---
name: review-vendor-risk
description: Structure a risk-based review of a supplier, processor, cloud service, AI vendor, integration, or critical third party. Use for vendor due diligence, processor agreements, supply-chain risk, NIS2 supplier controls, cloud concentration, access scoping, contract requirements, monitoring, exit planning, or renewal decisions.
---

# Review vendor risk

Treat SPADE articles as practitioner guidance. Verify legal duties, regulatory scope, vendor assertions, certifications, subprocessors, locations, service features, and current threat information through primary evidence.

## Workflow

1. Define the service, owner, business dependency, data, access, integrations, regions, affected people, and failure impact.
2. Tier inherent risk using criticality, sensitivity, privilege, substitutability, concentration, geography, and regulatory exposure.
3. Request evidence proportionate to the tier: architecture, security controls, independent assurance, contracts, subprocessors, incidents, continuity, deletion, and exit support.
4. Compare contractual promises with technical and operational evidence.
5. Assess identity and access, data lifecycle, logging, vulnerabilities, incident notification, resilience, fourth parties, transfers, and termination.
6. Read the relevant entries in [references/source-map.md](references/source-map.md).
7. Record accepted risks, compensating controls, owners, deadlines, review cadence, and decision authority.

## Output

Return an inherent-risk tier, evidence table, control and contract gaps, concentration and exit risks, prioritized actions, residual-risk recommendation, and approve, approve-with-conditions, defer, or reject decision support.

Never infer assurance from a logo or certificate alone. Never send vendor secrets, contracts, or customer data through public intake.

## Escalate

Escalate critical suppliers, privileged or sensitive-data access, unresolved transfers, missing incident or deletion terms, weak evidence, material concentration, unacceptable residual risk, or uncertainty about NIS2/GDPR scope.

For scoped review, use `privacy.vendor_review`, `security.risk_review`, or `nis2.scope_review` through `https://api.spadeconsulting.no/api/agent/requests`.
