Skip to main content
Free Resource — No Email Required

Vendor Risk Inventory

Every vendor that touches your data, in one list — with a signed agreement and a risk rating. It's the single most-cited gap in audits, HIPAA reviews, and exams. Fill it in, keep it current, and you've closed the one examiners and enterprise buyers check first.

How to use: list every vendor that can see or hold your data, confirm a signed agreement exists for each, and rate the risk with the 5-question screen below. This is the lite version; the full SOC 2 Readiness Pack ($147) includes the complete Vendor Risk Management Policy and vendor security questionnaire, plus 8 policy templates.

Step 1 — List every vendor that touches your data

SaaS apps, cloud/hosting, payroll/HR, email, backup, MSP/IT, payment processors, anyone with remote access. If it stores, processes, or can reach your customer / member / patient data, it goes on the list. Tap a cell to edit.
Vendor What data they touch Agreement on file? (DPA / BAA) Renewal date Risk (H/M/L) Owner Next action
DPA vs BAA: use a BAA (Business Associate Agreement) for any vendor that can see PHI / patient data (HIPAA) — see the HIPAA Compliance Pack. Use a DPA (Data Processing Agreement) for other personal / customer / member data. A vendor touching PHI needs a BAA specifically; a generic DPA does not satisfy HIPAA.

Step 2 — Rate each vendor (5-question screen)

For each vendor, answer Yes / No. More "Yes" = higher risk = handle first.
Do they store or process sensitive data (PII, PHI, financial, member/customer records)?
Do they have direct access to your systems or network (integration, remote access, admin)?
Is there no signed agreement on file (DPA/BAA), or has it expired?
Can they not produce a current security attestation (SOC 2, ISO 27001, HITRUST, or equivalent)?
Would an outage or breach at this vendor disrupt your operations or expose your data?

Set the rating

  • 🔴 High — sensitive data and (no signed agreement, or no attestation, or direct system access). Fix the agreement first.
  • 🟡 Medium — sensitive data, but agreement + attestation are in place; review at renewal.
  • 🟢 Low — no sensitive data and no system access (e.g., a marketing tool with no PII).
The 15-minute win: sort by 🔴 High, then look at every row where the agreement is missing. Each one is a vendor that can see your data with nothing signed governing it — the exact finding an auditor, examiner, or insurer flags first. Getting those agreements signed is the highest-ROI move on this page.

Do it yourself

The full Vendor Risk Management Policy + questionnaire, in the SOC 2 Readiness Pack — with 8 policy templates.

Get the Pack — $147 →

Want a second opinion?

Free 30-min Risk Snapshot — a real read on your top gaps, no pitch.

Book the Risk Snapshot →