Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Vendor Risk Assessment Questionnaire
I need a comprehensive Vendor Risk Assessment Questionnaire for evaluating cloud service providers in the healthcare sector, with specific emphasis on GDPR compliance and data protection requirements under Danish law, to be implemented by March 2025.
1. 1. Vendor Information: Basic information about the vendor including company details, key contacts, business structure, and service overview
2. 2. Business Profile and Operations: Detailed information about the vendor's business operations, including years in business, size, locations, and key services
3. 3. Financial Stability Assessment: Questions regarding financial health, including revenue information, financial statements, and insurance coverage
4. 4. Information Security Controls: Assessment of IT security measures, including data protection, access controls, and security certifications
5. 5. Data Privacy and Protection: GDPR compliance assessment and general data protection practices
6. 6. Business Continuity and Disaster Recovery: Evaluation of business continuity planning and disaster recovery capabilities
7. 7. Third-Party Risk Management: Assessment of vendor's own supplier management and subcontractor relationships
8. 8. Compliance and Regulatory Framework: Review of regulatory compliance, licenses, and certifications
9. 9. Physical Security: Assessment of physical security measures at vendor facilities
10. 10. Human Resources Security: Evaluation of employee screening, training, and security awareness programs
1. Cloud Services Security: Specific section for vendors providing cloud-based services, including cloud security controls and data center details
2. Healthcare Data Management: Additional questions for vendors handling healthcare-related data or providing healthcare services
3. Financial Services Compliance: Specific section for vendors providing services to financial institutions
4. Environmental Impact Assessment: Additional questions for vendors with significant environmental impact or sustainability concerns
5. Manufacturing and Supply Chain: Specific section for vendors involved in manufacturing or supply chain operations
6. Software Development Practices: Detailed assessment for vendors providing software development services
7. Professional Services Delivery: Specific questions for consulting or professional services providers
1. Schedule A: Required Documentation Checklist: List of all required supporting documents, certificates, and evidence
2. Schedule B: Security Controls Framework: Detailed technical security requirements and controls framework
3. Schedule C: Compliance Certificates: List of required compliance certificates and standards adherence proof
4. Schedule D: Service Level Agreements: Performance metrics and service level requirements
5. Schedule E: Incident Response Requirements: Detailed requirements for security incident handling and reporting
6. Appendix 1: Glossary of Terms: Definitions of technical and business terms used in the questionnaire
7. Appendix 2: Risk Rating Matrix: Framework for evaluating and scoring vendor responses
8. Appendix 3: Data Processing Requirements: Specific requirements for handling and processing data under GDPR
Authors
Applicable Law
Authorized Representative
Business Continuity Plan
Business Day
Confidential Information
Critical Services
Data Controller
Data Processor
Data Protection Laws
Data Subject
Disaster Recovery Plan
Due Diligence
Force Majeure
GDPR
Information Security Incident
Intellectual Property Rights
Material Adverse Change
Non-Compliance Event
Personal Data
Processing
Risk Assessment
Security Breach
Services
Service Level Agreement
Subcontractor
Supplier
Third Party
Vendor
Vendor Personnel
Working Hours
Compliance Framework
Control Measures
Critical Systems
Data Center
Information Assets
Risk Rating
Security Controls
Service Provider
Special Categories of Personal Data
Technical and Organizational Measures
Financial Stability
Information Security
Data Protection
Business Continuity
Operational Risk
Regulatory Compliance
Third-Party Management
Physical Security
Human Resources Security
IT Infrastructure
Incident Management
Quality Management
Environmental Management
Insurance Coverage
Certifications and Standards
Privacy Controls
Supply Chain Security
Business Ethics
Disaster Recovery
Change Management
Access Control
Network Security
Cloud Security
Data Governance
Risk Management
Compliance Monitoring
Information Classification
Asset Management
Vendor Dependencies
Financial Services
Healthcare
Information Technology
Manufacturing
Retail
Professional Services
Telecommunications
Energy
Transportation
Public Sector
Education
Construction
Pharmaceuticals
Insurance
Procurement
Risk Management
Information Security
Legal
Compliance
Vendor Management
IT Security
Internal Audit
Operations
Supply Chain Management
Chief Risk Officer
Procurement Manager
Vendor Management Specialist
Information Security Manager
Data Protection Officer
Compliance Manager
Legal Counsel
IT Security Officer
Supply Chain Manager
Chief Information Security Officer
Risk Assessment Specialist
Contract Manager
Operations Manager
Audit Manager
Third-Party Risk Manager
Find the exact document you need
Area Risk Assessment
A structured evaluation of workplace hazards and safety measures compliant with Danish regulations and EU safety directives.
Vendor Risk Assessment Questionnaire
Danish law-compliant vendor risk assessment questionnaire for evaluating supplier risk profiles and regulatory compliance.
Vulnerability Assessment Matrix
A Danish-compliant security assessment document that systematically evaluates and documents IT infrastructure vulnerabilities and their recommended mitigation strategies.
Asset Criticality Assessment
A Danish law-compliant document that assesses and documents the criticality level of organizational assets, incorporating local and EU regulatory requirements.
Workplace Assessment
A mandatory Danish workplace safety and health evaluation document that assesses and addresses all significant work environment risks and conditions.
Asset Management Risk Assessment
A Danish-law compliant risk assessment document for asset management activities, addressing key risks and regulatory requirements under Danish and EU financial regulations.
Audit Risk Assessment
A Danish-compliant audit planning document that assesses engagement risks and determines audit approach in accordance with Danish audit regulations and ISA standards.
Workplace Risk Assessment
Danish-compliant workplace risk assessment document for systematic evaluation of workplace hazards and safety measures under Danish Working Environment Act.
Activity Based Risk Assessment Form
A Danish-compliant workplace safety document for systematic risk assessment and control of specific work activities, meeting local regulatory requirements.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.