership investigation, and evidence validation standards for DORA and OCC examination.
The governance document that mandates your vendor risk assessment template across the organisation — required components, risk appetite definition, escalation thresholds, exit strategy requirements, and board approval process.
How to build the governance framework that the vendor risk assessment template sits within — covering ISO 31000, NIST SP 800-161, DORA framework requirements, and the combined approach most compliance-led organisations adopt.
How open-source intelligence is applied in vendor risk assessment — adverse media across 200+ languages, beneficial ownership investigation, sanctions network analysis, and how OSINT validates self-reported vendor questionnaire answers.
The broader due diligence framework — how vendor risk assessment fits within financial, legal, and operational due diligence, and how depth of investigation is calibrated to risk tier, transaction value, and regulatory obligation.
Every vendor you onboard is either strengthening your resilience—or quietly adding hidden exposure. Use this operational playbook and checklist not as theory, but as a live control you can run today. Build discipline into your procurement, prove audit readiness, and gain leadership confidence by showing vendor risk is being managed with precision.
👉 Download the full Vendor Risk Assessment Template now and put it into practice before the next audit or board review.
Templates are only powerful when adapted to your context. If you want a practical walkthrough of how to embed this vendor risk assessment framework into your procurement and compliance workflows, let’s talk. Our team can show you how to tailor the playbook, automate monitoring, and align with regulatory expectations.
👉 Schedule A Discovery Call with our experts today and turn vendor risk management into a competitive advantage.
Answers drawn from confirmed People Also Ask and search intent data for vendor risk assessment queries across US and UK search results.
financial crime compliance
financial crimes compliance
what is financial crime compliance
financial crime and compliance
financial crime and compliance management
financial crime compliance jobs
financial crime compliance solutions
financial crimes compliance jobs
compliance and financial crime
cost of financial crime compliance
enterprise financial crimes compliance
fcc financial crime compliance
anti financial crime compliance
conduct financial crime and compliance
financial crime compliance analyst
financial crime compliance analyst salary
financial crime compliance certification
financial crime compliance course
financial crime compliance definition
financial crime compliance framework
financial crime compliance in banking
financial crime compliance meaning
financial crime compliance risk management
global financial crimes compliance
true cost of financial crime compliance global report
what is financial crimes compliance
Neotas Enhanced Due Diligence covers 600Bn+ Archived web pages, 1.8Bn+ court records, 198M+ Corporate records, Global Social Media platforms, and more than 40,000 Media sources from over 100 countries to help you screen & manage risks.
Download the Neotas Vendor Risk Assessment Template and turn vendor risk into a controlled, repeatable process today.
vendor risk assessment template
vendor risk assessment template xls
vendor risk assessment questionnaire template
vendor risk assessment template excel
vendor management risk assessment template
bank vendor risk assessment template
free vendor risk assessment template
vendor risk management assessment template
third-party vendor risk assessment template
thirdparty vendor risk assessment template
vendor risk assessment questionnaire template pdf
free vendor risk assessment questionnaire template
vendor risk assessment template equation
vendor risk assessment questionnaire template excel
it vendor risk assessment template excel
vendor risk assessment template pdf
third party vendor risk assessment template
vendor risk assessment template – excel
soc 2 vendor risk assessment template
vendor risk assessment report template
it vendor risk assessment template
free vendor risk assessment template xls
vendor risk assessment template free
vendor risk assessment template xls excel
vendor risk assessment software
customer and vendor risk assessment software
software for vendor risk assessment
compare vendor risk assessment software solutions
vendor risk assessment
vendor management risk assessment
vendor risk assessment software
vendor security risk assessment
vendor risk assessment tools
vendor risk assessment template
automated vendor risk assessment
vendor risk assessment process
3rd party vendor risk assessment
third party vendor risk assessment
customer and vendor risk assessment software
vendor risk assessment checklist
vendor risk assessment questionnaire
information security vendor risk assessment
vendor risk assessment report
vendor risk assessment matrix
third party vendor risk assessment example
risk assessment third party vendor
vendor risk assessment criteria
hipaa vendor risk assessment
vendor cyber risk assessment
vendor risk assessment for banks
vendor risk assessment example
what is vendor risk assessment
vendor risk assessment tool
vendor risk assessment template xls
risk assessment for vendor management
vendor risk assessment questionnaire pdf
nist vendor risk assessment questionnaire
vendor financial risk assessment
vendor risk assessment services
ai vendor risk assessment
what is a vendor risk assessment
vendor due diligence risk assessment
vendor risk assessment policy
how to perform vendor risk assessment
vendor risk assessment program
vendor risk assessment procedure
vendor risk assessment questionnaire template
vendor management risk assessment questionnaire
vendor management risk assessment matrix
vendor risk management assessment matrix
nist vendor risk assessment
vendor risk assessment template excel
vendor risk assessment framework
vendor information security risk assessment
vendor risk assessment servicenow
vendor management risk assessment template
bank vendor risk assessment template
free vendor risk assessment template
risk assessment vendor selection
health risk assessment vendor
healthcare vendor risk assessment
vendor risk assessment form
vendor risk assessment questionnare
vendor risk assessment questions
risk assessment vendor management
vendor risk management assessment template
vendor risk assessment jobs
bank vendor management risk assessment
risk assessment for vendor qualification
vendor risk assessment checklist xls
sample vendor risk assessment
compare vendor risk assessment tools using ai for public procurement contracts.
third-party vendor risk assessment
vendor risk assessment library
vendor risk assessment resume
vendor risk assessment definition
third-party vendor risk assessment template
thirdparty vendor risk assessment template
vendor management risk assessment sample
risk assessment thirdparty vendor
vendor cybersecurity risk assessment
continuous vendor risk assessment
third party vendor risk assessment questionnaire
vendor qualification risk assessment
vendor risk assessment pdf
third-party vendor risk assessment example
vendor risk assessment tools ai public procurement contracts
social media archive services this vendor can also provide risk assessment monitoring
vendor risk assessment best practices
thirdparty vendor risk assessment example
vendor risk assessment scorecard
vendor management risk assessment
vendor risk assessment report sample
vendor risk management assessment
vendor risk assessment audits
cbanc network vendor management risk assessment
vendor risk assessment, reasonable security
vra vendor risk assessment
vendor risk assessment tools tech vendor credibility
vendor risk assessment questionnaire template pdf
sample vendor risk assessment questionnaire
free vendor risk assessment questionnaire template
what is vendor risk assessment process?
vendor risk assessment template equation
vendor risk assessment (vra)
vendor risk assessment process steps
vendor risk assessment methodology
how to do a vendor risk assessment
vendor management risk assessment
risk assessment for vendor management
vendor management risk assessment questionnaire
vendor management risk assessment matrix
vendor risk management assessment matrix
vendor management risk assessment template
risk assessment vendor management
vendor risk management assessment template
bank vendor management risk assessment
vendor management risk assessment sample
vendor management risk assessment
vendor risk management assessment
network vendor management risk assessment
vendor risk management business risk assessment
vendor management risk assessment
risk assessment for vendor management
vendor management risk assessment questionnaire
vendor management risk assessment matrix
vendor risk management assessment matrix
vendor management risk assessment template
risk assessment vendor management
vendor risk management assessment template
bank vendor management risk assessment
vendor management risk assessment sample
vendor management risk assessment
vendor risk management assessment
network vendor management risk assessment
vendor risk management business risk assessment vendor management risk assessment
risk assessment for vendor management
vendor management risk assessment questionnaire
vendor management risk assessment matrix
vendor risk management assessment matrix
vendor management risk assessment template
risk assessment vendor management
vendor risk management assessment template
bank vendor management risk assessment
vendor management risk assessment sample
ffiec vendor management risk assessment
vendor risk management assessment
vendor management risk assessment
vendor risk management business risk assessment
vendor risk assessment
vendor management risk assessment
vendor risk assessment software
vendor security risk assessment
vendor risk assessment tools
vendor risk assessment template
automated vendor risk assessment
vendor risk assessment process
3rd party vendor risk assessment
third party vendor risk assessment
customer and vendor risk assessment software
vendor risk assessment checklist
vendor risk assessment questionnaire
information security vendor risk assessment
vendor risk assessment report
vendor risk assessment matrix
third party vendor risk assessment example
risk assessment third party vendor
vendor risk assessment criteria
hipaa vendor risk assessment
vendor cyber risk assessment
vendor risk assessment for banks
vendor risk assessment example
what is vendor risk assessment
vendor risk assessment tool
vendor risk assessment template xls
risk assessment for vendor management
vendor risk assessment questionnaire pdf
nist vendor risk assessment questionnaire
vendor financial risk assessment
vendor risk assessment services
ai vendor risk assessment
what is a vendor risk assessment
vendor due diligence risk assessment
vendor risk assessment policy
how to perform vendor risk assessment
vendor risk assessment program
vendor risk assessment procedure
vendor risk assessment questionnaire template
vendor management risk assessment questionnaire
vendor management risk assessment matrix
vendor risk management assessment matrix
nist vendor risk assessment
vendor risk assessment template excel
vendor risk assessment framework
vendor information security risk assessment
vendor risk assessment
vendor management risk assessment template
bank vendor risk assessment template
free vendor risk assessment template
An advanced Due Diligence Platform that leverages AI to join the dots between Social Media, Corporate Records, Adverse Media and Open Source Intelligence (OSINT).
