GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

VND-001 Vendor Risk Assessment and Due Diligence

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A documented risk assessment is conducted for all third-party vendors, suppliers and service providers before engagement and periodically thereafter. The assessment evaluates security posture, privacy practices, regulatory compliance, financial stability and operational resilience. A register of all suppliers and supply chain relationships records each one's assessment status, a contact point for each direct supplier and service provider and the ICT products, services and processes each one provides. For suppliers of ICT products and components the assessment covers provenance and the supplier's controls against tampering, counterfeit components and malicious code insertion. A named cross-functional group owns the supply chain risk activity, with its members, their responsibilities and the activities it leads recorded. Findings are documented and inform the decision to engage or continue the relationship.

Rationale

Vendors with access to systems or data extend the organisation's attack surface, and formal due diligence creates a defensible record of proportionate risk management. Naming a group rather than a single owner reflects where the decisions actually sit: the security view, the contractual position, the commercial relationship and the operational dependency are held by different people, and an assessment owned by one of them alone tends to stop at that one dimension.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredrole duty

RTS 2024/1773 Art. 6(1) is the diligence a financial entity runs on the provider. Two of its criteria have no counterpart in the library: exposure to restrictive measures including embargos and sanctions under point (d) and ethical conduct, human rights, the prohibition of child labour, environmental protection and working conditions under point (f).

NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex point 5.1.1 requires a supply chain security policy as a named artefact in which the entity identifies its own role in the supply chain and communicates it to its direct suppliers. Point 5.1.2 adds the supplier secure development procedures and the ability to diversify sources and limit vendor lock-in as selection criteria. Point 5.2 adds two fields to the register, a contact point per supplier and the list of ICT products, services and processes each provides. Point 5.1.3 and Art. 21(3) require the results of an Art. 22 coordinated assessment to be taken into account once one is published.

Framework Mappings (42)

STA-01Supply Chain Risk Management Policies and Procedurespartial
STA-08Supply Chain Inventoryfull
STA-09Service Bill of Material (BOM)partial
STA-10Supply Chain Risk Managementfull
STA-16Supply Chain Data Security Assessmentfull
STA-01Supply Chain Risk Management Policies and Procedurespartial
STA-08Supply Chain Inventoryfull
STA-09Service Bill of Material (BOM)partial
STA-10Supply Chain Risk Managementfull
STA-16Supply Chain Data Security Assessmentfull
DORA-Art.28.3Register of information on contractual arrangementsinformative
DORA-Art.28.4Assessments before entering a contractual arrangementinformative
DORA-Art.29Preliminary assessment of ICT concentration risk at entity levelinformative
DORA-RTS-2024/1773-Art.6.1Due diligence assessment of the prospective providerinformative
DORA-RTS-2024/1773-Art.6.2Required level of assurance on the provider's risk managementinformative
GDPR-Art.28.1Processor Selection Due Diligencefull
HIPAA-164.308.b.2Subcontractor Assurancesfull
HIPAA-164.314.a.2.i.BBusiness Associate Contract Subcontractor Terminformative
5.19Information security in supplier relationshipsfull
5.21Managing information security in the ICT supply chainpartial
NIS2-Art.21.2.dSupply Chain Securitypartial
NIS2-Art.21.3Supplier-Specific Risk Factors in Supply Chain Measurespartial
NIS2-Art.22Union Level Coordinated Security Risk Assessments of Critical Supply Chainsinformative
NIS2-CIR-5.1Supply Chain Security Policypartial
NIS2-CIR-5.2Directory of Suppliers and Service Providersfull
NIS2-CIR-6.1Security in Acquisition of ICT Services or ICT Productsinformative
PM-30Supply Chain Risk Management Strategypartial
RA-3(1)Risk Assessment | Supply Chain Risk Assessmentfull
SA-1Policy and Procedurespartial
SA-9(1)External System Services | Risk Assessments and Organizational Approvalspartial
SR-1Policy and Procedurespartial
SR-2Supply Chain Risk Management Planpartial
SR-2(1)Supply Chain Risk Management Plan | Establish SCRM Teamfull
SR-3Supply Chain Controls and Processespartial
SR-5Acquisition Strategies, Tools, and Methodspartial
SR-6Supplier Assessments and Reviewsfull
SR-9Tamper Resistance and Detectionpartial
GV-6.1-005Third-Party AI Risk Policies | GV-6.1-005partial
GV-6.1-007Third-Party AI Risk Policies | GV-6.1-007partial
MG-3.1-002Third-Party AI Risk Monitoring and Controls | MG-3.1-002partial
GOVERN 6.1Third-Party AI Risk Policiespartial
CC9.2Vendor and Business Partner Risk Managementfull

Evidence (4)

reportdocumentmanual

Completed vendor risk assessment reports for all in-scope third-party vendors, documenting security posture, privacy practices, and engagement decision.

