SaaS Vendor Risk Assessment Form
Vendor Name
Vendor Contact Person
Contact Email
Service Description
Type of Data Processed/Stored
Data Storage Location(s)
Access Level Required
Read-Only
Read/Write
Admin
Vendor Certifications (e.g. SOC 2, ISO 27001)
Incident/Breach Notification Procedure
Third-Party Subprocessors Used
Data Retention & Deletion After Termination
Additional Comments