A third-party risk assessment answers two different questions, and programmes go wrong when they run them as one. The first is inherent risk: how much could this relationship hurt us before any control is considered, which decides the tier and therefore the depth of everything that follows. The second is control risk: does this provider actually operate the safeguards its tier demands, which is due diligence. This guide covers both, with the twelve tiering questions, the rules that turn a score into a tier, the depth each tier calls for, and how questionnaire responses are scored so that two reviewers reach the same answer.
What this guide covers
- Inherent risk first: why the third-party risk assessment starts before due diligence
- The twelve tiering questions
- From score to tier, and what the tier drives
- Control risk second: the third-party risk assessment as due diligence
- Scoring a third-party risk assessment consistently
- Recording the third-party risk assessment
- The mistakes that make a third-party risk assessment fail
- When a third-party risk assessment is repeated
- Where the instruments come from
- Frequently asked questions about third-party risk assessment

Inherent risk first: why the third-party risk assessment starts before due diligence
Every regime says effort must be proportionate to risk. NIST CSF 2.0 GV.SC-04 says suppliers are prioritised by criticality; DORA Article 28(1)(b) requires management of third-party risk in proportion to the nature, scale, complexity and importance of the dependency; 23 NYCRR 500.11(a)(1) requires identification and risk assessment of providers; the Interagency Guidance repeats “commensurate with risk” throughout. None of them says how to measure it. Tiering is the answer: a fixed set of questions about the arrangement itself, asked from the intake form rather than the provider’s marketing, whose answers place the relationship in a band.
The band decides which questionnaire is sent, which contract form is used, how often the provider is reassessed and whether an exit plan is required. A third-party risk assessment that runs due diligence first and tiers afterwards has done the review at the wrong depth, and often at one depth for everyone.
The twelve tiering questions
| # | Domain | Question | Scored as |
|---|---|---|---|
| 1 | Function | Does the service support a critical or important function? | Yes forces the Critical tier |
| 2 | Data | Most sensitive class the provider will hold, access or transmit | None, internal, confidential, customer personal or regulated |
| 3 | Volume | How many records or how much regulated data | Banded |
| 4 | Access | Network, system or physical access to the organisation | None, limited, standard, privileged |
| 5 | Customers | Does the provider interact with customers directly? | No, indirect, direct |
| 6 | Substitutability | How quickly could the service be replaced? | Days, weeks, months, not practically |
| 7 | Subcontracting | Does the provider rely on subcontractors? | No, disclosed, unknown |
| 8 | Location | Where is the service delivered and data processed? | Domestic, approved jurisdictions, other |
| 9 | Regulatory reach | Do regimes impose specific obligations on this arrangement? | None, one, several |
| 10 | Financial exposure | Annual spend and the cost of the provider’s failure | Banded |
| 11 | Concentration | Does this provider or its group already support other critical functions? | No, yes |
| 12 | Novelty | Is the service or technology new to the organisation? | No, yes |
Each answer in the third-party risk assessment carries a value and each question a weight, and the weighted total is read against thresholds the committee approves. Question 1 is the exception: a yes forces the Critical tier whatever the score, because the critical-function determination is made about the function and every provider supporting it inherits it.
From score to tier, and what the tier drives
| Tier | Due diligence depth | Contract form | Reassessment | Exit plan |
|---|---|---|---|---|
| Critical | Enhanced questionnaire, viability check, assurance review, resilience assessment, on-site or remote assessment | Critical form with every mandatory provision | Annual | Required and tested |
| High | Enhanced questionnaire, viability check, assurance review | Standard form plus the critical clauses assessed as needed | Annual | Where not easily substitutable |
| Standard | Standard questionnaire, assurance review, screening | Standard form | Every two years | Not required |
| Low | Lite questionnaire, screening | Standard terms | Every three years or on change | Not required |
A tier from the third-party risk assessment may be raised on judgement at any time with the reason recorded. It is lowered only through the committee, on a written case. That asymmetry is deliberate: the cost of over-assessing one provider is capacity; the cost of under-assessing one is the finding an examiner writes.
Control risk second: the third-party risk assessment as due diligence
With the tier set, the third-party risk assessment moves to the provider’s controls. The Interagency Guidance lists fourteen due diligence factors, from strategies and goals through information security, operational resilience, incident management, physical security and reliance on subcontractors to insurance. The questionnaire covers the security and resilience factors; separate checks cover financial condition, screening of the entity and its principals, data protection where personal data is involved, and assurance reports. Our companion guide to the vendor security questionnaire covers the questions themselves from the provider’s side.
