Supplier Security Review Report Template
Documents the assessment outcome in a form the business owner can act on and an auditor can rely on.
Available soon
- Format
- Word
- Size
- 59 KB
- Length
- 19 pages
- Version
- 1.0
- Updated
What's inside
- How to use this template
- The report
- Worked example — a completed review
- Related documents
- Adapting this template
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
How to use this template
Use this report to close every supplier security assessment at [[Organisation Name]]. One report covers one supplier and one assessment. It records what was assessed and how, what was found, the risk left and the decision, in a form the business owner can act on and an auditor can rely on. The Supplier Security Assessment Procedure governs it; the rules are in the Third-Party Security Policy.
Part | Who completes it | When |
|---|---|---|
A — Supplier and service | Assessor | When the assessment starts |
B — Tier, and why | Assessor, with the business owner | At intake, or when the service changes (Supplier Criticality & Tiering Model) |
C — Scope | Assessor | When the questionnaire is sent |
D, E, F — Evidence, findings, residual risk | Assessor | When the evidence has been checked |
G, H — Decision and sign-off | Business owner [[the manager who buys and relies on the service]], with the assessor | Within [[10]] (Tier 1), [[10]] (Tier 2), [[5]] (Tier 3) working days of the evidence being validated (Supplier Security Assessment Procedure) |
I — Next reassessment | Assessor | With the sign-off; entered in the register |
Steps
- Complete Parts A to C from the supplier's row in the Supplier Security Risk Register, and send the questionnaire set for the tier from the Tiered Supplier Security Questionnaire — never a set above the tier (TP-03).
- Check each piece of evidence against the Supplier Due Diligence Evidence Checklist: scope, dates and legal entity (Part D). Anything that fails is a finding.
- Write each finding with its severity; the deadline is the report date plus the severity's days (Part E).
- Score the residual risk on the P05 scale and read its position against the appetite (Part F). Outside appetite, enter it in the P05 Information Security Risk Register.
- Agree the decision and conditions with the business owner, and both sign (Parts G and H).
- Update the register: last assessed, evidence validated, residual scores, decision, contract clauses, exit plan, and each finding on the Findings sheet. The next due date follows from the tier (Part I).
Guidance — delete before approval
Keep the field names in step with the columns of the Supplier Security Risk Register, so the register can be updated from this report without retyping.
Attach or link the evidence you reviewed. The report says what was checked; the evidence shows it.
Choosing the decision
The decision follows from the position and the findings. The business owner may choose a stricter one, never a looser one.
Decision | What it means | Use it when |
|---|---|---|
Approve | Residual risk within appetite; no High finding open. | Within appetite, and no High finding open |
Approve with conditions | Proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register. | Within appetite, but a High finding is open, or Medium findings the owner wants fixed as a condition |
Escalate | Residual risk outside appetite: the risk goes to the risk register (P05) and its owner decides treatment (RM-06). | Outside appetite for third-party dependency: enter it in the P05 register |
Reject | Do not contract, or plan exit (TP-11). | The risk cannot be brought within tolerance, or the supplier will not fix a High finding |
Finding severity and deadlines
Severity | What it means | Deadline from the report date |
|---|---|---|
High | A gap that could directly cause a significant incident or data loss at this supplier | 90 calendar days |
Medium | A gap that weakens a control but has other protection around it | 180 calendar days |
Low | An improvement; tracked to the next assessment | the next assessment |
A High finding past its deadline is escalated to the business owner (TP-08) and counted in TPM-03, high findings past deadline (target: zero).
Field guidance
Field | What a good answer looks like | Common reason a report is returned |
|---|---|---|
B1 Tiering | Each criterion answered for the service we buy, not the supplier in general; the override named where it applies. | Tier chosen by instinct, with no criterion shown. |
C1 Out of scope | What was not looked at, and who covers it. | Blank — the decision is read as covering everything. |
D Evidence | Each item checked for scope, dates and legal entity, with the result. | "Certificate received" — not checked against the service. |
E Findings | The gap and the risk it leaves, in a sentence the business owner understands. | Questionnaire question numbers instead of findings. |
F1 Reasons | Why each rating, with the findings that drive it. | A score with no reason. |
G1 Conditions | Named findings and dates; who follows them up. | "Supplier to improve security". |
The report
Guidance — delete before approval
Replace the placeholders when you adopt the template, or leave them as prompts. Keep the tier, severity and decision tables identical to the Supplier Criticality & Tiering Model and the Supplier Security Assessment Procedure.
