Vendor Risk Red Flags

Difficulty: Beginner · Track: GRC

Review a vendor's security questionnaire response and spot what should stop onboarding.

Context

A vendor wants to handle your customers' data. Before onboarding them, you're reviewing their completed security questionnaire — this is third-party (vendor) risk management, one of the most common day-to-day GRC tasks.

Task

  1. Read the vendor's questionnaire response below (static, safe example).
  2. Identify the claim made without supporting proof, and the weak commitment on breach notification.
  3. Know the regulatory benchmark that commitment falls short of.

Vendor Questionnaire Response

Answers are directly copy-pasteable from this block.

Note: Educational example — vendor name and details are fictional.

Capture the Flags

Copy each answer directly from the questionnaire above. Case-insensitive.

0/3 flags captured

Flag 1 — Which certification did the vendor claim without proof?

Question: Copy the exact certification name listed with no certificate number.

Flag 2 — How many days does the vendor commit to for breach notification?

Question: Copy the exact number from their commitment.

Flag 3 — What's the commonly required breach notification window under GDPR (in hours)?

Question: This isn't in the questionnaire — it's the regulatory benchmark the vendor's 30-day commitment should be compared against.

Back to Challenges