> For the complete documentation index, see [llms.txt](https://wiki.songer.pro/interviewing/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://wiki.songer.pro/interviewing/security-domains-and-technical-aptitude/third-party-management/vendor-risk/questions/how-do-you-determine-the-level-of-risk-associated-with-a-vendor.md).

# How do you determine the level of risk associated with a vendor?

1. Review the vendor’s track record: Check the vendor’s past performance and previous customer reviews to get an idea of their reliability and quality of service.
2. Analyze the vendor’s security: Investigate the vendor’s security measures and processes to understand the level of protection they provide for your data.
3. Evaluate their terms and conditions: Carefully read the contract and any other terms and conditions to be sure that you understand the level of risk you’re taking.
4. Assess the impact of a breach: Consider what would happen if the vendor were to suffer a data breach or other security incident and how that would affect your business.
5. Ask questions: Make sure to ask the vendor specific questions about their security measures and risk management practices.
