Back to TPRM

Vendor Reassessment Frequency: How Often to Re-Review Your Vendors

Vendor reassessment frequency illustration: a circular calendar with vendor cards in four risk tiers, review checkmarks and alert icons marking trigger events

Short answer: Set vendor reassessment frequency by risk tier and let events override the calendar. A sensible start: annual full reviews for critical and high-risk vendors, lighter reviews every two years for moderate vendors and a check at renewal for low-risk ones. A breach, new data type such as PHI, scope change or acquisition should trigger an immediate review.

Related guides:

Key takeaways

  • No major framework hands SMBs a single required vendor review interval. Most expect oversight that is proportionate to risk, so your cadence should follow your tiers.
  • A practical default: critical and high-risk vendors yearly, moderate vendors every 24 months, low-risk vendors at renewal. Treat it as a starting pattern you document and defend, not a rule.
  • Trigger events beat the calendar. A vendor breach, new PHI flows, a scope change, an acquisition, a lapsed SOC 2 report or a changed BAA should restart the review clock.
  • Not every reassessment needs a full questionnaire. A light reassessment confirms nothing material changed; a full reassessment re-runs due diligence.
  • For HealthTech teams, HIPAA's focus is on the business associate agreement and how you respond to known problems, not a fixed audit schedule. A proposed HHS rule would add an annual verification step.

How often should you reassess your vendors?

Reassess each vendor at an interval set by its risk tier, and write that interval into your vendor management policy so reviewers and auditors can check you followed it.

If you have not tiered your vendors yet, start with our vendor tiering model. The cadences below are SecureSlate's recommended starting point, not an industry standard or a mandate, so adjust them to your risk appetite, contracts and customer commitments.

Tier Typical profile Suggested full-review cadence Light check in between
Critical Hosts or processes PHI or customer data, sits in your production path, or would stop service if it failed (cloud host, EHR integration, identity provider) Every 12 months Quarterly or when new evidence is published
High Has access to sensitive internal data or systems, but an outage would not stop service (support desk, HR platform, CI/CD tooling) Every 12 months At mid-point or on report renewal
Moderate Limited data access, replaceable within weeks (analytics, project tools) Every 24 months At contract renewal
Low No access to sensitive data or systems (office supplies, event venues) At renewal or every 36 months None beyond attestation of no change

Two adjustments are worth making early:

  1. Tie reviews to evidence dates. Many critical vendors publish a SOC 2 or ISO 27001 report once a year. Scheduling your review a few weeks after their new report lands avoids reviewing stale evidence.
  2. Tie reviews to renewal dates for lower tiers. A review is most useful when you can still renegotiate, add a clause or walk away.

Which events should trigger an out-of-cycle review?

Any change that alters what the vendor touches, how well it is protected or who controls it should trigger a review regardless of where the vendor sits on the calendar.

Calendars catch drift; triggers catch change. Use this list as your trigger register:

Trigger event Why it matters Suggested response
Vendor security incident or breach Controls may have failed and your data may be affected Full reassessment, incident questions, review notification obligations
New data type, such as PHI or payment data The vendor's risk tier may jump overnight Re-tier, then full reassessment; sign a BAA before PHI flows if the vendor will be a business associate
Scope change (new product, new integration, new region) New systems and locations may sit outside prior evidence Light or full review depending on data involved
Merger, acquisition or change of ownership Policies, infrastructure, subprocessors and leadership can change Full reassessment within a set window after close
SOC 2 or ISO 27001 report lapses or comes back qualified Your assurance has a gap or a known exception Request a bridge letter or new report, review exceptions, record risk acceptance
BAA or data processing terms change Obligations, notification timelines or subcontractor rules may shift Legal and security review of the changed terms
New subprocessor or offshoring of work Your data now reaches a party you never assessed Light review of the subprocessor and data flow
Material financial distress or service degradation Higher chance of failure or shortcuts on security Business continuity and exit plan check

Your continuous vendor risk monitoring signals feed this register. The trigger list decides what happens when a signal fires.

What goes into a light reassessment versus a full one?

A light reassessment confirms that nothing material has changed, while a full reassessment re-runs due diligence as if you were onboarding the vendor again.

Sending the full questionnaire to every vendor every year tends to produce slow responses and rubber-stamped reviews, so we suggest matching the depth of each review to the vendor's risk.

Light reassessment:

  • Confirm the vendor's tier, owner and data access are still accurate
  • Collect the latest certification or attestation report and check its period and scope
  • Ask a short change questionnaire: incidents, ownership, subprocessors, hosting locations
  • Check contract, BAA and insurance dates
  • Record the outcome and the next review date

Full reassessment:

  • Everything in the light review
  • Updated security questionnaire covering access control, encryption, logging, vulnerability management, incident response and business continuity
  • Review of report exceptions, carve-outs and complementary user entity controls you must operate
  • Validation of remediation for findings from the last review
  • Re-scoring of residual risk and sign-off by the business owner and security
  • Contract review for security, audit and notification clauses

For the full question set, our vendor risk assessment checklist covers what to ask.

What do frameworks and regulators expect?

Most frameworks expect ongoing, risk-based oversight of suppliers rather than a fixed review interval, so your documented cadence is how you show that oversight exists.

