Third-Party / Vendor Risk Assessment
Your suppliers hold your data, run your processes and carry your uptime. A returned questionnaire tells you what they are willing to claim. We tell you what they can evidence.
Service overview
Third-party assessment is where most control environments quietly fail. The organisation is certified, the policies are current, the internal audit is clean, and then a payroll processor with an unpatched file transfer server loses the lot.
ZULTIV assesses your suppliers the way an auditor would assess you: against a defined criterion, on evidence, with a graded finding for every gap. You end up knowing which vendors genuinely carry the controls their contract promises, which need remediation clauses added at renewal, and which represent a risk you should be escalating now.
What is assessed
- Governance and accountability: who owns security at the vendor, and whether that person has any authority
- Certifications and attestations: scope statements read properly, not just certificate logos collected
- Data handling: what they hold, where it lives, who can reach it, and how long it survives
- Access control: joiner-mover-leaver, privileged access, and their own remote workforce
- Technical controls: patching cadence, encryption in transit and at rest, logging and monitoring
- Incident response, notification timelines in the contract versus the ones in their playbook
- Business continuity, their recovery objectives against your tolerance for their outage
- Fourth parties: who your vendor depends on, because their concentration risk is now yours
- Contractual position: audit rights, security schedules, data processing terms and exit provisions
Scope
Scope is agreed in writing before anything begins, because "assess our vendors" means very different amounts of work depending on the answer to three questions: how many, how deep, and how much evidence you are entitled to demand.
Tier review
A whole supplier population classified by criticality and data exposure, so effort lands where the risk is. Usually the right first engagement.
Standard assessment
Evidence-based review of a defined vendor against an agreed criterion, with a graded finding register and a remediation position.
Deep assessment
For critical vendors: interviews, control walkthroughs, sampling and, where your contract permits, an on-site or live systems review.
Approach
01: Classify
We inventory the vendors in scope and tier them by data sensitivity, business criticality and substitutability. Not every supplier deserves the same scrutiny.
02: Set the criterion
We agree what each tier is assessed against: your own control set, ISO/IEC 27001 Annex A, NIST CSF, or a regulator's expectations. The bar is written down first.
03: Collect evidence
Questionnaire, then verification: certificates and their scope statements, SOC 2 reports and their exceptions, policies, tickets, configuration extracts, interviews.
04: Test the claims
Where a control is asserted, we sample it. A stated 30-day patch SLA is checked against actual patch records, not accepted because the box was ticked.
05: Grade and report
Every gap is written with the requirement, the evidence and the shortfall separated, then graded by residual risk to you, not by how awkward it is to raise.
06: Remediate and re-check
You get a remediation position per vendor: accept, remediate by a date, add a contractual clause at renewal, or replace. We re-verify when you are ready.
Key deliverables
Vendor risk register
Every assessed supplier with tier, criterion, residual risk rating and owner: a live document, not a one-off PDF.
Per-vendor assessment report
Scope, method, evidence examined and each graded finding, in a form you can send to the vendor without rewriting it.
Remediation and contract actions
What each vendor must fix, by when, and which gaps are better closed through the contract at the next renewal.
Management summary
A two-page read for your board or risk committee: concentration risk, the vendors that need a decision, and what changed since last time.
Who needs this
- Organisations certified to ISO/IEC 27001 that must evidence supplier controls under Annex A 5.19 to 5.22
- Companies whose own customers now send them a supplier security questionnaire every quarter
- Regulated sectors: BFSI, healthcare, and anyone processing personal data under the DPDP Act as a data fiduciary
- Teams that outsource development, support or infrastructure and have never verified what those partners actually do
- Anyone who has just been through a vendor incident and does not want a second one
Standards and frameworks we assess against
The criterion is chosen to fit your obligations, not our convenience. Commonly:
- ISO/IEC 27001:2022Annex A 5.19 to 5.23 supplier controls
- ISO/IEC 27036Supplier relationship security
- SOC 2Trust Services Criteria & report exceptions
- NIST CSF 2.0Govern & supply chain risk management
- HIPAABusiness associate obligations
- DPDP Act, 2023Data processor engagement duties
- GDPRArticle 28 processor requirements
Frequently asked questions
Request an assessment
Discuss your requirement
Tell us roughly how many vendors are in play and what they touch. We will come back with a scope, a method and a number, not a brochure.