Vendor assessment (third-party risk management)
Vendor assessment is the structured evaluation of a third-party supplier before engagement and periodically thereafter, to verify that it provides sufficient guarantees of compliance, security and quality for the services it delivers. Under Art. 28(1) GDPR a controller may only use processors providing sufficient guarantees to implement appropriate technical and organisational measures; under ICH GCP section 5.2 and Art. 71 CTR the sponsor remains responsible for tasks delegated to CROs and vendors and must oversee them; under Art. 21(2)(d) of the NIS2 Directive supply chain security is a mandatory risk management measure; and ISO 13485 and ISO 27001 both require supplier evaluation and control.
A proportionate assessment programme tiers vendors by the sensitivity and volume of data they handle and the criticality of the service (an EDC or safety database vendor is high tier; a translation agency handling anonymised documents is low tier). For each tier it defines the evidence to collect: a completed questionnaire, certifications (ISO 27001, SOC 2 Type II, HDS, ISO 13485, ISO 42001 for AI vendors), penetration test summaries, breach history, sub-processor lists, hosting locations and transfer mechanisms, business continuity arrangements, and for regulated systems the validation package. Findings feed the risk register, the DPIA (where iliomad scores each actor's security measures on a three-point scale) and the negotiation of the data processing agreement and, where needed, SCCs with a transfer impact assessment.
Assessment is not a one-off. Ongoing oversight includes review of audit reports and certification renewals, monitoring of sub-processor changes and incidents, periodic re-assessment (annually for high-tier vendors), audit rights exercised proportionately, and a clear exit plan covering return and deletion of data. Vendor files are among the first documents requested in GCP inspections, supervisory authority investigations and investor due diligence. iliomad runs vendor assessments and maintains vendor registers for sponsors and HealthTech companies; see vendor assessment services and the third-party risk management domain page.
