This free third-party risk assessment template assesses one vendor and one service the way supervisors and auditors expect: tier it by how critical it is, check the evidence, rate the risks it brings, choose the controls that manage them and record a decision. Instead of a blank spreadsheet, it asks the questions in turn, checks your answers as you go and tells you what an auditor or regulator would still ask for.
Start by tiering the vendor, then build its profile, run due diligence, rate the risks from a library of 30 third-party scenarios, choose controls referenced to ISO/IEC 27001:2022 controls A.5.19 to A.5.23, the NIST CSF 2.0 supply chain category GV.SC and DORA Articles 28 to 30, and record the review and decision. It is free, and your answers save as you go.
Premium report
See what the premium third-party risk assessment report looks like
A worked vendor risk assessment for a fictional organization: the tier, the vendor profile and due diligence, every risk with its controls and ISO 27001, NIST and DORA references, heat maps before and after, the review and decision, every finding with what closes it, an AI-assisted analysis with a 30/60/90-day roadmap, plus the live Excel workbook.
Other free risk assessments: Information Security Risk Assessment (ISO 27001) Privacy Risk Assessment (ISO 27701) Business Continuity Risk Assessment (ISO 22301) Enterprise Risk Assessment (ISO 31000) AI Risk Assessment (ISO 42001) Data Protection Impact Assessment (GDPR) Transfer Impact Assessment (GDPR) AI System Impact Assessment (ISO 42005) Legitimate Interests Assessment (GDPR)
What this third-party risk assessment template covers
- Tiering. Red flags such as sanctions or bribery, then the risk factors that set the tier: a critical or important function, data, system access, substitutability, subcontractors, data location and contract size. The tier (Critical, High, Moderate or Low) sets how deep the due diligence goes.
- Scope and criteria. The vendor and service you are assessing, and likelihood and impact scales for disruption, data exposure, financial loss and regulatory breach.
- What the relationship involves. The business function supported, the data shared, the systems connected, the vendor and its subcontractors, the locations and the people affected.
- Profile and due diligence. The vendor profile, then thirteen checks: independent assurance, evidence behind the questionnaire, vendor access, encryption, incident notification, continuity, financial health, subcontractors, data location, the data processing agreement, audit rights, the exit plan and regulator approval.
- Risks. Scenarios from breaches and outages to fourth-party failure, concentration, lock-in, contract gaps, sanctions and insolvency, each rated for your organization and its customers.
- Controls. The controls that manage each risk, from contract clauses and audit rights to exit plans, each referenced to ISO 27001, NIST CSF 2.0 or DORA, with an owner, a date and the level expected afterwards.
- Decision. The review, the vendor’s response to the findings, the decision (approve, approve on conditions, approve with the risk accepted, or do not engage) and the next reassessment date.
What you get from the third-party risk assessment template, free
The vendor’s tier, a heat map of its risks, the check that tells you whether High or Critical risk remains once your controls are in place, a process score out of 100, and the findings an auditor would raise, such as a critical vendor with no exit plan or limited audit rights. Sign in and it stays in your account, ready for the reassessment.
The full third-party risk assessment report turns the third-party risk assessment template into a finished record, with the controls by owner and due date and their references, the decision, an AI-assisted analysis with a 30/60/90-day roadmap, and the whole assessment as a live Excel workbook.
Where this fits
A third-party risk assessment template like this one covers a single vendor. Our guide to the third-party risk assessment explains tiering, due diligence depth and scoring across a portfolio, and the TPRM lifecycle shows where the assessment sits from planning to exit. For the evidence itself, see the vendor due diligence checklist and the vendor security questionnaire. Financial entities in the EU should also read our guides to the DORA register of information and DORA exit strategy. For the policies, registers and contract clauses around it, see the TPRM Toolkit.
Frequently asked questions
When should I use the third-party risk assessment template?
Before you sign with a new vendor, at renewal, at the reassessment date your tier sets, and after an incident, a change of service, new subcontractors or a change of ownership. One assessment covers one vendor and service.
How often should vendors be reassessed?
A common rule is every year for critical vendors, every two years for high-tier vendors and at renewal for the rest. Your own policy decides; the tool records the date you set.
Does it meet DORA?
It follows the pre-contract assessment in DORA Article 28 and checks the key contract terms in Article 30, including audit rights, incident support and exit. DORA also requires a register of information and an exit strategy for critical or important functions, which sit outside a single vendor assessment.
Is this a substitute for legal or audit advice?
No. It is a structured self-assessment built from the information you enter, and Governance Docs does not review or verify it. Whether an arrangement is material outsourcing under your regulator’s rules is a question for your compliance function.
What happens to the information I enter?
It is stored with your assessment so you can come back to it, and it is never shared. Describe the vendor and the service in general terms and avoid entering personal data or confidential contract details. You can delete an assessment permanently from your account at any time.
