Third-party risk used to be an enterprise concern. Large companies with hundreds of vendor relationships, dedicated risk teams, and regulatory obligations built formal vendor assessment processes. Mid-size companies generally did not.
That calculation changed in 2026. Verizon's Data Breach Investigations Report found that 48% of confirmed breaches now involve a third party, a 60% increase from the prior year. IBM puts the average cost of a third-party breach at $4.91 million. And the average mid-size company now manages 286 active vendors, most of them SaaS tools that were procured without a formal risk assessment at any point in their lifecycle.
A SaaS vendor risk assessment is the structured process for closing that gap.
What Is a SaaS Vendor Risk Assessment?
A SaaS vendor risk assessment is a structured process for evaluating every active vendor in a company's portfolio across five dimensions: security posture, financial stability, contractual terms, data handling practices, and infrastructure concentration risk. It identifies where risk has accumulated in the vendor portfolio and which vendors represent the highest exposure for the company.
A vendor risk assessment is not the same as a vendor onboarding checklist. A checklist covers a single vendor at the point of first procurement, typically assessing whether the vendor meets minimum security standards before being approved for use. A vendor risk assessment reviews the full portfolio on an ongoing basis, accounting for how vendors have changed since initial onboarding, which vendors have expanded their data access, and which tools entered the portfolio without any review at all.
For the broader context on how vendor risk connects to uncontracted spend and audit exposure, see SaaS and Cloud Vendor Risk Management: The Complete Guide for Mid-Size Companies.
Why Mid-Size Companies Are Running Vendor Risk Assessments in 2026
Three converging pressures have moved vendor risk assessment from a best practice to a practical necessity for mid-size companies.
The first is the scale of third-party breach exposure. According to Verizon's 2026 Data Breach Investigations Report, 48% of confirmed breaches involved a third party, up from 30% the prior year. IBM's 2025 Cost of a Data Breach Report found that third-party breaches cost an average of $4.91 million to remediate. At a company managing 286 vendors, the probability that at least one of those vendors experiences a security incident in any given year is no longer a theoretical question.
The second is portfolio growth. The average company now manages 286 vendors, up from 237 in 2024. AI tools, many of them expensed individually or adopted through department budgets without a formal contract, represent the fastest-growing slice of that portfolio. Vendors that entered without a review have never been assessed. They represent the densest concentration of unreviewed risk in the portfolio.
The third is regulatory pressure. DORA began enforcing third-party vendor oversight requirements for financial services firms in January 2025. PCI DSS 4.0 compliance deadlines passed in March 2025, tightening requirements around how companies assess and document third-party access to payment data. GDPR enforcement has intensified, with average fines running 18% higher year-over-year. Companies operating across multiple jurisdictions now face documented obligations around how they assess and manage the vendors processing their data.
What a SaaS Vendor Risk Assessment Covers
A SaaS vendor risk assessment evaluates each vendor across five dimensions. Together, these produce a risk profile for every vendor in the portfolio and a prioritised view of where remediation is needed.
Security posture. Does the vendor hold current certifications such as SOC 2 Type II or ISO 27001? Is there a documented incident response process? Has the vendor experienced a confirmed security incident in the last 24 months, and if so, how was it handled and disclosed?
Financial stability. What is the vendor's funding status and customer concentration? A vendor that loses a major funding round or its largest customer creates business continuity risk independent of any security considerations. SaaS tools that are discontinued without notice leave the company without recourse or data portability.
Contractual terms. Does the contract include a data processing agreement? Does it give the company the right to audit the vendor's security practices? Is there an exit clause allowing termination without penalty if the vendor fails to meet security or compliance obligations? Is there a liability cap that reflects the actual value of the data the vendor handles?
Data handling. What data does the vendor access, process, or store? Where is that data held, and in which jurisdiction? What are the vendor's data retention and deletion obligations? For AI tools in particular, acceptable use terms often restrict how company data can be used for model training, and most companies have not reviewed whether their current usage is compliant with those terms.
Infrastructure concentration risk. This is the dimension most mid-size companies have never assessed. The next section covers it in detail.
The Vendor Concentration Risk Dimension
Infrastructure concentration risk refers to the exposure created when multiple vendors in a portfolio share the same underlying cloud infrastructure. Research indicates that 92% of SaaS vendors run on AWS. At a company managing 200 or more active tools, the majority of the vendor portfolio shares a single infrastructure dependency.
A significant AWS service disruption does not affect one vendor. It affects most of the portfolio simultaneously. Unlike individual vendor risk, which can be mitigated through contractual protections and alternative sourcing, infrastructure concentration risk is a portfolio-level exposure that can only be identified by looking across the vendor register as a whole.
This dimension does not appear in a standard vendor contract review. Most vendor onboarding checklists do not ask which cloud infrastructure a vendor runs on. Identifying concentration risk requires a structured portfolio-level assessment, not individual vendor reviews conducted in isolation.
