Vendor Risk Assessment
Detects vendor risk assessments revealing third-party security posture and supply chain vulnerabilities.
- Type
- regex
- Confidence
- medium
- Confidence justification
- Medium confidence: keyword-based detection requires corroborative evidence for accurate identification.
- Jurisdictions
- global
- Regulations
- IPA 2009 (Qld), Privacy Act 1988 (Cth), SOCI Act 2018 (Cth)
- Frameworks
- DISP, ISO 27001, NIST CSF
- Data categories
- security, governance
- Scope
- narrow
- Risk rating
- 4
Should match
Vendor risk assessment— Low-tier probe - assessment title without assessed resultsVendor risk assessment: inherent risk high and residual risk medium.— Medium-tier probe - assessed risk result without due-diligence evidenceThird-party risk assessment: inherent risk high; security questionnaire response and data handling controls reviewed.— High-tier probe - assessed risk plus due-diligence evidence
Should not match
Vendor booth at the market— Commercial vendor sibling without risk-assessment contextBest vendor award ceremony— Public award proseThe public procurement page links to a vendor risk assessment.— Public link mentions only the document titleTemplate example: vendor risk assessment with inherent risk high, security questionnaire response, and data handling controls.— Template contains otherwise high-tier evidence
Known false positives
- Generic vendor references in non-risk contexts. Mitigation: Require risk assessment keywords alongside vendor.