Free public control tool

Third-party criticality questionnaire

Classify supplier dependency so due diligence and ongoing oversight match operational exposure.

Use this questionnaire before tiering a vendor or setting review expectations. It does not score a supplier automatically or determine contractual obligations.

Template / checklist for operators. Not legal advice. Not a certification.

Use when

A vendor is new, materially changing, renewing, or supporting a business-critical service.

Output

A documented criticality rationale, review owner, and proportionate follow-up plan.

Operator checklist

Work through the prompts and retain the evidence references.

Section 1

Service dependency

Understand what stops or degrades if the supplier fails.

  1. 1

    What service, product, or business process does the third party support?

    Evidence to retain: Service description and internal service owner

  2. 2

    Could a disruption halt, materially impair, or create unsafe conditions in operations?

    Evidence to retain: Business impact analysis or continuity plan

  3. 3

    Is there a feasible substitute, workaround, or exit path?

    Evidence to retain: Exit plan, alternate supplier, or recovery procedure

Section 2

Data and access

Identify the data, connectivity, and privileges involved.

  1. 1

    What data categories does the third party receive, process, store, or transmit?

    Evidence to retain: Data-flow record and classification

  2. 2

    What system access, integrations, or privileged roles are required?

    Evidence to retain: Architecture diagram and access request

  3. 3

    What locations, subprocessors, or concentration dependencies are relevant?

    Evidence to retain: Supplier disclosures and dependency map

Section 3

Oversight decision

Translate facts into a reviewable tiering decision.

  1. 1

    Assign a proposed criticality level and explain the rationale.

    Evidence to retain: Tiering criteria and completed rationale

  2. 2

    Set due diligence, contract, monitoring, and reassessment expectations for that level.

    Evidence to retain: Third-party risk procedure and review plan

  3. 3

    Record the approving owner and next reassessment trigger.

    Evidence to retain: Approval record and renewal/change trigger

Want a second set of eyes on the workflow?

Bring one completed worksheet or checklist. Ironframe can help map the handoffs, evidence, ownership, and remediation steps into a workable operating process.