Framework or guidance What it expects for existing vendors
ISO/IEC 27001:2022 Annex A includes supplier relationship controls, among them a control on regularly monitoring, reviewing and managing changes to supplier services. Frequency is left to your risk assessment.
SOC 2 (AICPA Trust Services Criteria) The criteria cover assessing and managing risks from vendors and business partners. Your auditor tests whether you follow the process you designed, including your stated review cadence.
HIPAA (HHS business associate guidance) Covered entities need satisfactory assurances, usually a BAA, from business associates. HHS explains that a covered entity is not required to actively monitor its business associates, but must act if it learns of a pattern of activity that materially breaches the contract.
Proposed HIPAA Security Rule update Proposed in a notice published in the Federal Register in January 2025. Among other changes, it would require covered entities to obtain written verification from business associates, at least once every 12 months, that required technical safeguards are in place. Check HHS for its current status.
Interagency guidance on third-party relationships Issued in June 2023 by the Federal Reserve, FDIC and OCC for banking organizations. It describes a third-party risk management life cycle that includes ongoing monitoring, scaled to the risk and complexity of each relationship. Relevant if you sell to banks, which may push similar expectations to you.

Two practical points follow. First, an auditor will hold you to what your policy says, so do not promise quarterly reviews you cannot staff. Second, HIPAA itself does not give covered entities an automatic right to audit a business associate; HHS notes that cloud providers are not required to provide documentation or allow audits unless the parties agree to it. If you want evidence on a schedule, put it in the contract.

What does a 12-month reassessment calendar look like?

A workable calendar spreads reviews across the year, anchors critical vendors to their report release dates and leaves capacity for trigger-driven reviews.

Here is a sample for a HealthTech SaaS company with about 40 vendors. The vendor names are generic placeholders, and the tiers are assumed: the cloud provider, identity provider, EHR integration, payment processor and telehealth vendor are critical; the email platform, support desk, HR platform, CI/CD tooling and logging vendor are high. High-tier vendors get their full review once a year and a light check about six months later. The calendar is a partial illustration: it shows a selection of the 40 vendors, and the remaining reviews and mid-point checks follow the same pattern.

Month Scheduled reviews Type Notes
January Cloud infrastructure provider Full Time it a few weeks after the provider publishes its new SOC 2 report; review exceptions
February Identity provider, email platform Full Confirm MFA and SSO settings align with your own controls
March Moderate tier batch 1 (5 vendors renewing in Q1), plus Q1 light check on critical vendors Full or light Full review for vendors in their two-yearly review year; light check at renewal for the rest
April EHR integration partner Full Re-check BAA terms and PHI data flows
May Support desk, HR platform Full Both hold sensitive personal data
June Q2 light check on critical vendors Light Incidents, subprocessors, ownership changes
July Payment processor, CI/CD tooling Full Align with PCI and code security reviews
August Moderate tier batch 2 (5 vendors renewing in Q3) Full or light Same rule as March; retire unused vendors
September Telehealth video vendor, plus Q3 light check on critical vendors Full, light PHI in transit and recording retention
October Low tier attestation sweep Light One-question change attestation
November Logging and monitoring vendor, plus mid-point light check on high-tier vendors (support desk, HR platform) Full, light Confirm log retention and access
December Program review, plus Q4 light check on critical vendors Internal, light Re-tier vendors, update policy, plan next year

We suggest holding back some reviewer capacity each quarter for trigger events, because ownership changes, new subprocessors and incidents do not follow your calendar.

How do you stop the cadence from slipping?

Give every vendor a named owner, a next review date and an automated reminder, and report overdue reviews to leadership.

  1. Store the next review date on the vendor record, not in a spreadsheet tab no one opens.
  2. Assign a business owner and a security reviewer. The owner chases the vendor; the reviewer judges the evidence.
  3. Write evidence delivery into contracts. Ask critical vendors to send their new report and notify you of incidents, ownership changes and subprocessor changes.
  4. Track overdue reviews as a metric. A short monthly list of overdue critical and high vendors keeps attention where it belongs.
  5. Close the loop. Every reassessment ends in a decision: continue, continue with remediation, or start an exit plan.

How SecureSlate helps

SecureSlate's vendor risk management module keeps each vendor's tier, owner, documents and review dates in one place, so periodic vendor reviews and trigger-based reassessments run from the same record. Risk management records residual risk and acceptance decisions. Multi-framework control mapping links your vendor reviews to SOC 2, ISO 27001, HIPAA and HITRUST controls at once, and audit management keeps the evidence ready for your auditor.

Start your free SecureSlate trial

FAQ

Is annual vendor reassessment required?

Not universally. Most frameworks expect risk-based ongoing oversight rather than a fixed interval. Annual review of critical vendors is a common, defensible pattern, and some standards or contracts set their own timelines, so check what applies to you.

What is the difference between vendor monitoring and vendor reassessment?

Monitoring is the continuous watch for signals such as breaches or expired reports. Reassessment is the periodic or triggered review where you re-examine evidence and decide whether the vendor's risk is still acceptable.

Should a SOC 2 report older than 12 months trigger a review?

We suggest treating it as a trigger. Ask for the new report or a bridge letter covering the gap, and record the decision if you continue to rely on older evidence.

Do HealthTech companies need to reassess vendors that handle PHI more often?

Vendors that handle PHI usually sit in the critical tier, so they get the most frequent full review and quarterly light checks. Adding PHI to an existing vendor should trigger an immediate review and a BAA where required.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

Keep reading

Oct 1, 2026 · TPRM

Fourth-Party Risk Management: How SaaS and HealthTech Teams Map and Monitor Their Vendors' Vendors

Jul 5, 2026 · TPRM

TPRM lifecycle: the 5 stages of third-party risk management (2026 playbook)

Jul 5, 2026 · TPRM

Vendor risk management software: evaluate, onboard, and monitor third parties at scale

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?