logo

Vendor Risk Management Checklist (Updated 2023) | UpGuard

ID: 9abb0def-ed7f-5072-9c9c-983cd3d93cb7

STIX ID: report--9abb0def-ed7f-5072-9c9c-983cd3d93cb7

Feed Name: UpGuard Blog

Date Published: 2023-11-17

Date Updated: 2026-05-01

...
...

This document is a comprehensive guide to vendor risk management, detailing how to conduct VRM audits, establish an operating model (three lines of defense), and implement policies and procedures for risk assessment, vendor management, and ongoing governance (e.g., SOC 2/ISO reviews, security questionnaires). It provides lifecycle guidance across qualification, engagement, information security management, delivery, and termination, with practical checklists for each stage, including due diligence, security controls, and contractual requirements. The piece also highlights UpGuard’s tooling—such as automated questionnaires, benchmarking, and AI Autofill—to streamline vendor assessments and improve the efficiency of third-party risk programs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.