Ongoing operations
Vendor and processor risk scoring
A vendor register that lists names and contracts does not on its own show which of those vendors is actually a risk. GDPR Article 28 requires you to only use processors offering sufficient guarantees, which means assessing what those guarantees actually are, vendor by vendor.
Transcript
A vendor register that just lists names and contracts does not tell you which of those vendors is risky. This is how you score every third party that touches your data.
Open the Trust & Privacy Hub and go to Data & Vendors. Register a processor with its name, the service it provides, the data types it touches, and where that data goes. Send it outside the EEA, and an Article 46 safeguards section appears on the spot, asking for the transfer mechanism and whether a transfer impact assessment has been done.
Once it is added, expand the entry to reveal the tools every processor gets: a risk questionnaire, a way to send it straight to the vendor's own contact, and an attachment panel for the signed paperwork.
The risk questionnaire asks the questions that actually matter: what data the vendor can access, whether they are a critical ICT provider, and whether an exit strategy exists.
Run the assessment and answer the questions. Answers are scored additively, with certain combinations, like personal data with no signed DPA, pushing the risk tier up.
The result is a dated risk tier: low, medium, high, or critical. The tier updates the vendor record so the risk is visible everywhere that vendor appears.
Now the register tells you where to focus: critical vendors first. Re-assess on a schedule, and the history shows that risk changing over time, which is exactly what an auditor wants to see.
Why this is required
Article 28 puts the burden on the controller to have assessed a processor's guarantees, not merely to have a signed contract. A DPA on file answers a different question than "is this vendor actually a risk".
For financial entities, DORA Article 28 additionally requires tracking which ICT third parties are critical, since a dependency on a critical vendor with no exit strategy is a concentration risk in its own right.
What EuroCompliant does
The risk questionnaire asks what actually matters: what data the vendor can access, whether a Data Processing Agreement is signed, what security certifications the vendor holds, whether data leaves the EEA and under what transfer mechanism, and, for financial entities, DORA criticality and exit-strategy status.
Answers are scored additively, with certain combinations, personal data with no signed agreement, or a cross-border transfer with no legal transfer mechanism, escalating straight to a critical tier. Every point on the score carries a stated reason, so the result is explainable rather than a bare number.
The result attaches to the vendor record with a dated risk tier and a history of past assessments, so a vendor's risk posture is something you can show changed, and when, rather than a single static label.
Walking through it
Open a vendor's record
Every processor already tracked in the register can be assessed.
Open /privacy-hub →Complete the risk questionnaire
Data access, transfer mechanism, certifications, and, where relevant, DORA criticality.
Open /privacy-hub →Review the scored result
A tier, a score, and the specific reasons behind it, kept as history for future reference.
Open /privacy-hub →The law
Frequently asked
What makes a vendor score "Critical" automatically?
A small number of combinations that are serious enough to short-circuit the score regardless of other answers: notably a cross-border data transfer with no valid legal transfer mechanism, or special-category or personal data processed with no signed Data Processing Agreement.
Does this replace legal review of vendor contracts?
No. It gives you a defensible, dated risk signal to decide where legal review and further diligence are actually worth spending time, not a substitute for reading the contract.
Related guides
Integrations, scanning and vendor risk
Connecting your infrastructure for automated scanning, wiring up notifications, and tracking third-party risk.
Vendor self-service due-diligence questionnaires
Send the same risk questionnaire directly to a vendor's own contact, instead of assessing them on their behalf.
DORA: digital operational resilience
What DORA requires of EU financial entities, and the real, working parts of the platform built around it: vendor criticality flags and infrastructure scanning.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial