Vendor Risk Assessment: The 50-Point Checklist Before You Sign
Your vendors have access to your data, your customers, and your systems. Here's how to vet them before it's too late.
A meaningful share of small-business data incidents trace back to a third-party vendor, not an internal system
Directionally illustrative figures — actual breach costs vary enormously by incident scope and industry.
Signing a contract is the same decision as handing over a login
A SaaS vendor's sign-up flow takes five minutes and asks for a credit card. What it actually grants, on the other side, is standing access to customer records, employee PII, and often a live connection into your financial systems — with none of the scrutiny you'd apply before handing a stranger your bank login. The 50-point checklist below is the scrutiny that sign-up flow skips.
Vendor risk assessment is due diligence you do once, before signing — not paranoia after something goes wrong.
Security checklist (20 points)
Security requirements
- SOC 2 Type II certification (not Type I)
- ISO 27001 certification (bonus)
- Encryption at rest (AES-256)
- Encryption in transit (TLS 1.3+)
- Two-factor authentication (required, not optional)
- SSO/SAML support (Okta, Azure AD, Google)
- Role-based access controls
- Audit logs (who accessed what, when)
- Data residency options (US, EU, etc.)
- GDPR compliance (if EU customers)
- HIPAA compliance (if healthcare data)
- Penetration testing (annual, third-party)
- Vulnerability disclosure program
- Incident response plan (documented)
- Breach notification SLA (24-72 hours)
- Backup frequency (daily minimum)
- Disaster recovery plan (tested)
- RTO/RPO defined (under 4 hours ideal)
- Employee background checks
- Security training (annual, documented)
Business continuity (15 points)
Continuity requirements
- Uptime SLA (99.9% minimum)
- SLA credits (automatic, not requested)
- Support response times (documented)
- 24/7 support availability
- Dedicated CSM (for enterprise)
- Escalation path (documented)
- Contract term (1-3 years max)
- Termination clause (30-60 days)
- Data export format (CSV, JSON, API)
- Data export timeline (under 30 days)
- Transition assistance (included)
- Price increase cap (5-10%/year)
- Auto-renewal opt-out (90 days)
- Liability cap (reasonable, not unlimited)
- Insurance coverage ($1M+ cyber liability)
The data export trap: vendors make it easy to get data in, impossible to get it out. Require export in standard formats (CSV, JSON) before signing.
Financial health (15 points)
Financial due diligence
- Years in business (3+ minimum)
- Funding stage (Series B+ stable)
- Revenue growth (positive trend)
- Customer count (100+ minimum)
- Customer retention rate (90%+)
- Churn rate (under 10%/year)
- Profitability (break-even or better)
- Customer references (3+ provided)
- Case studies (relevant to your size)
- G2/Capterra reviews (4+ stars)
- Employee count (growing, not shrinking)
- LinkedIn activity (active, professional)
- News mentions (positive, recent)
- Leadership stability (low exec turnover)
- Acquisition risk (low, or plan disclosed)
Illustrative failure risk by vendor age (directional, not a guarantee)
The three due-diligence categories, at a glance
| Category | What it protects against | Single biggest red flag |
|---|---|---|
| Security (20 pts) | A breach that exposes customer or employee data | No SOC 2 / ISO certification, or a Type I instead of Type II report |
| Business continuity (15 pts) | Being stuck with a tool that fails you or traps your data | No documented data-export path or timeline |
| Financial health (15 pts) | The vendor disappearing or getting acquired mid-contract | Can't produce customer references or shows shrinking headcount |
The bottom line
A vendor that fails the security checklist is a breach risk. One that fails business continuity is a migration project waiting to happen. One that fails financial health might not exist in two years. Any one category failing is enough to walk away or negotiate remediation before signing — not after.
Run the free BusinessAdvisor.Guide audit to see vendor risk scores for your current software stack.
- Software Vendor Risk Assessment: The Questions You Should Ask Before Signing
- The SaaS Security Checklist: What to Verify Before Signing Up
- Creating a Vendor Management Framework for Your Growing Business
- Evaluating Vendor Support Quality Before You Sign
- Practical decision guide: health information privacy and security
- Practical decision guide: health information privacy and security
