Vendor Risk Assessment Workbook

A free, downloadable spreadsheet for scoring and tracking every vendor your company relies on — security tools, cloud infrastructure, HR platforms, payment processors, and AI vendors — in one place.

Most vendor risk templates are a one-time questionnaire: fill it out, file it away, forget it. This one is built to stay current. It scores vendors across five risk domains, flags GDPR gaps automatically, and tells you exactly when each vendor is due for another look — not just when you onboarded them.

Download the free workbook → (.xlsx, no email required)

What’s inside

The workbook has five working tabs:

Dashboard — a live overview of your vendor ecosystem: total vendors, AI vendors, vendors handling personal data, failed risk gates, missing DPAs, and reviews coming due. Built to be understood in under 15 seconds.

Vendor Inventory — one row per vendor: what they do, what data they touch, and whether they’re acting as your GDPR processor, controller, or neither. This is the only sheet where you type a Vendor ID — every other tab pulls it in automatically.

Risk Assessment — score each vendor across five domains (security posture, data handling, compliance, AI governance, operational resilience), with space to record the actual evidence behind each score — a SOC 2 report, a DPA, a trust center page — so the score isn’t just a guess. The workbook calculates a weighted composite score and a final risk tier automatically.

DPA & Processing Compliance — checks your vendor DPAs against the specific contractual elements GDPR Article 28 requires, and correctly routes Joint Controller relationships to a different standard instead of forcing every vendor into the same box.

Renewal & Reassessment — sets a review date for every vendor based on its risk tier, and flags nine specific events (a breach, a sub-processor change, a new AI feature) that should trigger an early re-check regardless of the calendar.

Why score and gate, not just score

A vendor can score well overall and still have a dealbreaker — refusing to disclose its sub-processors, or training its models on your customer data with no opt-out. The workbook treats those as hard stops: any one of them overrides the numeric score and forces the vendor into the highest risk tier, so a good composite score can never quietly hide a real problem.

Who this is for

SaaS companies — particularly ones serving customers in Spain or the broader EU — that need to show real due diligence on their vendors, not just a folder of unread contracts. If you’re building your full AI governance program, start with the AI Governance Checklist; if you want the full methodology behind the scoring in this workbook, see the AI Vendor Risk Assessment guide.

How to use it

  1. Add each vendor to the Vendor Inventory tab and set its Vendor ID.
  2. Score it across the five risk domains in Risk Assessment, recording your evidence as you go.
  3. If it’s a data processor, complete its DPA compliance check.
  4. Check the Dashboard for anything that needs attention.
  5. Let the Renewal tab tell you when to look again.

Download the free workbook →


Related resources