Gain a 360-degree view of third-party risk by using our SaaS software to centralize, track, automate, assess and report on your vendors. 

Managed Services

Let us handle the manual labor of third-party risk management by collaborating with our experts to reduce the workload and mature your program. 

Document Collection
Policy/Program Template/Consulting
Virtual Vendor Management Office
Vendor Site Audit

Ongoing Monitoring

Let us handle the manual labor of third-party risk management by collaborating with our experts.

Venminder Exchange

As Venminder completes assessments for clients on new vendors, they are then made available inside the Venminder Exchange for you to preview scores and purchase as you need.


Use Cases

Learn more on how customers are using Venminder to transform their third-party risk management programs. 


Venminder is used by organizations of all sizes in all industries to mitigate vendor risk and streamline processes

Why Venminder

We focus on the needs of our customers by working closely and creating a collaborative partnership

Sample Vendor Risk Assessments

Venminder experts complete 30,000 vendor risk assessments annually. Download samples to see how outsourcing to Venminder can reduce your workload.



Trends, best practices and insights to keep you current in your knowledge of third-party risk.


Earn CPE credit and stay current on the latest best practices and trends in third-party risk management.  

See Upcoming Webinars

On-Demand Webinars



Join a free community dedicated to third-party risk professionals where you can network with your peers. 

Weekly Newsletter

Receive the popular Third Party Thursday newsletter into your inbox every Thursday with the latest and greatest updates.



Venminder Samples

Download samples of Venminder's vendor risk assessments and see how we can help reduce the workload. 

State of Third-Party Risk Management 2023!

Venminder's seventh annual whitepaper provides insight from a variety of surveyed individuals into how organizations manage third-party risk today.



3 Questions in Vendor Information Security Assessment Questionnaires

CPE Credit Eligible

Are you asking the right questions in your information security questionnaires?

Asking the right questions in your vendor information security assessment questionnaires can prevent future headaches down the road. Listen to this week’s podcast to find out three important questions we recommend you include in your questionnaire.

Available on
Listen-on-Apple-Podcasts-badge.jpg  google-play-badge 2.jpg


Podcast Transcript

lisa-mae-hill-headshot-circle-2018Hi – my name is Lisa-Mae Hill and welcome to Venminder’s podcast series.

In this 90-second podcast, we’re going to talk about three questions you'll want to include in your vendor information security assessment questionnaires.

Let’s just jump right in.

1. First, you’ll want to ask what kind of security testing the vendor has in place. This is a great way to identify weakness in a tangible format. Your vendors’ reported security testing should include regular, standardized penetration testing of internal and external networks as well as social engineering testing, and that can include things such as: simulated phishing emails and employee awareness tests.

2. Second, consider asking how they handle sensitive data security. In any environment, but especially in a pandemic environment, you want to ensure that vendors have measures in place for any changes in sensitive data storage. Understanding how vendors secure your data at rest and in transit is monumental. You’ll want to inquire about controls around encryption, data retention and destruction policies and remote access and infrastructure policies.

3. And third, ask what type of incident detection and response protocols the vendor has in place. It’s inevitable; incidents will happen. The key to minimizing the impact is discovering them quickly and having a plan to address them effectively. Your vendor should have to be able to demonstrate what they plan do if an incident occurs and should be able to provide documentation around how they’ll identify an incident, their response plan and their notification procedures.

Remember, asking the right questions up front, like the three we discussed today, can prevent a lot of bad discovery moments down the road.

We hope you found this podcast insightful. Thanks for tuning in; We’ll catch you next time!


Subscribe to our Third Party Thursday Newsletter

Receive weekly third-party risk management news, resources, and more to your inbox.


New Call-to-action

Ready to Get Started?

Schedule a personalized solution demonstration to see how Venminder can transform your vendor risk management processes.

Request a Demo