A vendor risk register is the working record of the risks your suppliers create, who owns them and what is being done about them. Assessments and questionnaires generate findings, but without a single register those findings scatter across emails, spreadsheets and platforms, and nobody can say which risks are open, which are accepted and which are getting worse.
This guide explains what to put in a vendor risk register, how to identify and score entries, how to assign owners and treatments, how to link the register to your wider risk process and how to keep it current. It is general guidance that you should adapt to your size and sector.
What a vendor risk register is for
A register turns scattered concerns into a managed list. It lets you see all supplier risks in one place, compare them, prioritise action and show leaders what is being done. It also gives auditors and regulators a clear record that risks were identified, assessed and treated.
It is not the same as the supplier inventory. The inventory lists who your suppliers are and what they do. The vendor risk register lists what could go wrong with them and what you are doing about it. Both are needed, and each should link to the other; see the third-party risk management framework for how the pieces fit.
Free third-party risk assessment
How much risk does this vendor bring?
Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.
Start the free vendor risk assessment → or View premium report sample
Where risks come from
Entries come from several sources: onboarding due diligence, periodic assessments, monitoring alerts, incidents, audit findings, regulatory changes and business-owner concerns. Add each significant risk to the register with a link back to its source.
Do not copy every finding. Group related findings into a single risk where they share a cause and treatment. For example, five separate access-control gaps at a supplier might become one risk: “weak access management could expose customer data”. See third-party risk assessment findings for how to classify findings.
Fields to include in a vendor risk register
Keep the fields practical. At minimum include the vendor and service, a clear risk description, category, likelihood and impact, inherent and residual ratings, existing controls, owner, treatment plan, target date, status and review date. Add a link to the evidence and to the relevant contract.
Write the risk description as a cause-and-effect sentence: “Because the supplier stores data in a single region, a regional outage could stop order processing for several days”. Vague entries such as “supplier risk” cannot be scored or treated. Our business continuity risk register page shows a similar structure.
| Field | Purpose | Example |
|---|---|---|
| Vendor and service | Identifies the relationship | Cloud CRM platform, customer data |
| Risk description | States the risk clearly | Extended outage could halt order processing |
| Category | Allows grouping and reporting | Operational resilience |
| Inherent rating | Risk before controls | High |
| Controls and evidence | What reduces the risk today | Contractual recovery time, annual test report |
| Residual rating | Risk after controls | Medium |
| Owner and treatment | Who acts and what they will do | Head of IT; add secondary provider by Q3 |
| Review date | When to reassess | 30 September |
- Vendor, service and criticality tier
- Clear risk description and category
- Inherent rating, controls and residual rating
- Named owner, treatment, target date and status
Scoring risks consistently
Use the same scales as your main risk framework so vendor risks can be combined with other risks. A five-by-five likelihood and impact matrix is common. Define each level with examples, and score inherent risk first, then residual risk after considering current controls.
Take the vendor’s criticality into account, as an issue at a critical supplier usually carries more impact than the same issue at a minor one. Our guide to vendor risk scoring explains how to build a scoring model, and vendor risk tiering explains tiers.
Assign owners and treatments
Every entry needs a risk owner: a person with authority to decide how to treat it, not a team mailbox. Usually this is the business owner of the supplier relationship, with the TPRM team advising. Record what will be done: mitigate, transfer, accept or avoid.
For mitigation, list specific actions, owners and dates. For acceptance, record who accepted the risk, why and until when. Acceptance without an end date turns into neglect. Track overdue actions and report them to management.
Link the vendor risk register to the wider risk process
Escalate significant vendor risks to your enterprise risk register, and feed relevant enterprise risks back down. Concentration in one provider, for example, is both a vendor risk and an enterprise resilience risk. Consistent categories and scales make this possible.
Link entries to other records, such as the supplier inventory, contracts, assessments, incident reports and continuity plans. A register that points to evidence is far more useful during an audit or an incident than one that stands alone.
Keep the vendor risk register current
A stale register is worse than none because it creates false comfort. Set a review date for each entry, review the whole register at least quarterly and update entries after incidents, assessments, contract changes and supplier changes. Remove closed risks after a review, but keep a history.
Use triggers: a new finding, an alert from monitoring, a supplier’s acquisition or a change in the service. Our guide to third-party continuous monitoring explains how to catch these signals, and TPRM metrics explains how to measure register health.
Report from the register
Turn the register into reports leaders can use: top risks by residual rating, risks by category, overdue actions, risks accepted and trends over time. A short summary each quarter with a heat map and commentary is usually enough.
Highlight decisions needed: risks above appetite that need additional treatment, risks that need formal acceptance and suppliers where exit may be the right option. Reporting from the register keeps it central to the programme.
Common mistakes with a vendor risk register
Frequent errors include listing findings rather than risks, vague descriptions, no owner, unscored entries, residual ratings that ignore whether controls actually work, no review dates, accepted risks with no expiry and a register nobody uses. Another is keeping several unlinked registers in different teams.
Avoid these by agreeing a standard format, checking entries for quality, assigning owners and reviewing the register in a regular governance meeting.
Getting started with limited time
If you have no register today, start small. List your critical suppliers, then add the top two or three risks for each from recent assessments and incidents. Score them, assign owners and set review dates. That first version, even with thirty entries, gives you more control than a hundred scattered findings. Expand to high-tier suppliers next, and add lower tiers only as capacity allows.
Agree a simple naming standard and a short guidance page so everyone writes entries the same way. Quality checks by the TPRM lead every month will keep the standard from slipping while the register is young.
Tools and formats
A spreadsheet is a fine starting point for a small programme, provided it is protected, version-controlled and owned. As the number of suppliers grows, a governance, risk and compliance platform or a dedicated supplier risk tool adds workflow, reminders and reporting. Choose based on how many suppliers and assessors you have, not on features you will not use. Whatever the format, make sure you can export the full register, with history, in a usable form.
Wherever the register lives, restrict edit rights, log changes and back it up. It contains candid statements about weaknesses in your suppliers and your own controls, so treat it as sensitive information and share it on a need-to-know basis.
A short worked example
A company has a payment processor rated critical. The register holds three entries: outage risk, with a residual rating of medium because of a contractual recovery time and annual test; data breach risk, rated medium because of encryption and certification; and concentration risk, rated high because the processor handles all card payments.
The concentration risk has an owner, the finance director, and a treatment to add a secondary processor within nine months. The entry is reviewed quarterly and appears in the board report. When the processor has an outage the following spring, the register shows the risk was known, owned and being addressed.
Structuring the register and assessments
If you want a report and workbook that carry vendor details, assessment results, ratings and treatment actions together, the Third-Party Risk Assessment Report and Workbook provides a structured layout that supports building and maintaining a register. Whatever the tool, a good vendor risk register is clear, owned, scored consistently and reviewed, and it is guided by principles such as those in ISO 31000 on risk management.
Vendor risk register FAQ
What is a vendor risk register?
A record of the risks that suppliers create, with ratings, owners, controls, treatments and review dates, used to prioritise and track action.
How is it different from a vendor inventory?
The inventory lists suppliers and what they do. The register lists the risks associated with them and how they are being managed.
Who should own each entry?
A named person with authority to decide the treatment, usually the business owner of the relationship, supported by the TPRM team.
How often should the register be reviewed?
Each entry should have a review date, and the whole register should be reviewed at least quarterly, plus after incidents or supplier changes.
Should accepted risks stay on the register?
Yes, with the approver, the reason and an expiry date, so acceptance is reviewed rather than forgotten.