> For the complete documentation index, see [llms.txt](https://wiki.songer.pro/interviewing/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://wiki.songer.pro/interviewing/security-domains-and-technical-aptitude/third-party-management/vendor-risk/questions/how-do-you-ensure-that-all-vendors-comply-with-your-risk-assessment-policy.md).

# How do you ensure that all vendors comply with your risk assessment policy?

The best way to ensure that all vendors comply with a risk assessment policy is to have a comprehensive vendor management program in place. This program should include a process for conducting due diligence on vendors, a process for assessing vendor risk, a process to review and monitor vendor performance, and a process for enforcing risk management policies. Additionally, it is important to have clear expectations and a communication plan in place to ensure that vendors understand the risk assessment policy and that they are aware of any changes that may be made. Finally, having a strong process for tracking and documenting all vendor activities will help to ensure that all vendors are compliant.