The depth is the tier’s decision, not the reviewer’s. A Lite questionnaire of around twenty questions is right for a provider with no data and no access; an Enhanced questionnaire across twenty control domains is right for a provider supporting a critical function. Sending the Enhanced questionnaire to everyone is not caution; it spends the capacity the critical providers needed and trains the team to skim.
Scoring a third-party risk assessment consistently
Two reviewers reading the same response should reach the same score, and that only happens with a written rule. Score each question from 3 to 0: a control in place, evidenced and meeting the requirement; in place and evidenced with an acceptable limitation; asserted but not evidenced, or evidenced but short of the requirement; absent or unanswered. A provider’s “not applicable” is not accepted until the reviewer agrees; a provider that marks encryption not applicable to a service that stores your data has answered zero.
Evidence is what separates the scores. A certificate with a scope statement, an assurance report covering the control and period, a dated policy extract, a configuration export, a penetration test summary or the reviewer’s own observation count. Marketing material, a summary of a policy, or a statement that testing is performed do not. Ten questions are marked mandatory, covering multi-factor authentication, encryption in transit and at rest, backups, incident notification time, subcontractors, data locations, data return, independent assurance and patching; a zero on any of them is a finding regardless of the total score.
Recording the third-party risk assessment
The assessment is only evidence if it leaves a record an examiner can follow from the inventory to the decision. Four records do that. The completed tiering questionnaire with its score, date and assessor, kept as the basis of the tier. The scored questionnaire with the reviewer’s notes and the evidence obtained, kept with the due diligence report. The report itself, stating what was assessed, what was found, the severity of each finding and the conditions of approval. And the selection decision record, naming the alternatives considered, the conflicts of interest declared and the authority that approved.
Every finding raised in a third-party risk assessment goes into the findings register on the day it is raised, with a severity, an owner and a due date, so that it is tracked from before the contract is signed rather than rediscovered at the first relationship review. A finding that will not be remediated is closed by reference to an approved exception, never silently.
The mistakes that make a third-party risk assessment fail
Answering the tiering questions from the provider’s website rather than from what the provider can reach. Describing the data by the service rather than by access, so a marketing platform “holds email addresses” when its support staff can read every message. Accepting a certificate without reading its scope. Sending one questionnaire to every tier. Treating the provider’s “not applicable” as an answer. And closing the assessment without a decision record, so that nobody can later say who approved the provider and on what conditions.
When a third-party risk assessment is repeated
At the reassessment cadence the tier sets; on any change notified by the provider, such as a change of control, a new subcontractor, a change of location or a change in assurance scope; on any incident; and when the organisation’s own use of the service changes, for example when a pilot becomes production. Each repeat re-runs the tiering questions first. A relationship can move outside appetite through the provider’s own changes, and a reassessment that only re-sends the questionnaire will miss it.
Where the instruments come from
The TPRM Toolkit ships the third-party risk assessment as a working set: the tiering methodology and its scoring workbook with the twelve questions and thresholds pre-loaded, the three questionnaires at 21, 84 and 136 questions generated from one question bank, the scoring guide, and the due diligence procedure that sets the depth by tier, each mapped to the regime that requires it. For where the assessment sits in the wider programme, read the TPRM lifecycle and the TPRM policy guides; the vendor due diligence checklist takes the control-risk half further, fourth-party risk covers the subcontractor question, and the third-party risk management framework shows where the assessment sits across the regimes.
Frequently asked questions about third-party risk assessment
How is a third-party risk assessment different from a vendor security questionnaire?
The questionnaire is one instrument inside the assessment. The assessment also includes the tiering that decides which questionnaire to send, the financial, screening, data protection and resilience checks, the assurance report review and the written report and decision at the end.
Can we rely on a SOC 2 report instead of a questionnaire?
Partly. A SOC 2 Type 2 report is strong evidence for the controls and period it covers, and the questionnaire can be shortened where the report answers a question. The report’s scope, exceptions and carved-out subservice organisations still have to be read, and the questions it does not cover still have to be asked.
How long does a third-party risk assessment take?
Tiering takes an hour from a completed intake form. Due diligence for a critical provider is measured in weeks, mostly waiting for the provider’s responses and evidence, which is why the questionnaire goes out at the start of planning rather than the end.
Who signs it off?
The relationship owner writes and signs the report; each reviewing function signs its section; the TPRM function accepts it; and the approver the tier requires, the committee for critical arrangements, records the selection decision with the conditions of approval.