Skip to content

Document template · generic.procurement.vendor_risk_assessment

Vendor Risk Assessment

  • Render-verified
  • Commercial
  • Version 1.0.0

Periodic risk assessment of an existing supplier across financial, operational, data-protection, cybersecurity, ESG, geographic, regulatory and concentration dimensions, with mitigations, monitoring cadence and review date. Aligned with ISO 31000:2018 (risk management — guidelines), ISO 9001:2015 clause 8.4.1 (evaluation and re-evaluation of external providers), Directive (EU) 2024/1760 (CSDDD) for human-rights and environmental risk and EBA / EIOPA outsourcing guidelines for the financial-services dimension.

JSON Schema

Fields in this template

Data sent to the API is validated against the template’s JSON Schema before anything is rendered. This template defines 9 fields:

Field Required Type Description
supplier Required object
assessment_date Required date
assessor Required object
risk_dimensions Required array
overall_rating Required enum
mitigations Required array
monitoring_cadence Required string
next_review_date Required date
signatory Required object

POST /render

Generate it

One POST /render call: send your JSON, get the finished PDF back. Or skip the JSON entirely and describe the document in plain language on chut.app.

curl
curl -X POST https://api.papii.eu/render \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "template": "generic.procurement.vendor_risk_assessment",
    "data": { ... },
    "options": {"language": "en"}
  }' -o vendor-risk-assessment.pdf

Frequently asked questions

What is “Vendor Risk Assessment”?

Periodic risk assessment of an existing supplier across financial, operational, data-protection, cybersecurity, ESG, geographic, regulatory and concentration dimensions, with mitigations, monitoring cadence and review date. Aligned with ISO 31000:2018 (risk management — guidelines), ISO 9001:2015 clause 8.4.1 (evaluation and re-evaluation of external providers), Directive (EU) 2024/1760 (CSDDD) for human-rights and environmental risk and EBA / EIOPA outsourcing guidelines for the financial-services dimension. On papii this document is available as template generic.procurement.vendor_risk_assessment: a JSON Schema plus a deterministic PDF renderer, so the same data always produces the same document.

Can I generate a Vendor Risk Assessment with AI?

Yes. chut.app — the AI back office papii powers — fills this template from a plain-language description: you describe the document in one sentence, the AI structures the data, papii validates it against the schema and renders the PDF. Developers can also call the papii API directly with structured JSON.

Is the Vendor Risk Assessment template legally compliant?

This template is render-verified: its schema, sample data and PDF output are automatically tested on every release. It is published with status “ready”, meaning it has not yet been through papii’s final legal review. Where it references specific legislation, that is stated in the template description — always have a professional check documents with legal effect before relying on them.