Vendor risk
Your security is only as good as the vendors you rely on. Keel keeps a living inventory of the third parties that touch your data or systems, with a risk rating and a review cadence for each, so third-party risk is managed rather than remembered.
Build your vendor inventory
Section titled “Build your vendor inventory”In Vendors, add each third party with what it does, the data it can access, and how critical it is to your operations. Tiering vendors (for example critical, important, or low) lets you focus your effort where a failure would actually hurt.
Inherent and residual risk
Section titled “Inherent and residual risk”As with your risk register, Keel captures two views of vendor risk:
- Inherent risk: how much risk the vendor represents based on the data and access it has.
- Residual risk: how much remains once you account for the vendor’s own controls and the safeguards you have in place.
When a vendor’s assessment reflects strong controls, its residual risk drops accordingly, so your inventory shows where the real exposure is rather than treating every vendor the same.
Assess with questionnaires
Section titled “Assess with questionnaires”Send or record a security assessment for each vendor. Keel’s questionnaire automation can help you work through assessments faster, and the results feed the vendor’s risk rating so the score is grounded in evidence, not a guess.
Review on a cadence
Section titled “Review on a cadence”Vendor risk is not a one-time check. Keel tracks a review date for each vendor and surfaces which reviews are due or overdue, so re-assessments happen on schedule and your inventory stays current between audits.
Next steps
Section titled “Next steps”- Evidence: store assessment results and supporting documents.
- Risk register: roll vendor exposure into your overall risk picture.
- Trust Center: show prospects how you manage third-party risk.