Glossary

Vendor Risk Management

Vendor risk management (VRM) is the process of identifying, assessing, and monitoring the security and compliance risks introduced by third-party suppliers and service providers.

Organizations increasingly depend on third parties for infrastructure, software, and services, and each vendor can introduce risk to data and operations. Vendor risk management is the discipline of evaluating and continuously monitoring those risks across the vendor lifecycle.

A typical VRM program inventories vendors, tiers them by criticality and data access, assesses them through security questionnaires and review of their attestations, and tracks remediation of identified issues. Contractual safeguards such as data processing agreements formalize each vendor's obligations.

VRM is reinforced by most compliance frameworks, which expect organizations to manage supply-chain risk. Automating questionnaire distribution, evidence collection, and ongoing monitoring keeps assessments current as the vendor portfolio changes.

Related terms