// Free quiz

Vendor Risk readiness quiz

Your suppliers, SaaS apps and contractors can be your weakest link, and most breaches now arrive through a trusted third party. Answer twelve high-level questions about how you inventory, vet, contract with and monitor your vendors, and get a readiness score with the gaps to close.

The 12 checks in this quiz

Answer each one No, In progress, or Yes. Anything not fully in place comes with a concrete next step.

Inventory & ownership

  1. Do you keep an up-to-date list of the vendors and SaaS apps that touch your data or systems?

    Build and maintain a vendor inventory, including the SaaS tools staff signed up for, so you know who has access to what.

  2. Is someone clearly responsible for approving new vendors and owning the relationship?

    Name an owner for vendor decisions so new suppliers are vetted, not just signed up ad hoc.

Due diligence

  1. Do you assess a vendor security posture before you hand over data or access?

    Run basic security due diligence before onboarding: ask for their controls, certifications and track record.

  2. For vendors that hold sensitive data, do you review their security reports (such as SOC 2 or ISO 27001)?

    Ask higher-risk vendors for a SOC 2 or ISO 27001 report and actually read it, focusing on exceptions and scope. See the SOC 2 quiz.

  3. Do you rank vendors by risk so you spend the most effort on the ones that matter?

    Tier vendors by the data and access they have, and scale your diligence to the risk instead of treating every vendor the same.

Contracts & data

  1. Do your vendor contracts cover security, data handling and breach notification?

    Put security expectations, data-use limits and breach-notification timelines in the contract or a data processing agreement, not just a handshake.

  2. Do you know what data each vendor can access and where it is stored, including cross-border?

    Map what data each vendor holds and where; cross-border storage can trigger privacy obligations. See the privacy quiz.

  3. Do vendors get only the access they need, with no shared or leftover admin logins?

    Grant least-privilege access to vendors and avoid shared logins, so you can track and revoke it cleanly.

Ongoing monitoring

  1. Do you re-check key vendors periodically rather than only at signup?

    Review your important vendors on a schedule (annually or at renewal), not only when you first onboard them.

  2. Would you find out if a vendor had a breach that affected your data?

    Make sure contracts require breach notification and that you watch for vendor incidents, so you are not the last to know.

Offboarding

  1. When you stop using a vendor, do you revoke their access and recover or delete your data?

    Run a vendor offboarding step: revoke access, pull back or confirm deletion of your data, and close the account.

  2. For your most critical suppliers, do you consider the vendors they rely on (fourth-party risk)?

    For critical suppliers, ask who they depend on; a failure deep in the chain can still take you down.

About this quiz. About this quiz. This is a readiness indicator, NOT an audit or a substitute for a real third-party risk program. It reflects the practical building blocks of frameworks like SOC 2 vendor management and NIST 800-161 supply-chain risk. Everything runs in your browser and is not saved.
// What this means for your business

A vendor breach is still your breach

A breach at a supplier or SaaS app is still your problem: your data, your customers, your reputation. We help Canadian businesses build a right-sized third-party risk program, who to vet, what to ask for, and how to watch the vendors that matter, so a weak link in your supply chain does not become your incident.