Example: Vendor Risk Assessment reports (SecurityScorecard / internal questionnaire) for top-tier vendors, each covering: security posture score, privacy compliance assessment (GDPR DPA status), regulatory certifications (SOC 2 / ISO 27001), data handling practices, incident history, and risk-based engagement decision with DPO and CISO sign-off

Test: Request completed risk assessment reports for a sample of 5 critical vendors. Verify: (1) a risk assessment was completed before the vendor was engaged, (2) each assessment covers security, privacy, regulatory, and operational dimensions, (3) findings are documented with a risk rating, (4) decision to engage (or not) is signed off by an appropriate authority, (5) critical vendors have been reassessed within the last 12 months.

attestationdocumentmanual

Current third-party security certifications (SOC 2 Type II, ISO 27001) obtained from key vendors as evidence of their security posture during due diligence.

Example: SOC 2 Type II reports or ISO 27001 certificates for critical vendors (e.g. cloud provider, CRM, payment processor), filed in the vendor management system with issuance dates confirming they were current at the time of the due diligence review

Test: Request vendor certification files for the 5 most critical vendors. Verify: (1) each critical vendor has provided a current SOC 2 Type II or ISO 27001 certificate (issued within 12 months), (2) the SOC 2 bridge letter is available where the report is more than 9 months old, (3) certificates are filed in the vendor management system with the associated vendor record.

recorddocumentmanual

Terms of reference and meeting records for the group that owns supply chain risk, naming its members, their functions and the activities it leads.

Example: Supply chain risk group terms of reference v2, minutes for 2026 H1

Test: Request the terms of reference and the meeting records. Verify: (1) the terms name the members by role and cover at least the security, legal, procurement and business-owner functions, (2) the activities the group leads are listed with an owner against each, (3) the group met at the interval its terms set and the minutes record decisions rather than attendance alone, (4) assessments completed during the period resolve to a decision the group recorded, (5) a vendor engaged during the period without the group's involvement is identified as an exception rather than passing unnoticed.

system_exporttechnicalautomated

Export of the supplier register showing, for each direct supplier and service provider, its assessment status, a contact point and the ICT products, services and processes it provides.

Example: Supplier register export from the vendor management system, 2026-09-01, 212 entries

Test: Export the supplier register. Verify: (1) every supplier and service provider engaged during the period appears in the export, reconciled against accounts payable or the contract repository, (2) each entry carries an assessment status, a named contact point and the ICT products, services and processes it provides, (3) a sample of five entries reconciles to the executed contract or order for the products and services listed, (4) an entry with an empty contact point or product list is recorded as an exception with an owner rather than left blank, (5) the export date is within the register's documented refresh interval.

Questions (3)

boolean

Is a documented risk assessment conducted for each third-party vendor before engagement?

The assessment should be completed before the vendor is engaged and produce a documented risk rating and engagement decision signed off by an appropriate authority (e.g. CISO, DPO). Critical vendors should be reassessed at least annually.

multi

What does the vendor risk assessment and supplier register cover?

Information security posture (e.g. certifications, security questionnaire or scorecard)Privacy practices and GDPR compliance (DPA status, data handling practices)Regulatory compliance and applicable certifications (SOC 2, ISO 27001)Incident history and breach notification track recordFinancial stability and operational resilienceSub-processor or supply chain riskA register entry per supplier carrying a contact point and the ICT products, services and processes it providesAssessment is limited to contract review onlyNone of the above

A comprehensive pre-engagement assessment should cover at minimum: security posture, privacy compliance, certifications and incident history. Financial and operational resilience assessment is important for critical suppliers.

boolean

Is there a named cross-functional group that owns supply chain risk activity, with its members and their responsibilities recorded?

Answer yes only where the membership and the activities the group leads are written down rather than understood informally. A standing meeting with no terms of reference, or a group that exists on a slide and has not met, does not count.