Vendor Risk Tiers

Not every vendor earns the same scrutiny. Hover (or tap) a ring or vendor to see the controls that fit its risk.

Tier 1 — Critical Tier 2 — Important Tier 3 — Standard Fourth party
Tier the vendor portfolio. The same questionnaire for every vendor is the wrong default — it over-burdens low-risk suppliers and under-scrutinizes the ones that could take you down.

Back to Documentation