How Often Should You Run a Vendor Risk Assessment?
Mid-size companies should run a full vendor risk assessment once per year, aligned to the annual budget and renewal calendar. This establishes a complete, current risk profile across the portfolio and feeds directly into renewal negotiations and contract remediation priorities for the next 12 months.
Beyond the annual assessment, a targeted reassessment is warranted in four specific situations: before renewing a contract with a critical vendor; when a vendor reports a security incident or significant organisational change; when the scope of data access changes materially, for example when a tool is expanded from one department to the full company; and when a new regulatory requirement comes into effect that changes how company data must be handled by third parties.
Want to Know Where Your Vendor Risk Is Concentrated?
CostRoom runs a structured vendor risk assessment across your full SaaS, cloud, and AI portfolio and delivers a prioritised action plan for contract remediation and renewal.
How to Run a Vendor Risk Assessment Without a Dedicated Risk Team
Most mid-size companies do not have a GRC function, a dedicated vendor risk manager, or a risk team separate from IT. Running a vendor risk assessment in-house typically means pulling the IT Director and a legal or compliance contact into a process that takes several weeks and produces a partial picture.
The practical approach is to tier the vendor portfolio before beginning the assessment work.
Critical vendors are those with access to sensitive company data, core business systems, or regulated environments. These receive a full assessment across all five dimensions. Standard vendors are active tools with limited data access; they receive a streamlined review at the point of contract renewal. Low-risk vendors are peripheral tools with no sensitive data access; they are catalogued and monitored but do not require a full assessment unless something changes.
Within the critical tier, prioritising uncontracted vendors is the most urgent starting point. These are tools that have been running without any review at all: active, potentially processing sensitive data, and carrying no contractual protection. For more on how uncontracted spend accumulates and where to find it first, see Why Mid-Size Companies Have More Uncontracted SaaS Spend Than They Think.
What a Vendor Risk Assessment Produces
A completed vendor risk assessment produces three outputs that feed directly into operations.
A risk-tiered vendor register. Every active vendor categorised by risk tier, with the current assessment status, identified gaps across the five dimensions, and the date of the next scheduled review. This becomes the operational record for ongoing vendor management.
A contract remediation priority list. Vendors missing required contractual protections, ranked by risk tier. Vendors in the critical tier without a data processing agreement, audit rights, or an exit clause are addressed first, regardless of their cost profile. This list drives the legal and procurement work for the next 90 days.
A renewal calendar input. Vendors approaching renewal in the next 90 days where the assessment has surfaced renegotiation priorities. The risk assessment and the renewal negotiation work best when they run together. Knowing a vendor's contractual gaps before renewal creates the position to close them as a condition of renewing. For how to convert that position into a negotiated outcome, see How to Negotiate SaaS and Cloud Vendor Contracts: A Guide for Mid-Size Companies.
CostRoom's Spend Analysis and Optimisation integrates vendor risk assessment with renewal calendar management and benchmarked pricing data. For how AI tools have introduced a specific new dimension to the vendor risk picture, see Managing AI, SaaS, and Cloud Spend Together: A Guide for Mid-Size Companies.
See Where Your Vendor Risk Sits
CostRoom assesses your full vendor portfolio across security, contractual terms, data handling, and concentration risk, and delivers a prioritised plan for what to address before your next renewal cycle.
Frequently Asked Questions
What is a SaaS vendor risk assessment?
A SaaS vendor risk assessment is a structured process for evaluating every active vendor in a company's portfolio across five dimensions: security posture, financial stability, contractual terms, data handling practices, and infrastructure concentration risk. It identifies which vendors represent the highest exposure and where contract remediation or vendor exit is required.
What does a vendor risk assessment cover?
A vendor risk assessment covers five areas for each vendor: whether the vendor holds current security certifications and has a documented incident response process; the vendor's financial stability and business continuity risk; whether the contract includes a data processing agreement, right to audit, and exit clause; how the vendor handles, stores, and retains company data; and whether the vendor shares infrastructure with a disproportionate number of other vendors in the portfolio, creating concentration risk.
How often should a mid-size company run a vendor risk assessment?
A full portfolio assessment once per year, aligned to the annual budget and renewal calendar, is the right baseline cadence for most mid-size companies. A supplementary assessment is warranted before renewing a critical vendor contract, after a vendor reports a security incident, when a vendor's scope of data access changes materially, or when a new regulatory requirement affects how the company's data must be handled by third parties.
What is vendor concentration risk in SaaS?
Vendor concentration risk in SaaS refers to the exposure created when multiple vendors in a portfolio share the same underlying cloud infrastructure. Research indicates that 92% of SaaS vendors run on AWS. A company with 200 or more active vendors may find that a large proportion of its portfolio is dependent on a single cloud provider's availability, meaning a single infrastructure incident can affect most of the vendor portfolio simultaneously. This risk is only visible when the portfolio is assessed as a whole rather than vendor by vendor.



