Resources/Selling Vendor Risk Assessments
    Vendor Risk and Stack

    Selling Vendor Risk Assessments

    Turn the vendor work you already do into a paid client offer, with scope, pricing bands, and the findings clients care about.

    You just built your own vendor inventory. You found 60 vendors when you expected 25, three of them still had live API keys from a provider you fired last year, and nobody could explain who signed up for two of the SaaS tools.

    Your clients are worse. No IT department, no procurement process, and a marketing person who expenses whatever they want. Unlike you, they have no idea any of this is a problem.

    That gap is a service line. This page covers what the offer looks like, who buys it, what to charge, and how to run the engagement without it eating your margin.

    It assumes you already fixed your own house. If you have not, start with the internal page first, because you cannot credibly sell a vendor risk assessment while your RMM console runs on a shared login.

    The framework comes from the Third-Party Vendor Management guidebook published by GTIA and written by Nett Lynch, MBA. GTIA covers the client opportunity in a few paragraphs. This is the version with prices and scripts in it.


    Why this sells right now

    Vendor risk used to be an enterprise concern. Three things pushed it down to the 30 person business.

    Cyber insurance questionnaires. Renewal applications now ask about third party risk management. Your client checks a box saying they have a process, their broker never follows up, and the answer is a lie sitting in an insurance file until a claim. Insurers deny claims over questionnaire misrepresentations. Your client does not know this.

    Compliance requirements with teeth. HIPAA covered entities must document business associate relationships. PCI-DSS requires vendor management controls. CMMC mandates supply chain risk management for anyone in the defense supply chain. State privacy laws keep expanding vendor obligations.

    Contract flow-down. Your client's biggest customer sends a security questionnaire asking who touches their data. Your client forwards it to you because they have no idea. You have already been doing an unpaid version of this work. Start charging for it.

    That last one is the best lead source you have. Every forwarded questionnaire is a buying signal with a deadline attached.


    Why you win this work

    You are not competing with the Big Four here. You are competing with nobody, which is a better market.

    Your client's options are a regional accounting firm that quotes $40,000 for a risk framework nobody reads, a compliance SaaS product that dumps a questionnaire on them and calls it a platform, or doing nothing. Doing nothing wins most of the time.

    You have three advantages over all three.

    You already know their stack. You can name their vendors before you walk in the door. Your RMM knows what agents are installed. Your documentation platform holds their credentials. Half the discovery work sits in tools you already own. Nobody else can say that.

    You did it yourself. You built your own inventory, tiered it, fixed your contracts. That story sells better than any certification logo, and you should tell it in the first meeting. Not "you should manage vendor risk," which is a lecture. Instead: "we went through this ourselves last year, here is what we found in our own environment, here is what it cost us to fix." Owners respond to the second one because it is a story about you being wrong and fixing it, not about them being wrong.

    You are already in the building. This does not require a new relationship. It requires a different conversation inside one you already have, usually at a QBR.


    Who buys, and who to start with

    Do not pitch your whole client base. Chasing a 12 person retail business wastes your time and burns goodwill. Four groups buy without much convincing.

    Clients renewing cyber insurance in the next 90 days. The application asks vendor questions they cannot answer. They are stuck and the deadline is real. Best trigger on the list, and you can pull it from renewal dates you already track.

    Clients whose customers send them security questionnaires. Anyone selling into enterprise, healthcare, finance, or government is getting these. They usually forward them to you hoping you will fill them out for free. Stop doing that for free and turn it into the engagement.

    Clients in regulated verticals. HIPAA covered entities, anyone in the defense supply chain facing CMMC, payment processors under PCI-DSS. They have a compliance obligation they are failing, and the fix is billable.

    Clients who just got acquired or are preparing to sell. Diligence surfaces this fast and they have a reason to move.

    Your non-buyers are companies where nobody is asking them for anything. They will not pay to solve a problem nobody raised. Leave them alone until something changes, then come back.


    The offer stack

    Three layers. They ladder, and the first one reliably feeds the other two.

    Layer one: the vendor risk assessment

    Fixed scope, fixed fee, point in time. This is your entry product and the one you lead with.

    What you deliver:

    • Complete vendor inventory built from your data and their records
    • Every vendor tiered by risk with the reasoning documented
    • Gap findings, with the ones that matter separated from the ones that do not
    • A prioritized remediation plan with effort and cost estimates
    • Executive summary an owner reads in four minutes

    How long it takes: two weeks of calendar time, roughly 12 to 20 hours of actual work for a client under 100 seats. Most of that is discovery.

    How to price it: flat fee, banded by seat count. $3,500 to $8,000 depending on client size and vendor count. Under 40 vendors sits at the low end. A multi-location healthcare client with over 100 vendors sits at the top. Do not price per vendor, because you will spend the whole engagement arguing about what counts as a vendor. Three bands, fixed number, and the fixed number is what makes the yes easy.

    Price it so it stands on its own. Do not discount it to zero as a loss leader hoping for the retainer. Free assessments get treated as free, and clients ignore free findings.

