This is an example risk assessment covering the main third party and outsourcing risks and the controls that manage them. It saves a lot of time compared with preparing your own from a blank page.
This example risk assessment has been prepared using the
F-Q36 General Risk Assessment form template - a purpose-built template designed to focus entirely on what matters: identifying business risks, assessing their likelihood and impact, and recording the controls that manage them, without any unnecessary fields getting in the way.
The file is supplied in fully editable MS Word format and can be easily customised and saved to Google Docs format if required. The document uses pre-defined style formatting throughout with styles to match the risk-ratings which are input using select boxes pre-populated with all possible risk ratings. All text is in Calibri font for improved readability.
The following document labelling is included in the footer:
- Form number and title
- Information-classification
- Version
- Page number / total pages
alphaZ documents - beautifully designed, tried and tested form templates. No junk, jargon or unecessary fields. Simple and usuable form templates
developed over 25 years through practical use in the real world. No AI generated nonsense here!
Further guidance on managing third parties and suppliers:
Download this form template with your company name and logo already added!
Document Preparation available with all document toolkits.
To get access to this file please click on Add to Cart to purchase for immediate download. If you have an alphaZ Subscription just click on Download Files to view all the files available to download.
Third Party and Outsourcing Business Risk Assessment
This fully completed third party and outsourcing business risk assessment example has been prepared by experienced ISO management system consultants. It covers the risks of relying on suppliers, contractors and outsourced service providers, including performance, dependence, data and system access, continuity and the contractual protection needed to manage them. It can be used as a starting point when developing your own business risk assessment documentation.
What Does This Third Party and Outsourcing Business Risk Assessment Cover?
This risk assessment identifies the key third party and outsourcing risks an organisation faces, including:
- Supplier and third-party selection
- Performance and service quality
- Dependence and concentration
- Data and system access
- Contractual protection
- Continuity and exit
- Subcontracting and fourth parties
- Conduct and compliance of third parties
- Ongoing management and review
A residual risk rating is then assigned to each risk, demonstrating how effective controls - such as careful supplier selection, clear contracts and service levels, controls over data and system access, continuity and exit planning, and ongoing supplier review - reduce the overall risk to a tolerable level.
A Professional Easy-to-Use Risk Assessment Template
This document uses colour-coded header styles matched to risk ratings, making it quick to read and easy to communicate during team briefings and staff training. A built-in risk rating matrix supports consistent evaluation of likelihood and consequence, and clear risk symbols help communicate each risk at a glance. An inherent and a residual rating are recorded for every risk, so the effect of your controls is easy to demonstrate.
Risk, Control and Prohibition Symbols
Each row in the assessment is tagged with a small symbol so the type of risk, the control that manages it and any prohibition are clear at a glance. The same icon set runs across every alphaZ business risk assessment, which keeps a finished document quick to read and easy to compare. You can read more about them in our blog post on the alphaZ business risk icons.

Who Is This Third Party and Outsourcing Business Risk Assessment Template Suitable For?
This template is suitable for organisations of any size that need to assess and document their third party and outsourcing risks. It is useful when managing supplier relationships, when meeting the supplier and third-party security expectations of ISO 27001, and when supporting the risks and opportunities requirements (clause 6.1) of ISO management system standards. Directors, procurement leads and management system managers can all use it as a practical, ready-made starting point.