Vendor Assessments
by Formiti's Global DPO Team
A structured assessment framework for evaluating third-party vendors and suppliers against privacy and security requirements before and during engagement.
Who uses this module?
DPOs, Procurement Teams, Vendor Risk Managers, Security Officers.
What governance problem does it solve?
Third-party risk is one of the leading causes of data breaches and regulatory penalties. Vendor Assessments provides a repeatable, scored methodology to evaluate vendors before onboarding and monitor them throughout the relationship.
What are the key workflows?
- Initiate vendor assessment with structured questionnaire
- Score vendor responses against privacy and security criteria
- Generate risk rating with traffic-light classification
- Track remediation requirements and vendor commitments
- Schedule periodic reassessment cycles
Initiate vendor assessment with structured questionnaire
Score vendor responses against privacy and security criteria
Generate risk rating with traffic-light classification
Track remediation requirements and vendor commitments
Schedule periodic reassessment cycles
What evidence and reporting does it produce?
Built-in outputs for accountability and regulatory readiness
Scored vendor assessment records
Risk rating distribution across vendor portfolio
Remediation tracking per vendor
Reassessment schedule and compliance calendar
How does it connect to other Privacy360 modules?
- Outcomes feed into Processor Records for DPA and contract management
- High-risk vendor findings can trigger DPIA requirements
- AI Suppliers module extends this pattern for AI-specific vendor due diligence
- Evidence links to Privacy Documents for contract and policy storage
What are some example use cases?
Before onboarding a new cloud provider, procurement completes a vendor assessment; the scored results flag inadequate data residency controls, triggering contractual remediation before sign-off.
A DPO runs annual reassessments across 30 vendors and identifies three requiring updated DPAs based on changed processing activities.
A security officer reviews vendor assessment trends to prioritise security audit resources.
Related modules
Processor Records
Maintain structured processor and sub-processor records with contract status, ownership and review evidence.
Privacy Assessments
Run global privacy gap assessments, DPIAs, LIAs, transfer reviews and vendor assessments against 150+ controls — with structured rationale, evidence and AI-assisted review.
AI Suppliers
Track AI-specific supplier commitments — AI terms, no-training guarantees, transparency documentation — across the AI supply chain.
Privacy Documents
A governed repository for privacy policies, notices and procedures with version control, review cycles and external reviewer access.
Vendor Assessments guides
Practical articles from Formiti's Global DPO team on running this work well.