    The important part: this assessment always produces findings. Always. Nobody passes. That is not a sales trick, it is what happens when a company inventories vendors for the first time. Which means layer one reliably creates demand for layers two and three.

    Layer two: remediation and program build

    The assessment says what is broken. This fixes it and leaves a program behind that stays fixed.

    What you deliver:

    • Vendor inventory handed over as a living document they own
    • Three tier classification model documented with their vendors in it
    • Written vendor management policy, signed by their leadership
    • Contract language they can hand to their attorney
    • BAAs signed with vendors that never had one, dormant accounts killed, access cleaned up
    • New vendor intake process built into whatever ticketing or approval system they use
    • Training session for whoever owns it on their side

    How long it takes: four to eight weeks depending on how much contract work is in scope.

    How to price it: $5,000 to $15,000, scoped off the findings, never before. It varies widely based on how bad the assessment was. Contract remediation is the piece that blows up estimates, so either exclude it and bill separately or cap the number of contracts you will review.

    Layer three: ongoing vendor oversight

    Recurring revenue, and this is where the model actually pays.

    What you deliver monthly or quarterly:

    • New vendor reviews as they come up, using the six question intake
    • Quarterly access review on Tier 1 vendors
    • Annual security documentation collection and chase
    • Contract renewal calendar with notice windows flagged before they close
    • Vendor incident monitoring and notification when one of their vendors gets breached
    • Annual reassessment and tier updates

    How to price it: $8 to $20 per seat per month depending on regulatory burden, folded into a vCISO or compliance retainer rather than sold standalone. Standalone vendor oversight is a hard sell at a price that makes sense. Bundled into a security governance retainer it is one of the more visible line items and it justifies the number.

    If you do not have a vCISO offer, this is a reasonable way to start building one.


    How to actually run the assessment

    The delivery mechanics matter more than the framework. Here is the sequence that keeps a two week engagement at two weeks.

    Week one: discovery

    Pull from six sources. Four of them you already have.

    1. Your RMM. Installed software inventory across their endpoints. Fastest yield and it costs you nothing.
    2. Your documentation platform. Everything you already documented about their environment, integrations, and credentials.
    3. Their identity provider. Export OAuth grants and SAML applications from Entra ID or Google Workspace. Every consented app is a vendor. This list is always longer than the client expects and it makes a great slide.
    4. Their firewall or DNS logs. Outbound destinations tell you what is actually in use versus what somebody thinks is in use.
    5. Twelve months of their credit card and AP records. You have to ask, and some clients hesitate. Frame it as finding money, because you will find subscriptions they stopped using and that pays for part of your fee.
    6. One 30 minute staff conversation. What tools do you use that IT might not know about. Amnesty framing. No exceptions.

    Sources one through four you can run before the kickoff call. Walking into kickoff with a draft inventory already built changes the entire tone of the engagement.

    Week two: tier, gap, report

    Tier every vendor using the same four questions from your internal program. Can they reach client systems, do they hold sensitive data, how long can the business run without them, does regulated data flow through them. Tier 1, Tier 2, Tier 3.

    Then check the Tier 1 vendors only for the gaps that actually matter. Do not build a 60 question survey. Check these seven:

    1. MFA enforced on the vendor portal
    2. Shared logins in use
    3. Admin access broader than the vendor needs
    4. Security documentation on file and current
    5. Breach notification language in the contract
    6. Data return and destruction terms in the contract
    7. A named owner on the client side

    Seven checks across ten to fifteen Tier 1 vendors is a real assessment. Sixty questions across all 60 vendors is a project that dies in week five and loses money.

    The report

    Keep it under 15 pages. Written for the owner, not for a security team.

    • Executive summary, one page
    • What we found, vendor count and tier breakdown, with the number of previously unknown vendors called out explicitly
    • Tier 1 vendors and their gaps
    • Top five risks in plain language, no CVSS scores, no jargon
    • Prioritized remediation plan with effort and cost
    • Full inventory as an appendix

    The line that lands hardest in every one of these reports is the count of vendors the client did not know they had. Put it in the executive summary, in the first paragraph, as a number.

    Prioritize ruthlessly. Five things to fix this quarter beats forty things to fix eventually. A report that lists 40 problems and stops gets filed and forgotten.


    The AI angle nobody else is selling

    Run the OAuth and enterprise application report in their Microsoft or Google tenant and look at what has been granted access. You will find AI tools. Note takers sitting in every meeting. Browser extensions with permission to read page content. Someone's personal ChatGPT account authenticated to their work Google Drive.

    Nobody approved any of it. Nobody knows it is there. Most of these tools hold broader data access than the vendors the client is worried about.

    This is the finding that sells the remediation project. When you show a healthcare client that an AI meeting assistant has been recording and transcribing patient care coordination calls to a vendor with no BAA, the conversation stops being theoretical. That is a reportable exposure, and now they need you.

    Lead with it in the findings. It is concrete, it is visual in a report, and it is the one item where the owner understands the problem without you explaining a framework.