Part A — Supplier and service
Completed by the assessor from the supplier's row in the Supplier Security Risk Register.
A1 Identification | |||
Report reference | [[SSR-YYYY-nnn]] | Supplier ref as in the register | [[SUP-nnn]] |
Supplier legal entity we contract with | [[Supplier legal name]] | ||
Business owner signs the decision (TP-05) | [[Role]] | Assessor | [[Role]] |
Contract | [[Contract reference; renewal date]] | ||
Reason for the review TP-01, TP-09 | [[New supplier / renewal / reassessment due / material change / incident or breach at the supplier]] | ||
Report date the date findings are raised | [[YYYY-MM-DD]] | ||
A2 What we buy and what it touches | |||
Critical services it supports | [[Services, as on the register's Critical Services sheet — or none]] | ||
Data it holds or sees | [[e.g. customer data, personal data, internal only, none]] | Access to our systems | [[e.g. privileged, network, remote support, none]] |
Part B — Tier, and why
The tier sets the questionnaire set, the evidence, the contract clauses and how often the supplier is reassessed. The tier must be the highest any criterion reaches, and never below an override's minimum. Use the Supplier Criticality & Tiering Model.
B1 Tiering (TP-02) | |||
TC-1 Service Tier 1: runs or supports a critical service, or a critical or important function | [[Tier n — the description that fits]] | ||
TC-2 Data Tier 1: sensitive or personal data at scale, or customer data | [[Tier n — the description that fits]] | ||
TC-3 Access Tier 1: privileged or network-level access to critical systems | [[Tier n — the description that fits]] | ||
TC-4 Substitutability Tier 1: could not be replaced within [[3 months]] without harm to a critical service | [[Tier n — the description that fits]] | ||
Override where one applies | [[None / an ICT service supporting a critical or important function of a DORA financial entity: at least Tier 1 / a processor of personal data under GDPR Article 28: at least Tier 2]] | ||
Tier | [[Tier n Name]] | Set by | [[Criteria that reached it, or the override]] |
Part C — Scope of the assessment
Each supplier must be sent the questionnaire set and evidence request for its tier, and never a set above it. Say what was and was not looked at, so the decision is not read as covering more than it does.
C1 Scope (TP-03) | |||
Questionnaire set | [[Set A / B / C / D]] | Sent / returned | [[YYYY-MM-DD / YYYY-MM-DD]] |
Evidence the tier requires | [[From the tier: see the Supplier Due Diligence Evidence Checklist]] | ||
In scope | [[The service, sites, teams and access assessed]] | ||
Out of scope and who covers it | [[What was not assessed, and why]] | ||
The supplier's own suppliers that matter to this service | [[Named sub-contractors or sub-processors, and whether they were covered]] | ||
How the assessment was done | [[Questionnaire, evidence review, call, site visit]] | ||
Part D — Evidence reviewed and how it was validated
Evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy. One row per item. An item that fails a check is not accepted as evidence; the gap becomes a finding.
Evidence | Date or period | Scope matches the service? | Legal entity matches? | Result |
|---|---|---|---|---|
[[e.g. certification, audit report]] | [[Valid to / period covered]] | [[Yes / No — what it covers]] | [[Yes / No]] | [[Validated / Not accepted — why]] |
[[e.g. penetration test summary]] | [[Test date]] | [[Yes / No]] | [[Yes / No]] | [[Validated / Not accepted — why]] |
[[e.g. continuity test results]] | [[Test date]] | [[Yes / No]] | [[Yes / No]] | [[Validated / Not accepted — why]] |
Part E — Findings
Every gap is a finding with an owner and a deadline set by its severity, counted from this report's date (TP-08): High 90 calendar days; Medium 180 calendar days; Low the next assessment. Findings go into the register's Findings sheet.
