Documentation

Ongoing operations

Vendor and processor risk scoring

A vendor register that lists names and contracts does not on its own show which of those vendors is actually a risk. GDPR Article 28 requires you to only use processors offering sufficient guarantees, which means assessing what those guarantees actually are, vendor by vendor.

Transcript

A vendor register that just lists names and contracts does not tell you which of those vendors is actually a risk. GDPR Article 28 requires you to only use processors offering sufficient guarantees, which means you first have to assess what those guarantees are.

The risk questionnaire asks the questions that actually matter: what data the vendor can access, whether a Data Processing Agreement is signed, what security certifications they hold, and, for financial entities, their DORA Article 28 criticality.

Answers are scored additively, with certain combinations -- personal data with no signed agreement, a cross-border transfer with no legal mechanism -- escalating straight to critical. Every point on the score has a stated reason attached to it.

The result attaches to the vendor record with a dated risk tier, so "we assessed our vendors" becomes a specific score, on a specific day, with a specific justification.

Why this is required

Article 28 puts the burden on the controller to have assessed a processor's guarantees, not merely to have a signed contract. A DPA on file answers a different question than "is this vendor actually a risk".

For financial entities, DORA Article 28 additionally requires tracking which ICT third parties are critical, since a dependency on a critical vendor with no exit strategy is a concentration risk in its own right.

What EuroCompliant does

The risk questionnaire asks what actually matters: what data the vendor can access, whether a Data Processing Agreement is signed, what security certifications the vendor holds, whether data leaves the EEA and under what transfer mechanism, and, for financial entities, DORA criticality and exit-strategy status.

Answers are scored additively, with certain combinations, personal data with no signed agreement, or a cross-border transfer with no legal transfer mechanism, escalating straight to a critical tier. Every point on the score carries a stated reason, so the result is explainable rather than a bare number.

The result attaches to the vendor record with a dated risk tier and a history of past assessments, so a vendor's risk posture is something you can show changed, and when, rather than a single static label.

Walking through it

1

Open a vendor's record

Every processor already tracked in the register can be assessed.

Open /data-records →
2

Complete the risk questionnaire

Data access, transfer mechanism, certifications, and, where relevant, DORA criticality.

Open /data-records →
3

Review the scored result

A tier, a score, and the specific reasons behind it, kept as history for future reference.

Open /data-records →

The law

Frequently asked

What makes a vendor score "Critical" automatically?

A small number of combinations that are serious enough to short-circuit the score regardless of other answers: notably a cross-border data transfer with no valid legal transfer mechanism, or special-category or personal data processed with no signed Data Processing Agreement.

Does this replace legal review of vendor contracts?

No. It gives you a defensible, dated risk signal to decide where legal review and further diligence are actually worth spending time, not a substitute for reading the contract.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial