Skip to main content
VENDOR-RISK5 MIN READ

Sort Vendor Findings by Risk Treatment

classify findings into accept, mitigate, transfer, or avoid

Drag each card into the right bucket, then check your score. Accept with owner Mitigate before launch Transfer in contract Avoid or replace No formal incident notification timeline No MFA for vendor admins Minor policy review overdue by two weeks Vendor refuses audit rights for critical service No exit assistance clause Unpatched internet-facing admin panel Vendor will not commit to 24-hour breach notice Backup restore test is six months late No encryption for regulated exports Vendor cannot support required data residency

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us