ID | Finding | Severity | Owner | Deadline |
|---|---|---|---|---|
[[F-nn]] | [[What is missing or weak, and the risk it leaves]] | [[High / Medium / Low]] | [[Business owner]] | [[Report date + severity's days]] |
[[F-nn]] | [[What is missing or weak, and the risk it leaves]] | [[High / Medium / Low]] | [[Business owner]] | [[Report date + severity's days]] |
Part F — Residual risk
Residual supplier risk must be scored on the P05 scale; a supplier outside appetite must be entered in the risk register. Score the risk this supplier still poses with the controls it and we have in place, on the P05 scale, and compare the band with the appetite for third-party dependency.
F1 Score and position (TP-06) | |||
Impact 1 Minor · 2 Moderate · 3 Major · 4 Severe | [[1–4]] | ||
Why this impact the worst consequence | [[Why this level]] | ||
Likelihood next 12 months: 1 Unlikely · 2 Possible · 3 Likely · 4 Almost certain | [[1–4]] | ||
Why this likelihood the findings count here | [[Why this level]] | ||
Residual score | [[I × L = n]] | Band Low 1–3 · Medium 4–6 · High 8–9 · Critical 12–16 | [[Low / Medium / High / Critical]] |
Appetite level RC-05 third-party dependency | [[Level: appetite band, tolerance band]] | Position | [[Within appetite / Outside appetite, within tolerance / Outside tolerance]] |
P05 Information Security Risk Register ref required outside appetite | [[R-nn / not needed]] | ||
Part G — Decision and conditions
Every assessment must end in a documented decision (Approve, Approve with conditions, Escalate, Reject), signed by the business owner. Choose the decision from the table in "How to use this template". Conditions name the findings to be fixed and by when.
G1 Decision (TP-05) | |||
Decision | [[Approve / Approve with conditions / Escalate / Reject]] | ||
Why this decision | [[Residual band, position and open High findings]] | ||
Conditions findings to fix, and by when | [[F-nn by YYYY-MM-DD; who follows up]] | ||
Contract clauses for the tier in place? TP-07 | [[Yes / No — what is missing, and when it is added]] | ||
Exit plan in place? TP-11, Tier 1 and 2 | [[Yes / No — when it will be written]] | ||
Supplier requirement not met? if yes, a P02 exception | [[None / exception reference, recorded in the Security Exception Register]] | ||
Part H — Sign-off
The assessor signs for the assessment; the business owner signs for the decision and its conditions. Escalate and Reject also go to the Head of Information Security.
H1 Signatures | |||
Assessor | [[Role]] | Signature and date | [[Signature, date]] |
Business owner TP-05 | [[Role]] | Signature and date | [[Signature, date]] |
Head of Information Security Escalate or Reject only | [[Role — or not required]] | Signature and date | [[Signature, date]] |
Recorded in the register by | [[Name or role, date]] | ||
Part I — Next reassessment and monitoring
Suppliers must be reassessed within their tier's interval, and on any material change, incident or breach at the supplier.
I1 Next steps (TP-09) | |||
Next reassessment due report date + the tier's interval | [[YYYY-MM-DD]] | ||
Monitoring until then by tier | [[From the tier]] | ||
Worked example — a completed review
The review of SUP-004, the ERP software provider (hosted), for a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. It is the same supplier and findings as in the Supplier Security Risk Register; the organisation, roles and dates are fictional.
Guidance — delete before approval
Note why the decision is Approve with conditions: the residual score is 6, Medium, and Cautious allows up to Medium, so the supplier is within appetite; but F-01 is High, and no High finding may be open under a plain Approve.
What happened next, as the register shows at 2026-09-30: F-01 passed its deadline on 2026-07-20 and was escalated to the Chief Financial Officer on 2026-07-21 (TP-08); F-02 is due 2026-10-18. A reassessment before 2027-04-21 is needed if the supplier's service or access changes (TP-09).
