Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
ATL-028WORKSHEETEDITORIAL REVIEW COMPLETE

Vendor Risk Assessment Worksheet

A per-vendor decision record that ties together what the vendor touches, what their questionnaire said, what the contract commits them to, and which access pathways they hold — ending in an owned decision: approve, approve with conditions, or decline.

Using this artifact

Purpose, inputs, and completion

Purpose. Questionnaires collect information; this worksheet is where the information becomes a decision. Each vendor gets one row that states what they can reach, what they claimed, what the contract binds them to, which pathways they hold, and what you decided — with conditions owned and dated rather than wished. It converts vendor management from a feeling about relationships into a record of choices.

When to use it. Assess vendors in order of reach: whoever can touch contract data, production systems, or your network comes first, whatever their invoice size. Complete a row per vendor from the questionnaire and pathway inventory rather than from memory of the sales relationship, and record the decision even when it is easy — a page of 'approve' decisions with citations is a real record. Re-run at every renewal and annually for critical vendors, and work the conditions table until it is empty or current.

Required inputsHave these before you start
  • The supplier questionnaire results (ATL-027)
  • The remote access pathway inventory (ATL-026) rows for the vendor
  • The contract or terms of service, for incident-notification and data-handling language
Completion instructionsIn order
  • Write down what the vendor actually touches — data, systems, access, deliveries — before forming any view; risk follows reach.
  • Cite the vendor's questionnaire (ATL-027) and pathway rows (ATL-026) in the record; an assessment citing neither is an opinion.
  • Check the contract for incident-notification terms; deep access plus no duty to tell you about their breach is a condition waiting to be written.
  • Record a decision — approve, approve with conditions, or decline — and give every condition a named owner and a due date; an unowned condition is a wish.
Keeping it honest

Evidence, validation, and failure modes

Evidence this producesWhat a reviewer could examine
  • A per-vendor risk record with a dated decision
  • A conditions list with owners and due dates
  • Cross-references tying each decision to questionnaire and pathway evidence
Validation checksRun these before calling it complete
  • Pick one approved-with-conditions vendor and check that each condition has an owner and a due date that has not silently passed.
  • Cross-check three vendors against ATL-026: every access pathway they hold appears in their assessment row.
What looks done but is not
  • Assessments happen once at onboarding and never at renewal, so the record describes the vendor as it was, not as it is.
  • Conditions are written but never tracked, and 'approve with conditions' quietly becomes plain 'approve'.
  • OT vendors get scored on their paperwork while their standing modem into the line — the actual risk — sits outside the assessment entirely.
Mapped relationships

Practices and requirements this artifact relates to

Brilliant at the Basics practices

NIST SP 800-171 Rev. 2

NIST SP 800-171 Rev. 3

Relationships are mapped support, not equivalence: completing this artifact documents work relevant to these requirements and does not by itself address any of them. Retention: Retain each vendor's assessments across cycles for the life of the relationship; the decision trail — approve, conditions, decline — is exactly what a reviewer will ask to see.

Full document

Preview — exactly what prints

WORKSHEET · SUPPLY CHAIN & THIRD PARTIESv1.0 · REVIEWED 2026-08-06

Vendor Risk Assessment Worksheet

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

Questionnaires collect information; this worksheet is where the information becomes a decision. Each vendor gets one row that states what they can reach, what they claimed, what the contract binds them to, which pathways they hold, and what you decided — with conditions owned and dated rather than wished. It converts vendor management from a feeling about relationships into a record of choices.

How to use it

Assess vendors in order of reach: whoever can touch contract data, production systems, or your network comes first, whatever their invoice size. Complete a row per vendor from the questionnaire and pathway inventory rather than from memory of the sales relationship, and record the decision even when it is easy — a page of 'approve' decisions with citations is a real record. Re-run at every renewal and annually for critical vendors, and work the conditions table until it is empty or current.

Vendor risk register

One row per vendor. The decision column admits three values only — approve, approve with conditions, decline — because 'we should look into them sometime' is not a decision.

Rows beginning EXAMPLE: show the expected shape — replace them with your own.

VendorWhat the vendor touches (data / systems / access)CriticalityQuestionnaire result summary (ATL-027)Incident-notification terms in contract?Access pathway reference (ATL-026)Risk decision (approve / conditions / decline)Conditions and ownerReview date
EXAMPLE: Machine builder (packaging line)Remote maintenance access to line PLCs; supplies spare parts and firmwareHigh — line is down without themPartial: MFA on their jump-host accounts; no restore-test date givenNo — notification clause absentATL-026 rows 4–5 (support tunnel)Approve with conditionsNotification clause at renewal; restore-test evidence — owner: procurement lead2026-12-01
EXAMPLE: Payroll SaaSEmployee PII; no contract data, no plant accessMediumYes with evidence, dated 2026-05Yes — 48-hour notificationATL-026 row 9 (admin portal)ApproveNone2027-06-01
         
         
         

Conditions tracking

Every 'approve with conditions' spawns rows here. This table is where those conditions either get done or get honestly re-decided — never silently forgotten.

Rows beginning EXAMPLE: show the expected shape — replace them with your own.

ConditionVendorOwnerDue dateStatus
EXAMPLE: Add 72-hour incident-notification clause at contract renewalMachine builder (packaging line)Procurement lead2026-11-30Drafted; with counsel
     
     
     

OT vendors deserve extra attention

Remote maintenance, spare parts, and firmware provenance

A vendor who dials into your controllers, stocks your spare parts, or ships firmware to your plant holds risks no office-vendor assessment captures. Ask three extra questions: how their remote maintenance sessions are brokered and logged on your side (their ATL-026 rows are the answer, or the gap); where spare parts and replacement units actually come from, since a gray-market drive with unknown firmware goes straight into production; and how firmware is obtained and verified before it reaches a controller. Any access or update change that follows from this assessment is coordinated with the vendor and the process owner through a maintenance window — an assessment that strands the plant without support has failed at its own job.

Document control, version history, and approval

An artifact without an owner, a review date, and an approval trail is a snapshot, not a record. Complete this section before the document is used, and update it at every review.

FieldEntry
Document owner (named person) 
Suggested owner roleIT leader or compliance lead
Approval authorityExecutive sponsor
Review frequencyAt vendor onboarding, at contract renewal, and annually for critical vendors
Next scheduled review 
Storage location of the completed document 
RetentionRetain each vendor's assessments across cycles for the life of the relationship; the decision trail — approve, conditions, decline — is exactly what a reviewer will ask to see.

Version history

VersionDateAuthorSummary of changeApproved by
     
     
     
     

Review and approval

Reviewed byRoleDateSignature / initials
    
    
Complete this offline — and mind what you write down

Fill this in inside your own environment, not on any public website or unapproved cloud tool. A completed copy may reveal your security posture: never include CUI, export-controlled data, credentials or keys, unremediated vulnerability details, network diagrams, or customer-sensitive information beyond what the artifact strictly needs, and store the completed document with the same care as the systems it describes.

Vendor Risk Assessment Worksheet · version 1.0 · reviewed 2026-08-06 · file name batb-vendor-risk-assessment-worksheet

Generated from the live artifact library at brilliantatthebasics.us/templates/vendor-risk-assessment-worksheet. Independent educational material published by inDirectIT, Inc. Tailor every section to your technical, operational, contractual, regulatory, and safety requirements.