By Ryan Windt | Head of Growth Marketing | Updated June 2026
For most of the last decade, cyber underwriting focused almost entirely on what was inside your own walls: your MFA, your backups, your endpoint protection. That made sense when most attacks targeted the insured directly. It makes much less sense now, when some of the largest losses in the market started at a vendor and rolled downhill.
Underwriters adjusted. Third-party risk management, often abbreviated TPRM, has moved from a compliance nicety to a control that carriers ask about and verify. The reasoning is straightforward: your security is only as strong as the weakest vendor with access to your data or systems, and a breach at one shared provider can trigger losses across hundreds of its customers at once.
This post covers what a vendor risk program actually involves, what underwriters specifically want to see, and how the requirement differs for an SMB managing a handful of vendors versus an MSP that both runs a vendor program and is the third party for its clients. This is the controls-side companion to our coverage post, Supply Chain Attacks and Cyber Insurance, which covers how the policy responds when a vendor is the source of a loss.
Why Vendor Risk Became an Underwriting Control
Two forces pushed third-party risk to the front of the application.
The first is aggregation. When many businesses depend on the same software vendor, managed provider, or cloud platform, a single compromise becomes a correlated loss event for the carrier. Insurers price and probe that exposure carefully, because it threatens the diversification their whole model relies on. Our breakdown of MSP aggregation risk shows how a single upstream breach cascades.
The second is claims experience. Years of incidents that began with a trusted vendor, a software update, a managed service, an integration, taught carriers that perimeter controls are not enough. The question is no longer just “are you secure?” but “do you know who can reach your data, and do you manage that access?”
Underwriters treat vendor risk management as evidence that you understand and govern your real attack surface, not just the part you own outright.
What a Vendor Risk Program Actually Includes
A program does not have to be enterprise-grade to satisfy an underwriter. It has to be real, documented, and proportionate to your size. The components carriers look for:
- A vendor inventory. You cannot manage risk you have not catalogued. Underwriters want to know you have a list of vendors and what each one can access.
- Risk tiering. Not every vendor matters equally. A vendor with access to your customer data or production systems is a different risk than your office snack supplier. Tiering shows you focus diligence where it counts.
- Due diligence and assessment. For higher-tier vendors, this means security questionnaires, reviewing their SOC 2 reports or equivalent, and understanding their controls before granting access. See SOC 2 and Cyber Insurance for how that report is used.
- Contractual requirements. Security obligations, breach-notification timelines, and liability allocation written into vendor contracts and SLAs. Without these, you absorb risk you could have shifted.
- Ongoing monitoring. Vendor risk is not a one-time check at onboarding. Programs that reassess key vendors periodically, and watch for their breaches, score better.
- Access governance. Limiting what each vendor can reach, and removing access promptly when a relationship ends, ties vendor risk directly to controls underwriters already verify.
What Underwriters Specifically Verify
Modern applications ask about vendor risk in increasingly pointed ways. Be ready to demonstrate:
- That you maintain a vendor inventory and can identify which vendors touch sensitive data or critical systems.
- That you assess vendor security before granting access, with questionnaires or third-party attestations for important vendors.
- That contracts include security and breach-notification terms, so a vendor incident does not leave you blind or unprotected.
- That you limit and review vendor access, rather than granting broad standing access that lingers.
- That you monitor key vendors over time, not just at onboarding.
Vague answers (“we trust our vendors”) read as no program at all. Specific answers (“tiered inventory, SOC 2 review for tier-1 vendors, contractual 72-hour breach notice, annual reassessment”) read as maturity and improve both terms and pricing. For the broader application picture, see Cyber Insurance Underwriting: What Carriers Evaluate and the security controls hub.
SMBs vs. MSPs: A Two-Sided Requirement
For SMBs, the realistic bar is awareness and basic governance, not a dedicated TPRM team. Underwriters want to see that you know which vendors can reach your data, that you do at least light diligence on the important ones, and that your contracts are not silent on security. A simple, documented process beats an elaborate one that exists only on paper.
For MSPs, vendor risk cuts both ways and the stakes are higher. An MSP runs a vendor program for its own stack, the RMM, PSA, security tools, and cloud platforms it depends on. But an MSP is also the high-tier vendor for every client it serves, which means its clients’ underwriters are scrutinizing the MSP as a third-party risk. Weak vendor governance inside an MSP becomes aggregation risk for everyone downstream. This is why underwriters evaluating an MSP look closely at tooling standardization and access governance, as covered in How Underwriters Evaluate an MSP’s Client Base and SaaS Security Risks for MSPs.
How This Connects to Coverage
A vendor risk program is a control, not a coverage. It reduces the likelihood and severity of a loss and improves your underwriting outcome, but it does not by itself determine what your policy pays when a vendor is breached. That depends on your contingent business interruption and supply-chain wording, which is the subject of our supply chain coverage guide. The strongest position combines both: a documented program that earns better terms, and coverage wording that actually responds when a vendor incident hits.
Frequently Asked Questions
Do small businesses really need a formal TPRM program? Not a formal enterprise program, but they do need basic vendor governance: knowing which vendors access sensitive data, doing light diligence on the important ones, and having security terms in contracts. Underwriters increasingly ask, and a simple documented process is enough.
Is vendor risk the same as supply-chain coverage? No. Vendor risk management is a control you operate to reduce risk. Supply-chain coverage is the part of your policy that responds when a vendor is the source of a loss. You want both.
What is the most important single step? Build and maintain a vendor inventory tiered by access. Almost everything else in a program depends on knowing who can reach what.
Will a vendor risk program lower my premium? It can. Demonstrating that you understand and govern your third-party exposure is recognized as a risk-reducing control and strengthens your submission at quoting and renewal.
Vendor risk management is the control that acknowledges a simple truth: most businesses no longer operate inside a clean perimeter. The companies that catalogue, tier, and govern their vendors are both more secure and more insurable, and they walk into underwriting with a stronger story. If you want a review of how your vendor governance looks to a carrier, and whether your coverage would respond to a vendor-driven loss, get in touch with our team.