Ongoing operations
Vendor and processor risk scoring
A vendor register that lists names and contracts does not on its own show which of those vendors is actually a risk. GDPR Article 28 requires you to only use processors offering sufficient guarantees, which means assessing what those guarantees actually are, vendor by vendor.
Transcript
A vendor register that just lists names and contracts does not tell you which of those vendors is actually a risk. GDPR Article 28 requires you to only use processors offering sufficient guarantees, which means you first have to assess what those guarantees are.
The risk questionnaire asks the questions that actually matter: what data the vendor can access, whether a Data Processing Agreement is signed, what security certifications they hold, and, for financial entities, their DORA Article 28 criticality.
Answers are scored additively, with certain combinations -- personal data with no signed agreement, a cross-border transfer with no legal mechanism -- escalating straight to critical. Every point on the score has a stated reason attached to it.
The result attaches to the vendor record with a dated risk tier, so "we assessed our vendors" becomes a specific score, on a specific day, with a specific justification.
Why this is required
Article 28 puts the burden on the controller to have assessed a processor's guarantees, not merely to have a signed contract. A DPA on file answers a different question than "is this vendor actually a risk".
For financial entities, DORA Article 28 additionally requires tracking which ICT third parties are critical, since a dependency on a critical vendor with no exit strategy is a concentration risk in its own right.
What EuroCompliant does
The risk questionnaire asks what actually matters: what data the vendor can access, whether a Data Processing Agreement is signed, what security certifications the vendor holds, whether data leaves the EEA and under what transfer mechanism, and, for financial entities, DORA criticality and exit-strategy status.
Answers are scored additively, with certain combinations, personal data with no signed agreement, or a cross-border transfer with no legal transfer mechanism, escalating straight to a critical tier. Every point on the score carries a stated reason, so the result is explainable rather than a bare number.
The result attaches to the vendor record with a dated risk tier and a history of past assessments, so a vendor's risk posture is something you can show changed, and when, rather than a single static label.
Walking through it
Open a vendor's record
Every processor already tracked in the register can be assessed.
Open /data-records →Complete the risk questionnaire
Data access, transfer mechanism, certifications, and, where relevant, DORA criticality.
Open /data-records →Review the scored result
A tier, a score, and the specific reasons behind it, kept as history for future reference.
Open /data-records →The law
Frequently asked
What makes a vendor score "Critical" automatically?
A small number of combinations that are serious enough to short-circuit the score regardless of other answers: notably a cross-border data transfer with no valid legal transfer mechanism, or special-category or personal data processed with no signed Data Processing Agreement.
Does this replace legal review of vendor contracts?
No. It gives you a defensible, dated risk signal to decide where legal review and further diligence are actually worth spending time, not a substitute for reading the contract.
Related guides
Integrations, scanning and vendor risk
Connecting your infrastructure for automated scanning, wiring up notifications, and tracking third-party risk.
Vendor self-service due-diligence questionnaires
Send the same risk questionnaire directly to a vendor's own contact, instead of assessing them on their behalf.
DORA: digital operational resilience
What DORA requires of EU financial entities, and the real, working parts of the platform built around it: vendor criticality flags and infrastructure scanning.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial