Templates / Vendor risk register template
Vendor risk register template
A vendor (third-party) risk register tracks the risk your suppliers carry into your organisation — a compromised vendor, a shared-service outage, sensitive data sent to an external model. The worked example below is free to download or open live, and Urna pairs it with a vendor register for supplier-by-supplier tracking.
No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.
Worked example: vendor risk register template
| Risk | Category | Likelihood | Impact | Rating | Suggested remediation |
|---|---|---|---|---|---|
| Supplier or third-party compromiseA vulnerability, breach or malicious update at a vendor, hosting provider or software dependency reaches your systems or data through the trusted connection. | security | medium | high | Keep an inventory of suppliers and the systems and data each can reach, and set security expectations in the contract before onboarding. | |
| Third-party AI and vendor-model riskA procured AI product or model API is outside your control: the vendor may train on the data you send, change or retire the model without notice, or lock you in with no way to export your data or switch. | strategic | medium | high | Before buying, confirm in writing whether your inputs are used for training, where data is processed, and how the vendor notifies you of model changes. | |
| Sensitive data sent to an external AI modelPrompts, documents or records sent to a hosted model for inference leave your security boundary — retained in logs, exposed to the provider, or transferred across borders — even when the AI use is sanctioned. | legal | high | medium | Classify what may and may not be sent to an external model, and minimise or redact personal and confidential data in prompts. | |
| Dependency on an AI service for availability or costA business process comes to rely on an external AI service, so a provider outage, rate-limit, deprecation or sudden price rise degrades or stops the process. | operational | medium | medium | Know which processes depend on the AI service and design a fallback — an alternative provider, a cached response, or a manual path — for when it is unavailable. | |
| Cloud misconfiguration or exposed storageA storage bucket, database or admin interface is left publicly reachable or without authentication through a configuration mistake, exposing data or a way in. | security | high | high | Build systems from a hardened, documented baseline that turns off public access and default credentials, and block deployments that drift from it. |
Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.
Questions
What is a vendor risk register?
A record of the risks introduced by third parties — suppliers, processors, model providers — with each rated and mapped to the controls (contract terms, testing, incident notification, DPAs) that reduce it. NIS2 and DORA both push this obligation down the supply chain.
How is vendor risk different from a supplier list?
A supplier list records who you use; a vendor risk register records what could go wrong through them and what you're doing about it. Urna keeps both — a vendor register and the risk register they feed.
Is the template free?
Yes — CSV download with no sign-up, or open it live in Urna. Free, no card.
Build your own in Urna — free
Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.