Direct answer
A useful vendor risk assessment starts with the exact service and data dependency, then connects privacy, security, contract and operational evidence to a named decision owner. It should not turn a generic questionnaire or certification into an approval of every service, entity or use case.
Preparation sequence
- Define the business use, service modules, minimum data and internal owner.
- Map storage, support, administrator, affiliate, subprocessor and onward-transfer access.
- Compare the DPA, security terms, product settings and current assurance evidence.
- Test incident, change, renewal, export, deletion, account-closure and exit workflows.
- Record required controls, accepted gaps, approvers and the next review trigger.
Decisions to record
What new dependency does the vendor create?
Describe the exact service, business owner, people and data involved, availability dependency, privileged access, manual workarounds and systems that cannot operate if the vendor changes or fails.
Does the evidence cover this entity and service?
Match every report, certification, contract and security statement to the contracting entity, service module, locations, period, exclusions and production configuration actually under review.
Can contract promises be performed?
Test subprocessor notice, incident escalation, rights assistance, audit support, export, retention, deletion and account closure against named owners and live product behavior.
What must happen before launch?
Record required controls, evidence gaps, accepted residual issues, approvers, deadlines, launch conditions and the event that triggers reassessment.
Evidence to organize
- Vendor proposal, architecture and data-flow map
- DPA, security terms, subprocessors and location record
- Current assurance reports, certifications and control evidence
- Incident, change-notice, export, deletion and exit procedures
- Decision record with conditions, owners, evidence dates and review date
Example decision record
Use case: a support platform will receive customer names, messages and attachments. Open issue: the sales material says EU hosting, but the subprocessor list shows global support access. Action: verify the legal entities and access path, restrict the initial data scope, reconcile the DPA and settings, and assign an owner before approval.
Use the result responsibly
This guide does not select a legal mechanism, determine compliance, validate a contract, calculate a legal deadline, or predict an outcome. Laws, procedures, facts, and provider terms change. Check the official sources and obtain qualified advice where the business decision requires it.
Official reference points
Reviewed 2026-09-02. These sources are starting points, not a complete statement of applicable law.