Vendor Risk Management
Vendor risk management (VRM) is the process of identifying, assessing, and monitoring the security and compliance risks introduced by third-party suppliers and service providers.
Organizations increasingly depend on third parties for infrastructure, software, and services, and each vendor can introduce risk to data and operations. Vendor risk management is the discipline of evaluating and continuously monitoring those risks across the vendor lifecycle.
A typical VRM program inventories vendors, tiers them by criticality and data access, assesses them through security questionnaires and review of their attestations, and tracks remediation of identified issues. Contractual safeguards such as data processing agreements formalize each vendor's obligations.
VRM is reinforced by most compliance frameworks, which expect organizations to manage supply-chain risk. Automating questionnaire distribution, evidence collection, and ongoing monitoring keeps assessments current as the vendor portfolio changes.
Related terms
- Risk RegisterA risk register is a centralized record of an organization's identified risks, capturing their likelihood, impact, ownership, and treatment status.
- GDPRThe General Data Protection Regulation (GDPR) is the European Union law governing the processing of personal data, granting individuals rights over their data and imposing accountability obligations on organizations.
- HIPAAThe Health Insurance Portability and Accountability Act (HIPAA) is a US law that sets standards for protecting sensitive patient health information held by covered entities and their business associates.
- Continuous ComplianceContinuous compliance is the practice of monitoring controls and collecting evidence on an ongoing basis, so an organization remains audit-ready at all times rather than only before an audit.