A vendor risk assessment checklist works when it collects evidence, not just answers. In practice that means: classify each supplier by the data and operations it touches, run proportionate due diligence, request the artefacts behind every questionnaire claim (SOC 2 report, penetration test summary, ISO 27001 certificate, DR test result), and re-check on a cadence tied to criticality. Australian regulators — APRA under CPS 230 and CPS 234, and the ASD for baseline hygiene — increasingly expect this to be continuous and demonstrable, not an annual spreadsheet exercise. This guide gives you the checklist and the evidence bridge.
By Aneis Samaan, founder of CyberSentien · Last updated July 2026
The fastest way to waste a security team is to send every supplier the same 300-question questionnaire. Effective third-party risk management framework design starts with classification: how much of your sensitive data does this vendor hold, and could an outage or breach at that vendor stop a critical operation of yours? A tier drives depth, and depth drives what evidence you demand. Tiering is also the connective tissue to APRA’s regime — a “critical” vendor in your language often maps to a “material service provider” in CPS 230 language.
Holds regulated or customer data, or underpins a critical operation. Full due diligence, independent assurance evidence, contractual controls, notification clocks, and continuous monitoring.
Meaningful data access or business dependency but recoverable. Targeted questionnaire plus core evidence (SOC 2 / ISO scope, MFA, backup testing).
Minimal data, easily substituted. Lightweight attestation and periodic review. Don’t drown these in paperwork.
Our third-party risk management framework follows this shape: tier first, then match the evidence bar to the tier so the effort lands where the exposure is.
Use this as a working vendor due diligence checklist for a Tier 1 or Tier 2 supplier. Each item names the artefact that proves the claim — because a “yes” on a form is a statement of intent, and the artefact is the fact.
The principle we hold to across the board: a control with no supporting artefact is marked “manual assessment required”, never a green tick. A checklist that turns unproven claims into false assurance is worse than no checklist.
The Standardized Information Gathering (SIG) questionnaire from Shared Assessments, and its lighter SIG Lite variant, are useful for one thing: giving both sides a common vocabulary so you’re not inventing questions from scratch. A vendor security questionnaire (SIG or otherwise) is a starting point, not a finding. The failure mode is treating the returned spreadsheet as the assessment.
| Dimension | Questionnaire-only | Evidence-led |
|---|---|---|
| What you get | Self-reported yes/no answers | Answers plus the artefact that proves each one |
| Point in time | The day it was filled in, then stale | Re-checked on a cadence tied to tier |
| Audit defensibility | Weak — assertions only | Strong — traceable to source documents |
| False-green risk | High — a tick can hide a gap | Low — no artefact means “not yet assessed” |
Keep the questionnaire — then insist the material claims are backed. A SOC 2 report attached to a claim about logging is worth more than fifty unbacked answers.
If any of your customers is an APRA-regulated bank, insurer, or superannuation fund, your vendor programme collides with theirs — and you may be on the other side of it. CPS 230 commenced 1 July 2025, with full effect and the material-service-provider contract transition due by 1 July 2026. It replaced the old CPS 231 (outsourcing) and CPS 232 (business continuity), consolidating operational risk into one standard. Regulated entities must identify their critical operations, set board-approved tolerance levels, maintain a register of material service providers, and meet notification clocks — notifying APRA as soon as possible and within 72 hours of a material operational-risk incident.
Are you a bank’s material service provider? Broadly, if a regulated entity relies on your service to run a critical operation — and failure of your service would breach their tolerance — you are likely material to them. That has two consequences. First, they will push contractual and evidence obligations down to you: right-to-audit, incident notification aligned to their clocks, and resilience testing. Second, running your own vendor programme to the same evidentiary standard makes you a far easier supplier to onboard. CPS 234, the information-security standard, adds the security spine: asset classification, control implementation and testing, board accountability, notifying APRA within 72 hours of a material incident and within 10 business days of a material control weakness. See our CPS 230 framework page and the CPS 230 templates for the register and tolerance structures. The primary source is APRA at apra.gov.au.
For vendors that don’t warrant a full assurance report, the ASD Essential Eight (Maturity Levels ML1–ML3) is a sensible baseline to ask about — application control, patching, macro settings, MFA, backups and the rest. Note that ASD guidance is revised from time to time; treat any changes as proposed until finalised, and track updates via cyber.gov.au. Smaller suppliers may instead sit on a tiered small-business cyber-certification standard whose higher tiers require independent certification — useful as a shared reference point for lighter vendors. Our small-business solution covers that lane.
Monitoring cadence should follow tier: Tier 1 continuously with quarterly evidence refresh, Tier 2 annually, Tier 3 on renewal. A programme that assesses once and forgets is a programme that discovers problems in the incident report.
CyberSentien’s role here is deliberately narrow and honest: we perform readiness and evidence assessment. We ingest the artefacts — SOC 2 reports, certificates, test results, policies — map them to your framework controls, and show exactly which claims are backed and which read “manual assessment required”. We do not certify vendors and we do not issue any mark; certification is issued only by accredited bodies, and CPS-style tripartite assurance is performed by an independent assurance practitioner, not by us. What we give you is the evidence-backed picture underneath all of it.
Vendor criticality, data access, security controls (MFA, backups, patching), sub-contractors, contract clauses, and evidence for each. CyberSentien assesses the evidence rather than accepting the questionnaire answer.
The Standardised Information Gathering (SIG Lite/Core) questionnaire collects a vendor's self-reported controls. It is a starting point, but self-attestation is not verified evidence — the gap CyberSentien closes.
If your service supports a bank's critical operations such that your failure could disrupt them, you are likely a material service provider under CPS 230 and must meet the flow-down contract and evidence obligations.
Identify and tier vendors, assess each against your obligations, evidence controls, monitor continuously, and maintain a register. CyberSentien automates the assessment and evidence layer.