Delete this worked example from your adopted template.
Part A — Supplier and service
Completed by the assessor from the supplier's row in the Supplier Security Risk Register.
A1 Identification — EXAMPLE | |||
Report reference | SSR-2026-004 | Supplier ref as in the register | SUP-004 |
Supplier legal entity we contract with | ERP software provider (hosted) | ||
Business owner signs the decision (TP-05) | Chief Financial Officer | Assessor | Information Security Manager |
Contract | [[Contract reference]]; renews [[YYYY-MM-DD]] | ||
Reason for the review TP-01, TP-09 | First assessment of an existing supplier, before its contract renewal (TP-01, TP-09) | ||
Report date the date findings are raised | 2026-04-21 | ||
A2 What we buy and what it touches — EXAMPLE | |||
Critical services it supports | Finance and payroll; Warehouse dispatch | ||
Data it holds or sees | Personal data | Access to our systems | Remote support |
Part B — Tier, and why
The tier sets the questionnaire set, the evidence, the contract clauses and how often the supplier is reassessed. The tier must be the highest any criterion reaches, and never below an override's minimum. Use the Supplier Criticality & Tiering Model.
B1 Tiering (TP-02) — EXAMPLE | |||
TC-1 Service Tier 1: runs or supports a critical service, or a critical or important function | Tier 1 — runs or supports a critical service, or a critical or important function | ||
TC-2 Data Tier 1: sensitive or personal data at scale, or customer data | Tier 2 — personal data | ||
TC-3 Access Tier 1: privileged or network-level access to critical systems | Tier 2 — remote user access to our systems | ||
TC-4 Substitutability Tier 1: could not be replaced within [[3 months]] without harm to a critical service | Tier 1 — could not be replaced within [[3 months]] without harm to a critical service | ||
Override where one applies | GDPR processor: at least Tier 2 (a processor of personal data under GDPR Article 28) | ||
Tier | Tier 1 Critical | Set by | TC-1, TC-4; the override's minimum (Tier 2) is lower |
Part C — Scope of the assessment
Each supplier must be sent the questionnaire set and evidence request for its tier, and never a set above it. Say what was and was not looked at, so the decision is not read as covering more than it does.
C1 Scope (TP-03) — EXAMPLE | |||
Questionnaire set | Set A (about 60 questions) | Sent / returned | 2026-03-10 / 2026-04-02 |
Evidence the tier requires | Independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results | ||
In scope | The hosted ERP service (finance, payroll and warehouse modules); the supplier's hosting, operations and support centre; its remote support access to our ERP. | ||
Out of scope and who covers it | Our own ERP configuration and user administration, which our IT team runs under our own controls. | ||
The supplier's own suppliers that matter to this service | Hosting in a cloud data centre run by the supplier's own cloud provider (named in the supplier's answers). Covered by the supplier's certification scope. | ||
How the assessment was done | Questionnaire set answered in writing; evidence requested and checked; a 90-minute call with the supplier's security lead on 2026-04-14 to test the answers on remote support and data deletion. | ||
Part D — Evidence reviewed and how it was validated
Evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy. One row per item. An item that fails a check is not accepted as evidence; the gap becomes a finding.
Evidence | Date or period | Scope matches the service? | Legal entity matches? | Result |
|---|---|---|---|---|
Information security certification (ISO/IEC 27001) | Valid to February 2027 | Yes — development, hosting and support of the hosted ERP service | Yes — the legal entity we contract with | Validated |
Penetration test summary (independent tester) | Tested February 2026 | Yes — the hosted ERP application and hosting | Yes | Validated; every High finding fixed and retested by March 2026 |
Continuity test results | Failover test January 2026 | Yes — failover between the ERP data centres | Yes | Validated; results shared with us |
Questionnaire set answers | Returned 2026-04-02 | — | Yes — signed for the contracting entity by its security lead | Reviewed; two gaps, raised as F-01 and F-02 |
Data processing terms in the contract (GDPR Art 28(3)) | Contract signed [[YYYY-MM-DD]] | Yes — covers the personal data in the ERP | Yes | Present; no evidence that deletion at contract end is carried out (F-02) |
Part E — Findings
Every gap is a finding with an owner and a deadline set by its severity, counted from this report's date (TP-08): High 90 calendar days; Medium 180 calendar days; Low the next assessment. Findings go into the register's Findings sheet.
