Vendor Risk Management
Right-sized for nonprofits. Grounded in SIG, CSA CAIQ, and HIPAA frameworks.
Answer five questions and get a questionnaire you can send today.
Risk Tiers
Low-risk vendor — limited data access, no system connectivity
22–30 questionsMedium-risk vendor — stores data, supports key operations
45–65 questionsHigh-risk vendor — PHI access or privileged system access
70–95 questionsStep 1 of 5
This information will appear on the cover page of the questionnaire you send to the vendor.
What type of review is this?
Step 2 of 5
What best describes this vendor's role?
How is the service delivered?
Will this vendor store your organization's data on their systems?
Will this vendor connect to your internal systems or network?
Step 3 of 5
These answers determine whether HIPAA-specific review applies.
Will this vendor create, receive, maintain, transmit, or otherwise access protected health information (PHI)?
Is a Business Associate Agreement (BAA) expected or required for this vendor?
Does this vendor use subcontractors or subprocessors that may also access your data?
Does this vendor handle regulated financial, donor, employee, or student data?
Step 4 of 5
Is this vendor operationally critical — would your team be unable to deliver services without them?
Would extended downtime from this vendor affect care delivery, donor operations, or finance?
Does this vendor have or require privileged or administrator access to your systems?
Recommended questionnaire tier
Override tier if needed:
Step 5 of 5
Email me this questionnaire
We'll send a copy you can forward to the vendor or share with your team. No account required.
We save your nonprofit's basic profile — org name, contact, and preferred settings. Do not enter PHI or patient information into this tool.
Generated Questionnaire
Next Step
Most of our clients find the vendor management process itself — the back-and-forth, the documentation, the compliance checks — is costing their team 3 to 5 hours a week. A Capacity Review finds those hours. 12 minutes with Alex. Written report in 24 hours.
Start Your Capacity ReviewCommon Questions
A vendor security questionnaire is a structured set of questions you send to a vendor to assess their security practices, data handling, and compliance posture before sharing data or granting system access. It is one of the most common tools in third-party risk management.
Any vendor that stores, processes, or has access to your organization's sensitive data. For HIPAA-regulated nonprofits, any vendor that may touch PHI should receive at least a baseline review and likely needs a Business Associate Agreement in place first.
HIPAA applies when a vendor will create, receive, maintain, or transmit protected health information on your behalf. That vendor becomes a Business Associate and must sign a BAA before PHI is shared. This tool automatically adds HIPAA-specific questions and a BAA reminder when you indicate PHI access.
A BAA is a legally required contract between a HIPAA Covered Entity (your organization) and any vendor (Business Associate) that handles PHI. It documents each party's responsibilities for protecting PHI and outlines breach notification obligations. This tool is not a substitute for a BAA — confirm requirements with your legal or compliance team.
The question library draws from SIG (Standardized Information Gathering), SIGLite, CSA CAIQ (Cloud Security Alliance Consensus Assessments Initiative Questionnaire), VSA (Vendor Security Alliance), and HIPAA Security Rule control expectations. These are widely recognized frameworks used by security and compliance teams.
No. You can complete the builder and export your questionnaire without creating an account. The optional save feature stores your organization details so you can skip setup on future visits.
No. This tool helps structure vendor due diligence but is not legal advice. It should not replace a review by your legal, compliance, or privacy team, especially for vendors that handle PHI or require a BAA.
Only your organization name, contact name, email, and preferred questionnaire settings. Do not enter PHI, patient data, or sensitive vendor responses into this tool.