Business Research, Information -- EDM Info Pro

When to Perform a Vendor Risk Assessment

Written by Eric Magill | Mar 7, 2025 3:49:56 PM

BetterCloud's 2024 State of SaaSOps Report contains some daunting numbers for small businesses trying to assess and then manage the cascading number of Software as a Service apps in their tech stacks.

According to that report, SMBs with fewer than 200 employees average a whopping average 42 SaaS aps in their tech stacks.

Keep in mind, that number only includes the SaaS applications that SMB executives would typically know about. Those would be the ones that you and your staff work in on a daily basis.

That does not include the Fourth, Fifth and Nth party vendors that your primary third party vendors farm out to or integrate with. Those lower level vendors could be handling your data without your knowledge unless you've collected a list of vendors used by your primary vendors.

Obviously, performing vendor risk assessments on that many vendors -- not counting all of your vendors in other industries -- would be burdensome for a small business.

How do you make VRAs manageable at that magnitude?

By rating how critical prospective vendors are to your operations, you can determine if a full or partial assessment is required. Or, perhaps their impact doesn't warrant more than basic contact, features. reviews and pricing information.

The following chart offers a quick glimpse of how to make that decision on each potential vendor.

Based on the impact of specific vendors on your business ...
  • High Impact vendors would need full VRAs because they could bring your business to a halt.
  • Medium Impact vendors would need at least partial VRAs for the areas most important to you.
  • Low / No Impact vendors might only require basic corporate info and Features / Pricing / Ratings comparisons.
Going through this exercise of separating your most critical SaaS vendors from less critical third - Nth parties will save your small business's resources while protecting your data and ensuring the best fit possible for your software selections.
 
For help choosing your next SaaS solution or other products or services with a Vendor Risk Assessment, contact me at 302-537-4198, ericm@edminfopro.com or on our Contact form.
 

You can download a copy of my e-Book on performing due diligence on SaaS providers or request an online meeting.