Third-party risk management
Know which of your vendors could cause your next breach
Most small-business breaches arrive through a supplier. BabsTech gives you a structured third-party vendor risk assessment — scored, tiered, and delivered as an executive report with a remediation plan you can act on the same week.
How the vendor assessment works
Answer 30 vendor questions
Contracts and data scope, assurance evidence, vendor-side controls, resilience, privacy and sub-processors, AI use and offboarding.
Get a tiered risk score
Each vendor is scored 0-100 and placed into a risk tier with a recommended re-assessment cadence.
Track them in one register
All assessed vendors sit side by side so you can see concentration risk and who needs review next.
Act on the remediation plan
A prioritised plan, risk register and policy recommendations you can hand to the vendor or your team.
Vendor risk tiers
Every assessed vendor lands in one of four tiers, which sets how often you should re-review them.
Material gaps in assurance or controls. Escalate before renewal.
Re-assess quarterly
Several controls unproven. Request evidence and set remediation dates.
Re-assess every 6 months
Reasonable posture with specific gaps to close.
Re-assess annually
Strong assurance and contractual protection in place.
Re-assess annually or on material change
What we look at
- Signed contracts, DPAs and BAAs
- SOC 2 Type II / ISO 27001 evidence
- MFA and encryption at the vendor
- Sub-processor (fourth-party) exposure
- Data residency and cross-border transfers
- Breach notification timelines
- Backup, export and exit strategy
- AI use and model-training on your data
- Ownership, monitoring and offboarding
Assess your first vendor today
Self-assessment or guided review with a veteran-owned GRC practitioner.