Description
What the report contains
You already have the vendor’s tier, your heat map, your top risks and your findings for free. This is the full third-party risk assessment behind them, written up as the record an auditor, a supervisor or your risk committee expects to see before a vendor is approved.
- The tiering, recorded. Red flags and risk factors, each answered, with the tier and your note: the record that shows due diligence was set by criticality.
- The vendor profile. The service, the business function it supports, the data and access involved, locations and subcontractors, the assurance reviewed, the contract and the exit route.
- Due diligence. Thirteen checks from independent assurance and vendor access to incident notification, continuity, subcontractors, audit rights, the exit plan and regulator approval, each answered yes, partly or no, with your explanation.
- Every risk, highest level first. With its owner, impact type, the controls already in place, its likelihood, impact and level, and the rationale for the rating.
- The controls by due date. For each risk: the decision, the planned actions, the third-party controls it relies on with their ISO/IEC 27001, NIST CSF 2.0 or DORA references, the owner, the due date and the level before and after.
- The residual risk check. Whether High or Critical risk remains once the controls are in place, and so whether the vendor can be approved as planned.
- Review and decision. Who reviewed it and whether their advice was followed, the vendor’s response, the decision, who approved it and when, and the reassessment date.
- Every finding, with what closes it. Each gap between your assessment and what ISO/IEC 27001, NIST CSF 2.0 and DORA expect, and the document that closes it.
- An AI-assisted analysis and 30/60/90-day roadmap. A one-sentence verdict, where you stand and what it means, a statement for senior management, three to five priorities and a roadmap, written from your own answers and checked automatically against them.
The live Excel workbook
Vendors change their services, subcontractors and owners, so you also get the assessment as a working file, not a static export:
- Dashboard: the process score, level and heat maps, recalculated as you edit.
- Criteria: your scales, band ceilings and appetite line, which drive every calculation.
- Scope and Risk register: change a likelihood or impact and the level, band and appetite check update.
- Treatment plan: decisions, controls, owners, due dates, targets and acceptance.
- Vendor assessment record: the tiering, the profile, the due diligence answers and the decision as a working record you can keep editing at each reassessment.
How to get it
- Run the free third-party risk assessment template: tier the vendor, build its profile, run due diligence, rate the risks, choose the controls and record the decision.
- Choose Get the full report. The report and workbook are in your account straight away, and they rebuild from your latest answers whenever you download them.
Built for organizations that rely on vendors, cloud providers and outsourced services, including financial entities working to DORA or to CBB, SAMA or EBA outsourcing rules. One assessment covers one vendor and service.
One payment covers this assessment. Edit it as often as you like and download the updated report at no extra cost. This is a self-assessment built from the information you enter; it is not a certification, an audit opinion or legal advice.
DORA Toolkit - 100+ Comprehensive Templates 







Reviews
There are no reviews yet