- The supplier questionnaire results (ATL-027)
- The remote access pathway inventory (ATL-026) rows for the vendor
- The contract or terms of service, for incident-notification and data-handling language
Vendor Risk Assessment Worksheet
A per-vendor decision record that ties together what the vendor touches, what their questionnaire said, what the contract commits them to, and which access pathways they hold — ending in an owned decision: approve, approve with conditions, or decline.
Purpose, inputs, and completion
Purpose. Questionnaires collect information; this worksheet is where the information becomes a decision. Each vendor gets one row that states what they can reach, what they claimed, what the contract binds them to, which pathways they hold, and what you decided — with conditions owned and dated rather than wished. It converts vendor management from a feeling about relationships into a record of choices.
When to use it. Assess vendors in order of reach: whoever can touch contract data, production systems, or your network comes first, whatever their invoice size. Complete a row per vendor from the questionnaire and pathway inventory rather than from memory of the sales relationship, and record the decision even when it is easy — a page of 'approve' decisions with citations is a real record. Re-run at every renewal and annually for critical vendors, and work the conditions table until it is empty or current.
- Write down what the vendor actually touches — data, systems, access, deliveries — before forming any view; risk follows reach.
- Cite the vendor's questionnaire (ATL-027) and pathway rows (ATL-026) in the record; an assessment citing neither is an opinion.
- Check the contract for incident-notification terms; deep access plus no duty to tell you about their breach is a condition waiting to be written.
- Record a decision — approve, approve with conditions, or decline — and give every condition a named owner and a due date; an unowned condition is a wish.
Evidence, validation, and failure modes
- A per-vendor risk record with a dated decision
- A conditions list with owners and due dates
- Cross-references tying each decision to questionnaire and pathway evidence
- Pick one approved-with-conditions vendor and check that each condition has an owner and a due date that has not silently passed.
- Cross-check three vendors against ATL-026: every access pathway they hold appears in their assessment row.
- Assessments happen once at onboarding and never at renewal, so the record describes the vendor as it was, not as it is.
- Conditions are written but never tracked, and 'approve with conditions' quietly becomes plain 'approve'.
- OT vendors get scored on their paperwork while their standing modem into the line — the actual risk — sits outside the assessment entirely.
Practices and requirements this artifact relates to
Brilliant at the Basics practices
NIST SP 800-171 Rev. 2
NIST SP 800-171 Rev. 3
Relationships are mapped support, not equivalence: completing this artifact documents work relevant to these requirements and does not by itself address any of them. Retention: Retain each vendor's assessments across cycles for the life of the relationship; the decision trail — approve, conditions, decline — is exactly what a reviewer will ask to see.
Preview — exactly what prints
Vendor Risk Assessment Worksheet
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
Questionnaires collect information; this worksheet is where the information becomes a decision. Each vendor gets one row that states what they can reach, what they claimed, what the contract binds them to, which pathways they hold, and what you decided — with conditions owned and dated rather than wished. It converts vendor management from a feeling about relationships into a record of choices.
How to use it
Assess vendors in order of reach: whoever can touch contract data, production systems, or your network comes first, whatever their invoice size. Complete a row per vendor from the questionnaire and pathway inventory rather than from memory of the sales relationship, and record the decision even when it is easy — a page of 'approve' decisions with citations is a real record. Re-run at every renewal and annually for critical vendors, and work the conditions table until it is empty or current.
Vendor risk register
One row per vendor. The decision column admits three values only — approve, approve with conditions, decline — because 'we should look into them sometime' is not a decision.
Rows beginning EXAMPLE: show the expected shape — replace them with your own.
| Vendor | What the vendor touches (data / systems / access) | Criticality | Questionnaire result summary (ATL-027) | Incident-notification terms in contract? | Access pathway reference (ATL-026) | Risk decision (approve / conditions / decline) | Conditions and owner | Review date |
|---|---|---|---|---|---|---|---|---|
| EXAMPLE: Machine builder (packaging line) | Remote maintenance access to line PLCs; supplies spare parts and firmware | High — line is down without them | Partial: MFA on their jump-host accounts; no restore-test date given | No — notification clause absent | ATL-026 rows 4–5 (support tunnel) | Approve with conditions | Notification clause at renewal; restore-test evidence — owner: procurement lead | 2026-12-01 |
| EXAMPLE: Payroll SaaS | Employee PII; no contract data, no plant access | Medium | Yes with evidence, dated 2026-05 | Yes — 48-hour notification | ATL-026 row 9 (admin portal) | Approve | None | 2027-06-01 |
Conditions tracking
Every 'approve with conditions' spawns rows here. This table is where those conditions either get done or get honestly re-decided — never silently forgotten.
Rows beginning EXAMPLE: show the expected shape — replace them with your own.
| Condition | Vendor | Owner | Due date | Status |
|---|---|---|---|---|
| EXAMPLE: Add 72-hour incident-notification clause at contract renewal | Machine builder (packaging line) | Procurement lead | 2026-11-30 | Drafted; with counsel |
OT vendors deserve extra attention
A vendor who dials into your controllers, stocks your spare parts, or ships firmware to your plant holds risks no office-vendor assessment captures. Ask three extra questions: how their remote maintenance sessions are brokered and logged on your side (their ATL-026 rows are the answer, or the gap); where spare parts and replacement units actually come from, since a gray-market drive with unknown firmware goes straight into production; and how firmware is obtained and verified before it reaches a controller. Any access or update change that follows from this assessment is coordinated with the vendor and the process owner through a maintenance window — an assessment that strands the plant without support has failed at its own job.
Document control, version history, and approval
An artifact without an owner, a review date, and an approval trail is a snapshot, not a record. Complete this section before the document is used, and update it at every review.
| Field | Entry |
|---|---|
| Document owner (named person) | |
| Suggested owner role | IT leader or compliance lead |
| Approval authority | Executive sponsor |
| Review frequency | At vendor onboarding, at contract renewal, and annually for critical vendors |
| Next scheduled review | |
| Storage location of the completed document | |
| Retention | Retain each vendor's assessments across cycles for the life of the relationship; the decision trail — approve, conditions, decline — is exactly what a reviewer will ask to see. |
Version history
| Version | Date | Author | Summary of change | Approved by |
|---|---|---|---|---|
Review and approval
| Reviewed by | Role | Date | Signature / initials |
|---|---|---|---|
Fill this in inside your own environment, not on any public website or unapproved cloud tool. A completed copy may reveal your security posture: never include CUI, export-controlled data, credentials or keys, unremediated vulnerability details, network diagrams, or customer-sensitive information beyond what the artifact strictly needs, and store the completed document with the same care as the systems it describes.
This is independent educational material. Completing it documents your work and produces records a reviewer can examine — it does not, by itself, implement a safeguard, satisfy any NIST SP 800-171 requirement, establish compliance with DFARS or CMMC, or replace your own analysis within your defined system boundary. Requirement references are mapped relationships, not equivalence claims. Tailor every section to your technical, operational, contractual, regulatory, and safety requirements.