Our platform offers the most advanced insights, so you can respond to risks immediately.
With insights spanning global jurisdictions, your business is never in the dark.
Whether you manage a small portfolio or a global enterprise, our platform adapts to your needs
Ready to Transform Your Third-Party Risk Approach?
| Cookie | Duration | Description |
|---|---|---|
| AWSALBTG | 7 days | AWS Application Load Balancer Cookie. Load Balancing Cookie: Used to encode information about the selected target group. |
| AWSALBTGCORS | 7 days | AWS Classic Load Balancer Cookie: Used to map the session to the instance. This cookie is identical to the original ELB cookie except for the attribute &SameSite=None; |
| cookielawinfo-checkbox-advertisement | 1 year | Set by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Advertisement" category . |
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| CookieLawInfoConsent | 1 year | Records the default button state of the corresponding category & the status of CCPA. It works only in coordination with the primary cookie. |
| debug | never | Cookie used to debug code and website issues |
| shown | session | Session cookie to control number of times a pop up is shown. |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
| Cookie | Duration | Description |
|---|---|---|
| __cf_bm | 30 minutes | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
| AnalyticsSyncHistory | 1 month | Used to store information about the time a sync took place with the lms_analytics cookie |
| bcookie | 2 years | LinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognize browser ID. |
| bscookie | 2 years | LinkedIn sets this cookie to store performed actions on the website. |
| lang | session | LinkedIn sets this cookie to remember a user's language setting. |
| lidc | 1 day | LinkedIn sets the lidc cookie to facilitate data center selection. |
| UserMatchHistory | 1 month | LinkedIn sets this cookie for LinkedIn Ads ID syncing. |
| Cookie | Duration | Description |
|---|---|---|
| li_gc | 2 years | Used to store consent of guests regarding the use of cookies for non-essential purposes |
| rl_anonymous_id | 1 year | Generates an unique anonymous Id to identify a user and attach to a subsequent event. |
| rl_user_id | 1 year | to store a unique user ID for the purpose of Marketing/Tracking |
| Cookie | Duration | Description |
|---|---|---|
| _ga | 2 years | The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors. |
| _gat_gtag_UA_107495977_1 | 1 minute | Set by Google to distinguish users. |
| _gat_UA-107495977-1 | 1 minute | A variation of the _gat cookie set by Google Analytics and Google Tag Manager to allow website owners to track visitor behaviour and measure site performance. The pattern element in the name contains the unique identity number of the account or website it relates to. |
| _gcl_au | 3 months | Provided by Google Tag Manager to experiment advertisement efficiency of websites using their services. |
| _gid | 1 day | Installed by Google Analytics, _gid cookie stores information on how visitors use a website, while also creating an analytics report of the website's performance. Some of the data that are collected include the number of visitors, their source, and the pages they visit anonymously. |
| attribution_user_id | 1 year | This cookie is set by Typeform for usage statistics and is used in context with the website's pop-up questionnaires and messengering. |
| CONSENT | 2 years | YouTube sets this cookie via embedded youtube-videos and registers anonymous statistical data. |
| Cookie | Duration | Description |
|---|---|---|
| _fbp | 3 months | This cookie is set by Facebook to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising, after visiting the website. |
| fr | 3 months | Facebook sets this cookie to show relevant advertisements to users by tracking user behaviour across the web, on sites that have Facebook pixel or Facebook social plugin. |
| IDE | 1 year 24 days | Google DoubleClick IDE cookies are used to store information about how the user uses the website to present them with relevant ads and according to the user profile. |
| test_cookie | 15 minutes | The test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies. |
| VISITOR_INFO1_LIVE | 5 months 27 days | A cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface. |
| YSC | session | YSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages. |
| yt-remote-connected-devices | never | YouTube sets this cookie to store the video preferences of the user using embedded YouTube video. |
| yt-remote-device-id | never | YouTube sets this cookie to store the video preferences of the user using embedded YouTube video. |
| yt.innertube::nextId | never | This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen. |
| yt.innertube::requests | never | This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen. |