Governance, risk and compliance

SmartSuite for the Vendor Risk Analyst

The Vendor Risk Analyst executes vendor assessments: sending questionnaires, reviewing responses, validating documentation, scoring risk and keeping vendor profiles accurate. They produce the trend reporting that shows vendor risk by category, geography and criticality tier.

What you own

  • Send questionnaires, review responses and document findings
  • Validate vendor documentation and certifications
  • Score vendor risk using the programme methodology
  • Maintain accurate vendor profiles and tiering data
  • Track remediation requests with vendors
  • Analyse vendor risk trends by category, geography and tier

Where the role sits

Each name opens that role's page.

Reports to

Third-Party Risk Manager

Third-Party Risk Manager

See the role

Direct reports

Works closely with

Procurement Manager

Procurement Manager

See the role
Compliance Analyst

Compliance Analyst

See the role
Information Security Officer

Information Security Officer

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

Touches

contributes or approves

third-party, issues-actions, reporting

Depends on

consumes its output

compliance

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use the Third Party Risk Management suite

Assessment coordination

Sends questionnaires, reviews responses, and documents findings.

Trend reporting

Analyzes vendor risk by category, geography, business unit, or criticality tier.

Data integrity

Maintains accurate vendor profiles and ensures all documentation is current.

Suites that serve this role

How SmartSuite supports this role

Third-party risk. Accelerates assessment cycles by centralising vendor data, documentation and risk scoring, with questionnaires sent and reviewed in workflow.

Issues and actions. Tracks vendor remediation requests and documentation gaps to closure.

Reporting. Analyses vendor risk by category, geography, business unit or criticality tier with trend dashboards.

Industry reference

The Shared Assessments SIG questionnaire and NIST SP 800-161 define the assessment content the analyst works with: security, privacy, resilience and financial-viability questions scored against inherent risk tiers. Evidence such as SOC 2 reports and ISO 27001 certificates is validated rather than taken on trust.

Regulators test the file. Bank examiners apply the 2023 Interagency Guidance and, in the EU, DORA's register of information; healthcare organisations must hold business associate agreements under HIPAA; public sector buyers verify FedRAMP authorisations; technology companies document vendor reviews for their own SOC 2 and NIS2 obligations.

In their words

Related roles

Third-Party Risk Manager

Third-Party Risk Manager

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.