Vendors

Vendor Risk Assessment: Process, Checklist and Framework

Vendor risk assessment rates a supplier's compliance, financial, operational, data and reputational risk into a score and tier that set approval and controls.

Blue blocks spelling risk next to a magnifying glass

Vendor risk assessment is the process of evaluating a supplier’s compliance, financial, operational, data security and reputational risk before you sign it up and at regular intervals afterwards. Done once at onboarding and filed away, it misses the vendor who stops filing GST returns in month four, and the input tax credit you claimed goes with it.

In OneFinOps, the Vendor Compliance Agent re-screens each vendor on the cycle its risk tier sets, so a lapse shows before the next payment.

Key takeaways

  • Tier first, then assess the vendor at the depth its tier needs.
  • Score six domains from 1 to 5, weight them, then read each alone.
  • Verify key answers on official portals, not only the questionnaire.

What is the vendor risk assessment process?

  1. Tier by inherent risk. Access to personal data or systems, or sole supply of a critical input, makes a vendor High.
  2. Send a questionnaire scaled to the tier, with evidence for high and critical.
  3. Verify independently. PAN, GSTIN and return filing, Udyam, and MCA company status.
  4. Score, weight and tier using the framework below.
  5. Decide and set controls. Approve, approve with conditions (advance limits, audit rights, data clauses), or reject.
  6. Reassess on schedule, and at once after a GSTIN cancellation or data incident.

What is a vendor risk assessment framework?

Weighted score = sum of (domain score × weight), between 1.0 and 5.0.

DomainWeightScore 1 (low risk) looks likeScore 5 (very high risk) looks like
Compliance and tax25%PAN operative, GSTIN active, returns on time for 12 monthsGSTIN cancelled, returns missing, PAN inoperative
Financial20%Profitable for 3 years, no defaultLosses, negative net worth, demands large advances
Operational and delivery20%Two or more sites, on-time delivery above 95%Single site, no backup, repeated delays
Information security and data15%No data access, or ISO 27001 or SOC 2 reportSensitive data with no controls
Legal and contractual10%Signed contract with SLA and audit rightsNo contract, fraud or insolvency proceedings
Reputational, ESG and concentration10%No adverse news, below 40% of category spendRegulatory action, above 70% of category spend

Tiers: 1.0 to 1.9 low, 2.0 to 2.9 medium, 3.0 to 3.9 high, 4.0 to 5.0 (or any domain at 5) critical. Reassess critical every 6 months, high yearly, medium every 2 years.

Vendor risk assessment example

A packaging supplier with ₹1,20,00,000 (₹1.2 crore) of annual purchases scores a weighted 2.95, which says medium. Its compliance score of 4 says otherwise: GSTR-3B is not filed for three of the last six months. At 18% GST, about ₹21,60,000 of input tax credit a year depends on it, and section 16(2) of the CGST Act allows credit only when the supplier actually pays the tax. Decision: approve with conditions, and hold the GST portion of payments until returns are current.

How OneFinOps handles vendor risk

The Vendor Compliance Agent keeps the assessment live. It re-screens each vendor on the cycle its risk tier and category set, tracks every certificate to its expiry date, and holds the payment when a required document has lapsed. Every held payment goes to the compliance owner with the missing document named, and any override goes to the approver allowed to grant it, with the reason recorded.

The usual setup keeps risk ratings in a separate tool that warns but blocks nothing. In OneFinOps the check sits where it can still stop the payment.

See how vendor management works

Sources

Frequently asked questions

What is vendor risk assessment in simple words?

It means checking how likely a supplier is to cause you a problem and how bad that would be. You review its tax standing, finances, delivery, data handling and reputation, then score it.

What is the difference between vendor risk assessment and vendor risk management?

A vendor risk assessment is a point-in-time evaluation of one vendor that produces a score and a decision. Vendor risk management is the ongoing programme around it: tiering, contract controls, monitoring and reassessment.

How often should vendor risk be reassessed?

Commonly every year for high-risk vendors and every two years for medium-risk ones. GSTIN status and return filing need a monthly check regardless of tier, and any incident should trigger an immediate reassessment.

What is a vendor risk assessment questionnaire?

It is a structured set of questions sent to a vendor, grouped by risk domain, with evidence requested for key answers. Independent checks on the GST portal and MCA data are the other half.

Book a Demo