Skip to main content
All resources
Template
6 min readUpdated 22 May 2026

Third-Party Vendor Risk Assessment Template

A tiered supplier due-diligence questionnaire you can send tomorrow, with data-sovereignty questions specific to Australian privacy obligations.

Tier before you question

Not every supplier needs a 200-question assessment. Tier by data sensitivity and operational dependency: Tier 1 suppliers hold personal or financial data or can halt operations; Tier 3 suppliers hold nothing and touch nothing.

Assess Tier 1 annually with evidence, Tier 2 on a self-attested questionnaire, Tier 3 at onboarding only.

Australian-specific questions people forget

Where is data stored and backed up, and does any support team access it from offshore? Cross-border disclosure triggers Australian Privacy Principle 8 accountability.

Will the supplier notify you within a contractual timeframe short enough for you to meet your own NDB assessment obligation?

The checklist

Governance

  • Named security contact and escalation path provided
  • Current ISO 27001, SOC 2 Type II or IRAP assessment evidence supplied
  • Sub-processor list disclosed and change-notification committed

Data handling

  • Primary and backup data hosting locations documented
  • Offshore support access disclosed and access controls described
  • Encryption in transit and at rest confirmed
  • Data return and deletion process on exit documented

Security controls

  • MFA enforced for staff and for customer administrative access
  • Vulnerability management and penetration test cadence stated
  • Logging and monitoring coverage described

Contractual

  • Breach notification within 24–48 hours written into the contract
  • Right to audit or receive annual assurance reporting
  • Cyber liability insurance evidence current
  • Availability commitments and credits defined

Need this done, not just documented?

Fast Emu delivers the controls in this checklist as a managed service, monitored 24/7 from Australia.