Vendor Risk Management Checklist (Updated 2023) | UpGuard
ID: 9abb0def-ed7f-5072-9c9c-983cd3d93cb7
STIX ID: report--9abb0def-ed7f-5072-9c9c-983cd3d93cb7
Feed Name: UpGuard Blog
This document is a comprehensive guide to vendor risk management, detailing how to conduct VRM audits, establish an operating model (three lines of defense), and implement policies and procedures for risk assessment, vendor management, and ongoing governance (e.g., SOC 2/ISO reviews, security questionnaires). It provides lifecycle guidance across qualification, engagement, information security management, delivery, and termination, with practical checklists for each stage, including due diligence, security controls, and contractual requirements. The piece also highlights UpGuard’s tooling—such as automated questionnaires, benchmarking, and AI Autofill—to streamline vendor assessments and improve the efficiency of third-party risk programs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