ID | Finding | Severity | Owner | Deadline |
|---|---|---|---|---|
F-01 | Support staff reach our ERP without multi-factor authentication | High | Chief Financial Officer | 2026-07-20 |
F-02 | No evidence that our data is deleted at contract end | Medium | Chief Financial Officer | 2026-10-18 |
Part F — Residual risk
Residual supplier risk must be scored on the P05 scale; a supplier outside appetite must be entered in the risk register. Score the risk this supplier still poses with the controls it and we have in place, on the P05 scale, and compare the band with the appetite for third-party dependency.
F1 Score and position (TP-06) — EXAMPLE | |||
Impact 1 Minor · 2 Moderate · 3 Major · 4 Severe | 3 Major | ||
Why this impact the worst consequence | Finance and payroll and warehouse dispatch both depend on the ERP, which holds personal data (staff pay and bank details, supplier contacts) with our order and stock records: a compromise could stop both services for days and be a notifiable breach. | ||
Likelihood next 12 months: 1 Unlikely · 2 Possible · 3 Likely · 4 Almost certain | 2 Possible | ||
Why this likelihood the findings count here | Strong, certified controls and a penetration test in February 2026 with every High finding fixed; but the provider's support staff reach our ERP without multi-factor authentication (F-01), a known route for attackers. | ||
Residual score | 3 × 2 = 6 | Band Low 1–3 · Medium 4–6 · High 8–9 · Critical 12–16 | Medium |
Appetite level RC-05 third-party dependency | Cautious: appetite Medium, tolerance High | Position | Within appetite |
P05 Information Security Risk Register ref required outside appetite | Not needed (within appetite) | ||
Part G — Decision and conditions
Every assessment must end in a documented decision (Approve, Approve with conditions, Escalate, Reject), signed by the business owner. Choose the decision from the table in "How to use this template". Conditions name the findings to be fixed and by when.
G1 Decision (TP-05) — EXAMPLE | |||
Decision | Approve with conditions | ||
Why this decision | Proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register. Residual Medium is within appetite, but a High finding is open, so the decision cannot be a plain Approve. | ||
Conditions findings to fix, and by when | F-01 and F-02 fixed by their deadlines. The business owner follows them up; the assessor checks the evidence of each fix. A High finding past its deadline is escalated to the business owner (TP-08). | ||
Contract clauses for the tier in place? TP-07 | Yes — the Tier 1 clauses from the Supplier Contract Security Clause Library | ||
Exit plan in place? TP-11, Tier 1 and 2 | Yes — data return and deletion, access removal and a transition period (TP-11) | ||
Supplier requirement not met? if yes, a P02 exception | None | ||
Part H — Sign-off
The assessor signs for the assessment; the business owner signs for the decision and its conditions. Escalate and Reject also go to the Head of Information Security.
H1 Signatures — EXAMPLE | |||
Assessor | Information Security Manager (assessor) | Signature and date | Signed, 2026-04-21 |
Business owner TP-05 | Chief Financial Officer (business owner) | Signature and date | Signed, 2026-04-21 |
Head of Information Security Escalate or Reject only | Not required (not Escalate or Reject) | Signature and date | — |
Recorded in the register by | Information Security Manager, 2026-04-21 | ||
Part I — Next reassessment and monitoring
Suppliers must be reassessed within their tier's interval, and on any material change, incident or breach at the supplier.
