Third-party risk management

Know which of your vendors could cause your next breach

Most small-business breaches arrive through a supplier. BabsTech gives you a structured third-party vendor risk assessment — scored, tiered, and delivered as an executive report with a remediation plan you can act on the same week.

How the vendor assessment works

Answer 30 vendor questions

Contracts and data scope, assurance evidence, vendor-side controls, resilience, privacy and sub-processors, AI use and offboarding.

Get a tiered risk score

Each vendor is scored 0-100 and placed into a risk tier with a recommended re-assessment cadence.

Track them in one register

All assessed vendors sit side by side so you can see concentration risk and who needs review next.

Act on the remediation plan

A prioritised plan, risk register and policy recommendations you can hand to the vendor or your team.

Vendor risk tiers

Every assessed vendor lands in one of four tiers, which sets how often you should re-review them.

Tier 1 — Critical risk

Material gaps in assurance or controls. Escalate before renewal.

Re-assess quarterly

Tier 2 — High risk

Several controls unproven. Request evidence and set remediation dates.

Re-assess every 6 months

Tier 3 — Moderate risk

Reasonable posture with specific gaps to close.

Re-assess annually

Tier 4 — Low risk

Strong assurance and contractual protection in place.

Re-assess annually or on material change

What we look at

  • Signed contracts, DPAs and BAAs
  • SOC 2 Type II / ISO 27001 evidence
  • MFA and encryption at the vendor
  • Sub-processor (fourth-party) exposure
  • Data residency and cross-border transfers
  • Breach notification timelines
  • Backup, export and exit strategy
  • AI use and model-training on your data
  • Ownership, monitoring and offboarding

Assess your first vendor today

Self-assessment or guided review with a veteran-owned GRC practitioner.