When an auditor, acquirer, or private equity sponsor reviews a mid-market manufacturer, the vendor risk register is often one of the first documents requested. The reviewer wants to know which suppliers can stop production, which service providers hold sensitive data, whether those relationships have been assessed, and who owns each risk.
Most companies with 100 to 1,000 employees cannot answer from one place. Procurement has contracts, finance has payment records, IT has application lists, and plant managers know which suppliers are irreplaceable.
You can build a defensible first version in one day: one inventory, one classification method, named owners, documented evidence gaps, and a review schedule.
What a Vendor Risk Register Actually Is (and Is Not)
A vendor risk register is a centralized inventory of third parties, the services or materials they provide, the risks they create, the controls that reduce those risks, and the actions your company has agreed to take. It combines vendor inventory, supplier risk assessment, ownership, evidence, and follow-up in one record.
It is not the accounts-payable vendor master. That list may contain every company you have paid, but it rarely explains data access, operational dependency, security evidence, substitutability, or assessment status. It is also not a folder of completed questionnaires. A vendor questionnaire is an input; the register is the decision record.
A defensible register shows both inherent risk, the exposure before controls, and residual risk, what remains after verified controls and mitigations. A payroll processor may have high inherent risk because it stores employee data, yet lower residual risk when independent assurance, contract terms, and tested incident procedures are in place.
This structure aligns with established guidance. The U.S. banking agencies recommend maintaining a complete third-party inventory, periodically reassessing relationships, and applying more rigorous oversight to higher-risk or critical activities.[1] NIST CSF 2.0 similarly calls for suppliers to be known and prioritized by criticality and for their risks to be recorded, assessed, responded to, and monitored across the relationship.[2]
The Four Vendor Risk Tiers and the Information to Collect
Do not apply the same review to every supplier. Tiering concentrates effort where failure would hurt most. Use four levels and classify each vendor according to its most serious exposure:
- Critical: Failure could stop production, create a major safety or compliance event, expose highly sensitive data, or materially affect revenue. Examples include an ERP provider, a sole-source component manufacturer, a managed IT provider, or a plant-control systems integrator.
- High: The vendor handles sensitive data or supports an important process, but a tested workaround or replacement exists. Examples include payroll, logistics, quality-management software, or a secondary raw-material supplier.
- Medium: The vendor has limited system, facility, or internal-data access, and disruption would be manageable. Examples include a marketing agency, travel platform, maintenance contractor, or office-equipment provider.
- Low: The relationship creates little operational, data, regulatory, or financial exposure. Examples include catering, event venues, or commodity purchases available from many alternatives.
Classification should reflect your use of the vendor, not its size. A small calibration laboratory may be critical if certification lapses prevent product release; a large software company may be medium risk if its tool is non-sensitive and replaceable.
For each vendor, collect enough information to explain the relationship and reproduce the decision later:
- Identity and ownership: Legal name, service description, business unit, location, and a named internal relationship owner.
- Operational dependency: Processes, plants, products, or customer commitments that rely on the vendor; recovery-time expectation; approved alternative; and estimated replacement time.
- Access and data: Systems, facilities, networks, and data types the vendor can access, store, transmit, or process.
- Commercial dates: Contract start, renewal, termination notice deadline, annual spend, and insurance expiration where relevant.
- Assessment evidence: Last review date, questionnaire status, SOC report or certification dates, identified gaps, remediation owner, and target date.
- Dependency chain: Material subcontractors, fourth parties, geographic dependencies, and any shared cloud, logistics, or component provider that creates concentration risk.
This is the core of a useful vendor risk register template. If a field will not change a decision, support an audit, or trigger action, leave it out of version one.
How to Score Vendor Risk and Use Questionnaires Without a Consultant
Start with a transparent 15-point inherent-risk score. Rate five factors from 0 to 3: operational criticality, sensitivity of data or system access, regulatory or safety impact, financial impact of failure, and difficulty of replacement. Add the scores.
- 13–15 points: Critical
- 9–12 points: High
- 5–8 points: Medium
- 0–4 points: Low
Write one sentence supporting every factor scored 2 or 3. “Only approved source for a customer-specified casting; estimated qualification time is six months” is defensible. “Important supplier” is not. Use the same rubric for every vendor so the result can be challenged and repeated.
Next, evaluate controls and evidence to determine residual risk. Do not subtract points merely because a vendor answers “yes.” Give credit for current, relevant evidence: a SOC 2 Type 2 report whose scope includes your service, an ISO 27001 certificate with a matching scope, a tested recovery plan, cyber insurance, incident-notification terms, or proof that critical sub-suppliers are managed. Record exceptions, expired documents, and evidence you could not obtain.
