Supplier Risk – Interview Cheat Sheet

Compact view of key concepts + 2–3 use cases each. Designed for quick recall during interviews.

1) Inventory Tools Used to Manage Vendors
Key Points Details
SupplierNinja Primary supplier inventory; used for filtering reassessments, lifecycle status, and risk tier.
OneTrust Holds vendor records, DRI details, contact info, and assessment status fields.
ServiceNow Sometimes used for onboarding workflows, tickets, and integration with other processes.
Airtable Used to track onsite coverage and avoid duplicate remote assessments.
Use Cases
UC1: Filter SupplierNinja for “High risk + reassessment due” to build weekly reassessment list.
UC2: Update DRI email in OneTrust after ownership validation with GSM.
UC3: Cross-check Airtable to confirm a supplier already had onsite assessment this year.
2) Key Attributes Captured for Vendors
Attribute Example
Supplier Name “CloudSync Solutions” – cloud data processing provider.
Service & Risk Tier Cloud hosting – High risk due to sensitive data processing.
Data Sensitivity Processes PII and financial data; requires annual reassessment.
DRI & Contacts DRI: GSM owner; includes email, region, and business unit.
Use Cases
UC1: Use risk tier + data sensitivity to prioritize which vendors are reassessed first.
UC2: Correct DRI and contact details to prevent emails going to inactive owners.
UC3: Use assessment history to confirm last review date before scheduling reassessment.
3) Vendor Management Lifecycle (Very Short)
Stage Summary
Onboarding Collect vendor details, assign DRI, set risk tier, and create vendor record.
Assessment Security assessment by assessors (new or periodic) based on risk and data sensitivity.
Monitoring Track issues, escalations, and changes in services or risk profile.
Reassessment Periodic review to ensure controls remain effective and aligned with requirements.
Offboarding Terminate relationship, remove access, and update inventory to inactive.
Use Cases
UC1: Identify vendors in “Active + Reassessment Due” stage and trigger the workflow.
UC2: Move a vendor to “Offboarded” after contract termination and confirm access removal.
UC3: Flag a vendor for early reassessment after a major incident or scope change.
4) New vs Re‑Assessment of Vendors
Type Definition
New Assessment First-time security review before or during onboarding of a new supplier.
Reassessment Periodic review (e.g., annually) to confirm controls remain effective and compliant.
Trigger Risk tier, data sensitivity, regulatory requirements, or internal policy.
Use Cases
UC1: New SaaS vendor onboarded → trigger new assessment before production use.
UC2: High-risk vendor hits 12-month mark → schedule annual reassessment.
UC3: Vendor scope expands to handle PII → convert to higher risk and initiate reassessment.
5) DRI (Direct Responsible Individual)
Aspect Details
Definition Internal person who owns the relationship with the vendor (often GSM or business owner).
Purpose Single point of accountability for decisions, approvals, and communication.
Location Stored in vendor record (OneTrust / SupplierNinja) with name, email, and role.
Use Cases
UC1: Confirm DRI is still correct before sending assessment kick‑off email.
UC2: Use DRI as escalation point when vendor is unresponsive.
UC3: Ask DRI to validate whether vendor is still in use before reassessment.
6) DRI Roles and Responsibilities
Responsibility Example
Approve Assessments DRI confirms “Yes, this vendor is active and should be reassessed this year.”
Provide Context Explains how the vendor is used, what data they handle, and business criticality.
Support Communication Responds to coordinator emails, helps chase vendor or internal stakeholders if needed.
Escalate Issues Raises concerns if vendor is non-compliant or unresponsive to assessment requests.
Use Cases
UC1: DRI approves reassessment and confirms correct vendor contact for self‑assessment.
UC2: DRI escalates internally when vendor delays evidence submission.
UC3: DRI clarifies that a vendor is no longer used → you update inventory and skip reassessment.
7) Managing When Vendors & DRIs Are Correct
Step Action
Confirm Accuracy Verify vendor status, DRI, and contact details in SupplierNinja / OneTrust.
Initiate Assessment Send kick‑off email, get acknowledgement, and create Wrike task for assessors.
Track Progress Monitor responses, follow-ups, and escalations until assessment is underway.
Use Cases
UC1: All data validated → you can batch-create Wrike tasks for multiple vendors.
UC2: Use accurate inventory to generate a clean weekly reassessment list.
UC3: Quickly answer leadership questions about “who owns which vendor” using DRI data.
8) Escalation Process
Level Action
Follow‑ups 1st, 2nd, 3rd reminders to DRI or contact with clear timelines and asks.
1st Escalation Escalate to DRI’s manager or GSM lead with evidence of non‑response.
2nd Escalation Escalate to higher leadership or program owner for critical vendors.
Documentation Log all follow‑ups and escalations for audit and reporting.
Use Cases
UC1: After 3 unanswered emails, escalate to GSM manager with a summary of attempts.
UC2: For high-risk vendor, escalate faster if reassessment deadline is at risk.
UC3: Use escalation history in weekly reports to show bottlenecks in the process.
9) Reporting to Higher-Level Management
Metric Example
Email Volume Total outreach, follow-ups, and escalations sent in the week.
Response Rates Percentage of DRIs/vendors who responded vs. non‑responses.
Assessment Status Counts of “Not started / In progress / Completed” for reassessments.
Coverage How many in-scope vendors have current-year assessments (onsite + remote).
Use Cases
UC1: Present weekly dashboard showing where reassessments are stuck (e.g., DRI non‑response).
UC2: Highlight high-risk vendors still pending reassessment to drive leadership focus.
UC3: Use trends (e.g., improved response rate) to show process maturity over time.
10) Types of Vendors (with Examples)
Type Examples
Cloud & SaaS AWS, Azure, GCP, Salesforce, Workday, Okta.
IT & Security Services Managed service providers, SOC-as-a-service, MDR, penetration testing firms.
Payment & Data Processors Stripe, PayPal, ETL platforms, analytics/ML platforms.
Business Services HR vendors (background checks), marketing platforms, consulting firms.
Use Cases
UC1: Classify vendors by type to apply different assessment depth (e.g., deeper for cloud & payment).
UC2: Use vendor type to explain risk context to leadership (e.g., “payment processor with PCI impact”).
UC3: Filter inventory by vendor type to prepare focused reassessment waves (e.g., all SaaS this quarter).