Vendor risk assessment is the process of evaluating a supplier’s compliance, financial, operational, data security and reputational risk before you sign it up and at regular intervals afterwards. Done once at onboarding and filed away, it misses the vendor who stops filing GST returns in month four, and the input tax credit you claimed goes with it.
In OneFinOps, the Vendor Compliance Agent re-screens each vendor on the cycle its risk tier sets, so a lapse shows before the next payment.
Key takeaways
- Tier first, then assess the vendor at the depth its tier needs.
- Score six domains from 1 to 5, weight them, then read each alone.
- Verify key answers on official portals, not only the questionnaire.
What is the vendor risk assessment process?
- Tier by inherent risk. Access to personal data or systems, or sole supply of a critical input, makes a vendor High.
- Send a questionnaire scaled to the tier, with evidence for high and critical.
- Verify independently. PAN, GSTIN and return filing, Udyam, and MCA company status.
- Score, weight and tier using the framework below.
- Decide and set controls. Approve, approve with conditions (advance limits, audit rights, data clauses), or reject.
- Reassess on schedule, and at once after a GSTIN cancellation or data incident.
What is a vendor risk assessment framework?
Weighted score = sum of (domain score × weight), between 1.0 and 5.0.
| Domain | Weight | Score 1 (low risk) looks like | Score 5 (very high risk) looks like |
|---|---|---|---|
| Compliance and tax | 25% | PAN operative, GSTIN active, returns on time for 12 months | GSTIN cancelled, returns missing, PAN inoperative |
| Financial | 20% | Profitable for 3 years, no default | Losses, negative net worth, demands large advances |
| Operational and delivery | 20% | Two or more sites, on-time delivery above 95% | Single site, no backup, repeated delays |
| Information security and data | 15% | No data access, or ISO 27001 or SOC 2 report | Sensitive data with no controls |
| Legal and contractual | 10% | Signed contract with SLA and audit rights | No contract, fraud or insolvency proceedings |
| Reputational, ESG and concentration | 10% | No adverse news, below 40% of category spend | Regulatory action, above 70% of category spend |
Tiers: 1.0 to 1.9 low, 2.0 to 2.9 medium, 3.0 to 3.9 high, 4.0 to 5.0 (or any domain at 5) critical. Reassess critical every 6 months, high yearly, medium every 2 years.
Vendor risk assessment example
A packaging supplier with ₹1,20,00,000 (₹1.2 crore) of annual purchases scores a weighted 2.95, which says medium. Its compliance score of 4 says otherwise: GSTR-3B is not filed for three of the last six months. At 18% GST, about ₹21,60,000 of input tax credit a year depends on it, and section 16(2) of the CGST Act allows credit only when the supplier actually pays the tax. Decision: approve with conditions, and hold the GST portion of payments until returns are current.
How OneFinOps handles vendor risk
The Vendor Compliance Agent keeps the assessment live. It re-screens each vendor on the cycle its risk tier and category set, tracks every certificate to its expiry date, and holds the payment when a required document has lapsed. Every held payment goes to the compliance owner with the missing document named, and any override goes to the approver allowed to grant it, with the reason recorded.
The usual setup keeps risk ratings in a separate tool that warns but blocks nothing. In OneFinOps the check sits where it can still stop the payment.
See how vendor management works
