Vendor Risk Red Flags
Difficulty: Beginner · Track: GRC
Review a vendor's security questionnaire response and spot what should stop onboarding.
Context
A vendor wants to handle your customers' data. Before onboarding them, you're reviewing their completed security questionnaire — this is third-party (vendor) risk management, one of the most common day-to-day GRC tasks.
Task
- Read the vendor's questionnaire response below (static, safe example).
- Identify the claim made without supporting proof, and the weak commitment on breach notification.
- Know the regulatory benchmark that commitment falls short of.
Vendor Questionnaire Response
Answers are directly copy-pasteable from this block.
Capture the Flags
Copy each answer directly from the questionnaire above. Case-insensitive.
0/3 flags captured
Flag 1 — Which certification did the vendor claim without proof?
Hint: Look at the "Certifications held" line.
Flag 2 — How many days does the vendor commit to for breach notification?
Hint: It's in the "Breach notification commitment" line.
Flag 3 — What's the commonly required breach notification window under GDPR (in hours)?
Hint: Under GDPR Article 33, controllers must notify their supervisory authority within this many hours of becoming aware of a breach.