Vendor Governance Classification Tool

Vendor Name *
1. Does the vendor provide a service that your organisation can't operate without? *
2. Does the vendor have access to your organisation's internal networks (i.e., on-premises)? *
3. Does the vendor have access to your organisations cloud services? *
4. Does the vendor have remote access to your organisations systems? *
5. Does the vendor have privileged access to your the organisation? *
6. Does the vendor have direct or indirect access to restricted and/or confidential information? *
7. Does the vendor have access to and/or process financial information? *
8. Data/Information Types
Vendor Name:
0.00
Vendor Tiering Structure
Tier 1Critical or high risk
Tier 2Non-critical and moderate risk
Tier 3Non-critical and low risk
Your Vendor Tier

Tier 1 - Critical or high risk

Tier 2 - Non-critical and moderate risk

Tier 3 - Non-critical and low risk

Your Answers

1. Does the vendor provide a service that your organisation can't operate without?
Answer: Yes
Risk Rating: Low

1. Does the vendor provide a service that your organisation can't operate without?
Answer: No
Risk Rating: Low

2. Does the vendor have access to your organisation's internal networks (i.e., on-premises)?
Answer: Yes
Risk Rating: Low

2. Does the vendor have access to your organisation's internal networks (i.e., on-premises)?
Answer: No
Risk Rating: Low

3. Does the vendor have access to your organisation's cloud services?
Answer: Yes
Risk Rating: Medium

3. Does the vendor have access to your organisation's cloud services?
Answer: No
Risk Rating: Low

4. Does the vendor have remote access to your organisation's systems?
Answer: Yes
Risk Rating: Medium

4. Does the vendor have remote access to your organisation's systems?
Answer: No
Risk Rating: Low

5. Does the vendor have privileged access to your organisation?
Answer: Yes
Risk Rating: High

5. Does the vendor have privileged access to your organisation?
Answer: No
Risk Rating: Low

6. Does the vendor direct or indirect access to restricted and/or confidential information?
Answer: Yes
Risk Rating: High

6. Does the vendor direct or indirect access to restricted and/or confidential information?
Answer: No
Risk Rating: Low

7. Does the vendor have access to and/or process financial information?
Answer: Yes
Risk Rating: High

7. Does the vendor have access to and/or process financial information?
Answer: No
Risk Rating: Low

8. Data/Information Types

  • Critical Business Data
  • Sensitive Customer Data
  • Personally Identifiable Information (PII)
  • Personal Health Information (PHI)
  • Payment Card Information (i.e. PCI DSS)
  • Public Sector Information (i.e. VPDSS)
  • Other Sensitive Data
Copy & paste the below URL with your saved answers for your records:
0.00