Your vendor questionnaire should be proportional to the tier. Critical and high-risk vendors need questions across governance, access control, encryption, vulnerability management, incident response, business continuity, privacy, subcontractor oversight, physical security, and financial resilience. Manufacturing suppliers may also require questions about quality systems, traceability, capacity, geographic exposure, safety, and alternate production sites. CISA’s supplier assessment template demonstrates this evidence-based approach, including supplier governance, material-change notification, incident response, business continuity, and downstream supplier controls.[3]
Medium-risk vendors can receive a shorter set focused on access, data handling, continuity, and notification. Low-risk vendors usually need business verification and contract review, not a 100-question security assessment.
When responses arrive, classify each issue as acceptable, needs clarification, remediation required, or risk accepted. Assign owners and due dates. If evidence is unavailable, document the limitation and add contract protection, restrict access, increase monitoring, create a contingency plan, obtain executive acceptance, or select another vendor. This decision trail makes vendor risk management defensible.
Build It by 5:00 p.m.—Then Keep It Current
8:00–9:00 a.m.: assemble the inventory. Export active vendors from accounts payable, contracts, IT applications, procurement, plant maintenance, and quality systems. Remove obvious duplicates, but do not wait for perfect data. Add any supplier a plant or department says is operationally essential, even if another entity pays it.
9:00–11:00 a.m.: run a rapid classification workshop. Bring together procurement, IT, finance, operations, quality, and legal or compliance. Review vendors by category and answer five questions: Can failure stop production? Does the vendor access sensitive data or connected systems? Is it tied to a regulatory, safety, or customer requirement? What is the credible financial impact? How quickly can it be replaced? Apply the 15-point rubric and capture the rationale.
11:00 a.m.–1:00 p.m.: complete the critical and high-risk records. Add owners, contracts, renewal dates, data access, dependencies, current evidence, and open issues. Flag sole-source arrangements and shared dependencies. Vendor concentration risk exists when multiple critical processes depend on one supplier, geography, logistics route, cloud platform, or fourth party; it may not be visible when vendors are reviewed individually.
1:00–3:00 p.m.: launch questionnaires and evidence requests. Send critical and high-risk vendors the appropriate assessment. Give vendors the option to provide current assurance documents instead of repeating questions already addressed by independent evidence. Set a response date and identify the internal owner copied on follow-ups.
3:00–4:00 p.m.: create the action log. Record missing contracts, expired certificates, unanswered questions, unapproved access, and continuity gaps. Give each item an owner, treatment decision, and due date. Do not hide unknowns; an identified gap with a plan is more credible than an unjustified “low risk” rating.
4:00–5:00 p.m.: approve the cadence. Review critical and high-risk vendors at least annually and at material events such as a breach, ownership change, major service change, contract renewal, quality failure, or new data access. Review medium-risk vendors every two years or at renewal. Reconfirm low-risk classification during onboarding and renewal.
To keep the register current, connect reviews to events the business already manages: vendor onboarding, purchase approval, contract renewal, system access, insurance renewal, incident response, and offboarding. Send reminders 60 to 90 days before an assessment or contract expires. Require procurement or IT to update the register before introducing a new vendor or materially changing access.
A spreadsheet can establish the baseline, but it becomes fragile as questionnaires, evidence, reminders, and remediation multiply. A GRC vendor risk workflow should maintain the inventory, tier vendors, collect questionnaires through a secure portal, score responses consistently, track renewal dates, and preserve the evidence trail. Korinza is designed for this mid-market operating model: structured assessments, critical/high/medium/low tiering, AI-assisted review, and a live risk register without a full-time vendor risk team.
Frequently Asked Questions
What is a vendor risk register?
A vendor risk register is a centralized record of third-party suppliers, the services they provide, their operational and data dependencies, their inherent and residual risk, supporting evidence, internal owners, and open remediation. It is also called a third-party risk register or supplier risk register.
How do you score vendor risk?
Score inherent risk using consistent factors such as operational criticality, data access, regulatory or safety impact, financial impact, and substitutability. Then review verified controls and evidence to determine residual risk. Document the reason for the score, not just the color or tier.
What questions should a vendor risk questionnaire include?
Questions should cover governance, access control, encryption, vulnerability management, privacy, incident notification, business continuity, subcontractors, physical security, and financial resilience. For manufacturing suppliers, add quality, capacity, traceability, geographic exposure, alternate production, and safety questions. Tailor the depth to the vendor’s risk tier.
How often should you review vendor risk?
Review critical and high-risk vendors at least annually and whenever a material event occurs. Medium-risk vendors can usually be reviewed every two years or at renewal. Low-risk vendors should be reconfirmed during onboarding and renewal. Your industry, contracts, customers, or regulators may require a different cadence.
What is vendor concentration risk?
Vendor concentration risk is the exposure created when too many critical operations depend on one supplier, location, technology platform, transport route, or fourth party. Measure it across the full register, not only within individual vendor assessments, and mitigate it with alternatives, inventory buffers, contractual protections, or tested contingency plans.
Sources: [1] Interagency Guidance on Third-Party Relationships; [2] NIST Cybersecurity Framework 2.0; [3] CISA Vendor Supply Chain Risk Management Template.