I1 Next steps (TP-09) — EXAMPLE | |||
Next reassessment due report date + the tier's interval | 2027-04-21 | ||
Monitoring until then by tier | Continuous: breach news, certificate and report expiry, material changes | ||
Related documents
Document | Relationship |
|---|---|
Third-Party Security Policy | The rules this report applies (TP-01 to TP-12) |
Supplier Security Assessment Procedure | The procedure that governs this report |
Supplier Criticality & Tiering Model | The tiering criteria and overrides in Part B |
Tiered Supplier Security Questionnaire | The questionnaire set sent for the tier (Part C) |
Supplier Due Diligence Evidence Checklist | What evidence each tier needs and how to validate it (Part D) |
Supplier Contract Security Clause Library | The contract clauses for each tier (Part G) |
Supplier Security Risk Register | Where the result is recorded: the supplier's row and its findings |
Third-Party Risk Dashboard | Reports coverage, overdue reviews, late findings and concentration each quarter |
P05 Information Security Risk Register | Where a supplier outside appetite is entered and treated |
P02 Security Exception & Waiver Standard | The route when a supplier requirement is not met |
Adapting this template
Guidance — delete before approval
Small organisation: for Tier 3 and Tier 4 suppliers, Parts A, B, G and H are enough. Where the assessor is also the business owner — common when one person runs IT and buys the services — ask a second manager to countersign the decision, so nobody approves their own supplier alone.
Regulated entity (NIS2, DORA, GDPR): NIS2 Article 21(3) expects each direct supplier's vulnerabilities and the quality of its products and security practices to be taken into account; Parts D to F are that record. For a DORA financial entity, a supplier of ICT services supporting a critical or important function is Tier 1 by override; keep the report with the register of information (Art 28(3)) and check the contract content required by Art 30. Where the supplier processes personal data for you, GDPR Article 28(1) allows only processors with sufficient guarantees: Part D is where you show you checked them, and the Data Protection Officer [[where one is appointed]] should see the report.
IT run by a service provider: the provider is assessed with this report like any Tier 1 supplier. Ask it to name the suppliers it relies on for your service (Part C) and to report changes to them as a material change (TP-09).
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR).
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Annex A 5.19 — Information security in supplier relationships | Parts B and G: security requirements set by tier and agreed with the supplier, recorded with the decision |
ISO/IEC 27001:2022 | Annex A 5.22 — Monitoring, review and change management of supplier services | Parts D, E and I: supplier security reviewed against evidence, findings tracked and the next review set |
NIST CSF 2.0 | GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship” | Parts E to G: supplier risk assessed, recorded, prioritised and responded to |
NIST CSF 2.0 | GV.SC-06 — “Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships” | Parts C and D: due diligence before contracting or renewal |
NIS2 — Directive (EU) 2022/2555 | Article 21(3) — measures take into account each direct supplier's specific vulnerabilities and the overall quality of its products and cybersecurity practices, including secure development | Parts D to F: the supplier's vulnerabilities and security practices taken into account |
GDPR — Regulation (EU) 2016/679 | Article 28(1) — use only processors providing sufficient guarantees of appropriate technical and organisational measures | Part D: evidence that a processor provides sufficient guarantees |
Definitions
Term | Meaning in this report |
|---|---|
Assessor | The person who runs the assessment and signs Part H: [[e.g. Information Security Manager]]. |
Business owner | [[the manager who buys and relies on the service]]. Signs the decision (TP-05) and receives escalated findings (TP-08). |
Evidence validated | Evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy. |
Finding | A gap between what the supplier does and what its tier requires, with a severity, an owner and a deadline. |
Position | Where the residual band stands against the appetite for third-party dependency: Within appetite; Outside appetite, within tolerance; Outside tolerance. |
Residual risk | The risk the supplier still poses with the controls in place, scored impact × likelihood on the P05 scale (bands Low 1–3 · Medium 4–6 · High 8–9 · Critical 12–16). |
Tier | Tier 1 Critical, Tier 2 Important, Tier 3 Standard, Tier 4 Minimal. The tier must be the highest any criterion reaches, and never below an override's minimum. |
TP-nn, TPM-nn | Rule and measure numbers in the Third-Party Security Policy. |