If you are searching for a third-party risk assessment questionnaire, you probably need more than a list of questions. You need a file that helps your team decide what to ask, what evidence to request, how to record gaps, and what to do with the result.
This guide explains how to use Third-Party Risk Assessment Questionnaire Template work in a manual TPRM process. It also includes a downloadable LearnTPRM Excel workbook built for a broad third-party assessment covering security, privacy, resilience, financial, legal, and fourth-party risk.
What this assessment is for
Third-Party Risk Assessment Questionnaire Template work should help the buyer understand the vendor’s service, exposure, control environment, evidence quality, and remaining risk. The right scope depends on the vendor’s data, access, criticality, geography, subcontractors, regulatory duties, and dependency on the service.
Use the workbook for vendor risk, operational risk, compliance, and audit teams. Start with the vendor profile and risk triage pages before sending detailed questions. A proportional review is easier for the vendor to complete and easier for the buyer to defend.
What the questionnaire should cover
- Scope and ownership: service description, business owner, data flows, access paths, criticality, and responsibilities.
- Security governance: policies, roles, risk tracking, exceptions, training, and oversight.
- Data and privacy: processing, locations, retention, deletion, privacy requests, and subprocessors.
- Access and technology: authentication, privileged access, vulnerability management, logging, secure development, and change control.
- Response and resilience: incidents, notification, business continuity, recovery objectives, backups, and testing.
- Assurance and contracts: independent reports, scope, findings, audit rights, cooperation, and exit obligations.
How to use it in a manual TPRM assessment
1. Define the service boundary
Write down what the vendor will do, which systems it will touch, what information it will process, and what would happen if the service failed. This keeps the review focused on the relationship you are actually approving.
2. Assign inherent risk before reviewing controls
Risk triage should look at impact before control strength. Sensitive data, production access, critical operations, internet exposure, concentration risk, and complex subcontractor chains usually justify a deeper review.
3. Ask for evidence that answers the question
Good evidence is relevant, current, and scoped to the service. A certificate may demonstrate a management system, but it may not answer how the vendor handles your data, supports your recovery objective, or notifies you about a material change.
4. Record gaps as decisions
Do not leave findings as comments at the bottom of a spreadsheet. Link each material gap to remediation, a compensating control, a service restriction, formal risk acceptance, or a decision not to proceed.
5. Carry the result into monitoring
Record reassessment dates and change triggers. Incidents, new subprocessors, ownership changes, new integrations, poor performance, and expired assurance should be reasons to revisit the assessment.
Evidence checklist
- Service and data flow description
- Current security and privacy policies
- Independent assurance report or certification
- Penetration test or security testing summary
- Vulnerability management and remediation evidence
- Incident response and notification procedure
- Business continuity and recovery test summary
- Subprocessor or supplier list
- Contract security addendum
- Data return, deletion, and access removal evidence
What is inside the LearnTPRM workbook?
The workbook contains a vendor profile, risk triage page, questionnaire, evidence register, findings and remediation tracker, executive summary, and framework crosswalk. The scoring is formula-driven and the response fields use dropdowns for consistent status values.
This is an original LearnTPRM workbook designed for manual assessment work. Adapt the scope and question depth to your risk policy.
Download the Excel workbook
LearnTPRM Third Party Risk Assessment
Check the reuse and source note inside the workbook before sharing it externally. For standards-owned questionnaires, use the official source when the buyer specifically requires the official form.
Common mistakes to avoid
- Using a critical-vendor questionnaire for every supplier
- Accepting unsupported yes answers as evidence
- Failing to document unanswered or not-applicable questions
- Ignoring subcontractors and service dependencies
- Scoring without considering business impact
- Approving a vendor without clear remediation ownership
Practical checklist
- Record service, owner, data, access, and criticality.
- Choose review depth using inherent risk.
- Send only relevant questions.
- Review evidence for scope, date, and exceptions.
- Score gaps and escalate high-impact issues.
- Record approval conditions and remediation.
- Set monitoring triggers and renewal dates.
FAQ
Is this an official Third-Party Risk Assessment Questionnaire Template?
No. It is an original LearnTPRM workbook designed to support manual TPRM work. Where a standard or regulator owns the official form, obtain and use that form when required.
Who should complete the questionnaire?
The vendor’s security, privacy, technology, continuity, or compliance contacts should provide answers, while the buyer’s TPRM team coordinates review and evidence validation.
Should every vendor complete the full questionnaire?
No. Use risk-based tiering. Lower-risk vendors may need a short review, while critical vendors may need deeper evidence, contract negotiation, independent assurance, and ongoing monitoring.
Can the workbook replace a SOC 2 or ISO 27001 report?
No. The workbook helps organize assessment questions and evidence. Independent reports and certifications may provide valuable assurance, but the buyer still needs to evaluate scope and service-specific risk.
Sources
-
Third Party Risk Management Guide
- NIST Cybersecurity Supply Chain Risk Management
- LearnTPRM vendor security questionnaire guide