Third-party risk
What is a vendor risk register? (SMB guide)
A vendor risk register is the living list of every company that processes your data, with risk, contracts, and owners attached. Here is how SMBs build one that survives the next security questionnaire.
Published 2026-08-24
A vendor risk register is a maintained inventory of every third party that can access your company or customer data — with enough context to decide whether that access is acceptable. It is not a contract archive and it is not a full GRC platform. It is the list you wish you had when a customer asks “who are your sub-processors?” on a Friday.
Why spreadsheets stop being a register
A column in Excel can hold names. It rarely holds current DPA status, training-on-data flags, DSAR relevance, or a risk score that updates when a contract expires. Teams then reconstruct the answer from Slack, finance exports, and whoever last filled a SIG questionnaire. That reconstruction is the operational risk.
- Procurement buys faster than legal files DPAs.
- Employees adopt AI tools before IT hears about them.
- Vendors get acquired, change regions, or quietly start training on inputs.
- Security questionnaires still expect a current, complete list.
What each entry should record
- Legal name and product (API vs consumer tier often have different terms).
- Category (HR, CRM, infrastructure, AI, payments, support).
- Data types and whether they include special-category or customer content.
- Processing region and transfer mechanism if data leaves the EEA.
- DPA / SCC status and expiry.
- Whether the vendor may train models on your inputs.
- Internal owner and next review date.
Risk scoring that an SMB will actually use
Enterprise suites model inherent vs residual risk with questionnaires you never finish. For an SMB, a useful score is a heuristic you can explain: missing DPA, trains on customer data, processes health or payment data, hosts outside an adequate jurisdiction, no owner assigned. The point is ranking, not a three-decimal “cyber rating.”
How PrivyLedger runs the register
PrivyLedger is a vendor risk register built for that SMB gap: catalog or CSV import, automatic 0–100 scores with reasons, DPA chase letters, an AI vendor view, DSAR deadlines, and one-click exports for questionnaires. It is not Vanta, Drata, or OneTrust — and it does not pretend to be.
This guide describes general practice. It is not legal advice. Your DPO or counsel should review exports before they go to a customer or regulator.
Questions
Is a vendor risk register the same as a GDPR Article 30 record?
They overlap. Article 30 is your record of processing activities. A vendor risk register is the operational slice: which processors you use, what they touch, residual risk, and contract status. Most SMBs maintain one list that feeds both.
How many vendors does an SMB typically have?
Even a 15-person company often has 20–60 SaaS processors once you count payroll, email, CRM, cloud, AI copilots, and the tools each team bought on a card. The number is why spreadsheets go stale.
Do I need enterprise GRC to run a register?
No. You need inventory, scoring, DPA status, and an export. Full GRC (policies, audit workflows, SOC 2 evidence) is a different product class and a different budget.