    Positioning it in the conversation

    Do not lead with compliance. Compliance sells to the 30 percent who have a deadline. Business risk sells to everyone else. Frame vendor risk as business risk, not an IT concern.

    Three openers that work.

    At a QBR: "I pulled a quick list of the software running in your environment. There are 47 vendors on it. How many did you think there were?" Then wait. The gap between their guess and the real number does your selling for you.

    On an insurance renewal: "Your application is going to ask which third parties have access to your systems and what security requirements you have with them. Do you want to answer that from a list, or from memory?"

    On a customer questionnaire: "This is the fourth one of these you have forwarded me this year. They will keep coming and they will get harder. Let's build the answer once."

    Short, specific, tied to something already on their desk. Then let them ask what it costs.

    Copy-paste outreach email

    Subject: The vendor list nobody has

    Hi [NAME],

    Quick thing I want to put in front of you before your renewal.

    I ran a rough count of the third-party software with access to your environment. I got to [NUMBER]. Most companies your size guess about half that, and the ones nobody remembers signing up for are usually the ones with the most access.

    That matters for two reasons. Your insurance application asks about it, and any one of those vendors getting breached becomes your problem, not theirs.

    I put together a two-week assessment that inventories every vendor, ranks them by actual risk, and gives you a short list of what to fix first. Fixed fee, no surprises.

    Worth 20 minutes?

    Mike


    What breaks, and how to handle it

    The client will not share financial records. Common, especially with a controller who does not report to your buyer. Work without it and note the limitation in the report. You will still catch 70 percent from technical sources. Ask again during remediation once trust is higher.

    They want you to fix everything you found, for free. This is why the assessment is a separate fixed fee deliverable with a defined end. The findings are the product. Remediation is the next contract. Be clear about that boundary in the proposal, not after the report lands.

    They want you to sign off that they are compliant. Do not. You documented current state and identified gaps on a date. You are not an assessor, not an auditor, not their attorney. Never tell a client a vendor is secure. Put that in writing in the report and in your MSA, and have your attorney look at the language once. It costs a couple hundred dollars and it matters if a reviewed vendor gets breached later.

    Their vendors will not answer your questions. Same problem you have. Large vendors ignore security questionnaires from a 40 person company. Use published SOC 2 reports and trust center pages instead of chasing responses, and document the non-responders as a finding rather than an open item.

    Scope creep into procurement. Six months later you are reviewing every SaaS subscription the marketing team wants. That is a service with a price, not a favor. Define it in the retainer or decline it.

    You become their vendor risk department by accident. The most common failure. The assessment ends, nobody at the client owns the sheet, and six months later you are the only one who knows anything about it, unpaid. Name an owner on their side during the program build, train that person, make the handoff explicit. If they will not name someone, that is what layer three is for, and you should price it that way.

    Selling it before you have done it internally. Do your own house first. Not just for credibility, though that helps. You need to know how long the work takes before you quote it, and the first inventory always takes longer than you expect.


    The honest limits

    This is not a huge revenue line at your size. An assessment is a few thousand dollars and a program build is a few thousand more. That is real money for a shop your size, and it is not a business by itself.

    What makes it worth building is where it sits. It is a credible reason to have a strategic conversation with an owner instead of a technical one with an office manager. It reliably uncovers work you were not going to find otherwise, because every vendor gap is a project. And it is the natural front door to a vCISO retainer, which is the offer that actually changes your margin.

    Start here

    Take the inventory you built for your own shop. Pick one client who fits the buyer profile, most likely the one who sent you a security questionnaire in the last six months. Run the same process on them and price it at $3,500.

    Your first one takes longer than it should. That is fine. You will learn where the time goes, and the second one is profitable.

    Talk it through

    Sell the assessment, deliver it cleanly, and let the findings do the rest. Where owners get stuck is upstream of all that. Which accounts buy it first, what the fee should be in your market, and whether adding a service line is even the right move when your delivery team is already at capacity.

    Everything above is a template. Run it yourself this week and never talk to me. What I will not do is hand you a system and tell you your shop is wrong for not matching it.

    Not sure this is your actual constraint? Take the MSP Owner Reality Check. Five questions, nine minutes, and it names the two or three things quietly capping your growth. https://themsphero.com/resources/msp-owner-reality-check-assessment

    If you already know what is broken, book a 30 minute fit call at https://letschat.themsphero.com

    Mike Kolb The MSP Hero


    Adapted from Third-Party Vendor Management: A Guidebook for IT Solution Providers, written by Nett Lynch, MBA, and published by the Global Technology Industry Association. The TPVM framework and client service model are GTIA's. The pricing structure, delivery sequence, outreach language, and opinions are mine. Pricing ranges reflect what shops in this market charge and are not a quote.

    I WILL NOT SELL YOU A PLAYBOOK

    Frameworks are easy to buy and easy to ignore. What changes your business is someone looking at your actual numbers, your actual team, and your actual clients, then telling you what to fix first. Start with the free read, or just book the call.