CORAA

Third-Party / Outsourcing Risk Audit Checklist

Vendor risk tiering, SLA monitoring, sub-outsourcing chain visibility, and exit-strategy readiness — the controls around depending on someone else's process for a critical function.

Free · CORAA original — SA-aligned
Updated 28 Jul 2026
Scope
Vendor tiering, SLA monitoring, sub-outsourcing, exit readiness
Key test
Does oversight intensity actually scale with vendor criticality?
Common gap
No visibility into whether the vendor itself sub-outsources
Format
Microsoft Word (.docx)
Share this template
Your firm — letterhead
Appears at the top of the document as the audit firm letterhead.
Used as the letterhead block.
Engagement details
The client and period this document is for.
What’s inside

An excerpt from the template.

THIRD-PARTY / OUTSOURCING RISK AUDIT CHECKLIST

Entity: ___ · Period: ___

Scope: risk arising from dependence on third parties for a critical business function or process — vendor risk tiering, service-level monitoring, visibility into the vendor's own sub-outsourcing chain, and readiness to exit or transition the arrangement if needed.

Risk & Control Matrix

↑ Excerpt only — the full template is what you download as Word
About this template

What you’re downloading, and when to use it.

This template follows the format published by the Institute of Chartered Accountants of India (ICAI) in the AASB Audit Working Paper Templates (June 2023), the authoritative reference for Indian statutory-audit documentation. Fill in your firm’s letterhead and the engagement details on the form above, click Download Word file, and you’ll get a fully formatted .docx ready to use.

Everything is generated in your browser and on a stateless API endpoint — no account, nothing stored on our servers. We’ll ask for a work email once before your first download so we can send you the file and the occasional relevant update; after that, downloads on this device are instant. Edit freely in Word, Google Docs or Pages before sending to your client.

Common questions

FAQs.

What does "vendor risk tiering" actually mean in practice?
It means classifying vendors — typically into something like critical/high/medium/low — based on factors such as data access, financial exposure, and how hard the function would be to replace on short notice, and then matching the depth of ongoing oversight (site visits, financial health checks, SLA review frequency) to that tier. A common finding is that every vendor gets the same light-touch annual check regardless of how critical they are.
Why does sub-outsourcing visibility matter if the entity's contract is only with the primary vendor?
If the primary vendor further outsources a critical part of the work to a fourth party the entity never vetted and has no contractual relationship with, the entity's actual risk exposure extends beyond what its own due diligence covered. Many outsourcing failures trace back to a sub-contractor two or three layers removed from the original vendor relationship.
Is an exit strategy only relevant if the entity plans to terminate the vendor?
No — exit readiness matters even for a vendor relationship in good standing, because the vendor itself could fail, be acquired, or exit the market. The test here is whether the entity COULD transition within an acceptable timeframe if it had to, not whether it currently intends to.
Related templates

You might also need.

Vendor Management Internal Audit Checklist
Free vendor management internal audit checklist. Tests vendor onboarding KYC, master data controls, price appr
Cybersecurity Internal Audit Checklist
Free cybersecurity internal audit checklist. Vulnerability management, incident response, security awareness,
Contract Management Internal Audit Checklist
Free contract management internal audit checklist. Tests approval authority, renewal tracking, SLA and penalty