Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Third party risk assessment findings workflow from rating to closure

Third Party Risk Assessment Findings and Remediation 2026

Third party risk assessment findings are the point at which a vendor assessment either changes something or becomes paperwork. Many organisations send questionnaires, score the answers and file the result, yet the gaps found never reach a named owner or a deadline. The assessment then exists to satisfy an auditor, not to reduce risk.

This guide explains how to record third party risk assessment findings, rate them consistently, agree remediation with the supplier, and decide when the right answer is to accept a risk or end the relationship.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

What counts as a third party risk assessment finding

A finding is a specific gap between what a supplier does and what you require, backed by evidence. “The supplier has weak security” is an opinion. “The supplier could not show that administrator access is reviewed, and its latest penetration test is over two years old” is a finding. Each one should name the requirement, the evidence reviewed, the gap and the affected service.

Findings come from several sources: questionnaire answers, reviewed certificates and audit reports, technical scans, on-site or remote assessments, incident notifications and performance reviews. Whichever source they come from, they should land in one register so you can see the full position for each supplier. Our guide to the third-party risk assessment covers how the underlying assessment is run.

Free third-party risk assessment

How much risk does this vendor bring?

Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.

Start the free vendor risk assessment →  or  View premium report sample

Rating third party risk assessment findings consistently

Two assessors looking at the same gap should reach the same rating. That only happens with a written scale. A simple four-level scale is enough for most programmes.

RatingMeaningTypical response
CriticalGap could directly cause serious harm or a regulatory breach for a critical serviceImmediate escalation; remediate or suspend use
HighSignificant control weakness in an important areaDated remediation plan, short deadline
MediumWeakness with compensating controls or limited impactRemediation in the normal cycle
LowMinor or documentation gapTrack; fix at next review

Rate the finding against the importance of the service, not just the supplier’s control. The same missing control means more for a vendor holding customer data than for one supplying office stationery. That is why criticality tiering matters; see our explanation of vendor risk tiering for how to set tiers that feed the rating.

Separate inherent risk from residual risk

Inherent risk is the exposure before controls; residual risk is what remains after the supplier’s controls and yours. Record both. A finding may rate high on its own but sit at medium residual risk if you encrypt the data before it reaches the supplier. Writing the reasoning down lets a reviewer follow your decision later.

Agreeing remediation with the supplier

Once third party risk assessment findings are rated, each needs an action. A workable remediation record includes the action required, the supplier owner, your internal owner, a target date, the evidence you will accept as proof of closure and the interim measure if the fix takes time.

Deadlines should follow the rating. Set shorter windows for critical and high items and longer ones for medium and low. Avoid open-ended commitments such as “will improve in future”. If the supplier proposes a date beyond your window, treat that as a decision to be approved, not a default.

Interim compensating controls

Some fixes take months. In the meantime you may be able to reduce exposure yourself: limit the data shared, add monitoring, restrict access to a smaller group, or add a manual check. Record these as compensating controls with an owner and an end date, so they do not become permanent by neglect.

Deciding whether to accept, transfer or avoid

Not every finding will be fixed. Sometimes the supplier will not change, the cost is out of proportion, or the risk is small. In those cases there are three legitimate routes.

  • Accept. A named person with authority signs off the residual risk for a defined period, with the reason recorded.
  • Transfer or share. Add a contractual protection, such as an audit right, a service credit or insurance, so the consequence is shared.
  • Avoid. Stop using the supplier or the affected service, and plan the exit. Our vendor offboarding checklist covers the steps.

Acceptance should never sit with the person who runs the relationship alone. The accountable owner for the risk, often a senior manager or the risk committee, should decide, and the decision should expire so it is reviewed again.

Closing third party risk assessment findings with evidence

A finding is closed only when evidence shows the gap no longer exists. A supplier’s email saying “done” is not evidence. Accept a screenshot of a configuration, a policy with an approval date, a fresh test report or a re-run scan. Have someone other than the original assessor verify the closure for critical and high items, and record the date and reviewer.

Track a few figures each quarter: the number of open findings by rating, the number overdue, the average time to close and the number of accepted risks nearing expiry. These give the security or risk committee a clear view without wading through individual records. For external guidance on supply chain risk practice, NIST publishes SP 800-161 Rev. 1 on cybersecurity supply chain risk management, which is a useful reference for structuring the programme.

Third party risk assessment findings and fourth parties

Some findings concern the supplier’s own suppliers. If a vendor relies on a subcontractor to host or process your data, a gap at that layer is still your exposure. Ask the supplier which subcontractors support your service, how they are assessed and how the supplier flows requirements down. Our guide to fourth-party risk explains how to handle this without assessing every link in the chain yourself.

Reporting third party risk assessment findings upward

Individual records matter to the people fixing them, but leaders need a summary. Report third party risk assessment findings by supplier tier and rating, and show trends rather than snapshots: are critical and high items falling quarter on quarter, and are the same control themes recurring across suppliers? A repeated theme, such as missing access reviews or stale penetration tests, points to a contract or onboarding requirement that should change for everyone. See our overview of the TPRM lifecycle for where these feedback loops fit.

Linking findings to contract renewal

Renewal is the moment you have most leverage. Before a contract is renewed, pull the open and overdue findings for that supplier and make the renewal decision with them in front of you. Where necessary, add remediation milestones, audit rights or termination triggers to the new contract, so a supplier that keeps missing deadlines faces a defined consequence rather than another polite reminder.

A hypothetical example of tracking findings

The following is a hypothetical example invented for illustration. A company assesses a cloud payroll provider. The assessment records four findings: no evidence of quarterly access reviews (high), a penetration test report older than 18 months (medium), an out-of-date subprocessor list (medium) and a missing version date on a policy (low).

The company gives the provider 30 days on the high item and 90 on the medium ones, asks for a completed access review log as evidence, and limits the payroll export to named administrators in the interim. The provider closes the access review finding on time, sends a new test report at day 70 and updates the subprocessor list at day 45. The low item is left for the annual review. Every step is dated in the register, so the file shows exactly what was found, decided and closed.

Common mistakes with third party risk assessment findings

Recurring weaknesses include findings written as vague opinions, no severity scale, remediation with no owner or date, closure without evidence, risk acceptance by the relationship owner alone, and findings stored in email threads instead of one register. Another is failing to feed results back into the supplier’s risk tier or the contract renewal decision. A supplier with several overdue high findings should not renew automatically.

Using a structured report for third party risk assessment findings

A consistent format makes findings comparable across suppliers and easier to defend in an audit. The Third-Party Risk Assessment Report and Workbook provides a report and register for documenting supplier assessments, ratings and actions in one place. Whatever tool you use, keep the same fields for every supplier so the numbers can be compared and reported upward.

Third party risk assessment findings FAQ

How long should a supplier have to fix a high-rated finding?

There is no universal deadline. Many organisations use 30 to 60 days for high items, and shorter for critical ones. Set the window in your policy and record any approved exception.

Can we accept a finding on a critical supplier?

Yes, but with senior sign-off, a stated reason, a compensating control where possible and an expiry date for the decision. Critical services deserve tighter scrutiny of acceptances.

What should we do when a supplier refuses to remediate?

Escalate to the accountable owner, consider contractual remedies, add compensating controls and, if the residual risk stays above your appetite, plan an exit.

Do findings from a certificate review count?

Yes. A certificate with a scope that excludes your service, or a report with qualified opinions, is a finding in its own right and should be logged and rated.

Who should own the findings register?

The third-party risk or procurement risk function usually owns it, with business owners responsible for actions on their suppliers and a senior committee reviewing the aggregate position.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.