Free · No sign-up required · Results in 5 minutes

Score your third-party risk programme readiness.

Answer 15 questions across all 5 outsourcing-risk domains aligned to the SAMA Outsourcing Regulations. Get an instant maturity score, scored domain breakdown, and prioritised list of gaps — built for Saudi banks managing material vendor estates.

Under 5 minutes
15 questions, one at a time, with keyboard auto-advance.
5 outsourcing domains
Governance, Materiality, Due Diligence, Contracts, Monitoring — all benchmarked.
SAMA-aligned
Each question maps to a SAMA Outsourcing Regulations expectation.
Prioritised remediation
Walk away with your top 3 gaps ranked and actionable first steps.
SAMA Third-Party Risk · Readiness self-assessment

How robust is your third-party risk programme under SAMA?

15 questions across 5 control domains. One at a time. Keyboard-driven. You'll get an instant maturity score and a prioritised remediation roadmap in under five minutes.

15
Questions
5
Domains
< 5 min
Complete
After the questions

What happens when you finish

Your full results are instant — score, domain breakdown and priority gaps, no email required. Optionally enter your email on the results screen to receive the report in your inbox.

01Instant maturity score

Overall outsourcing readiness percentage and your maturity level — Initial, Developing, Defined, or Managed.

02Domain-by-domain breakdown

See which outsourcing domain — Governance, Materiality, Due Diligence, Contracts, or Monitoring — is your biggest exposure.

03Prioritised remediation plan

Top 3 gaps ranked by severity, with specific first steps you can act on before your next SAMA examination cycle.

Beyond the assessment

Ready to put your vendor estate on auditable rails?

GRC Vantage has the SAMA Outsourcing Regulations, NCA CCC, and PDPL controls pre-mapped. Run vendor due diligence once, prove third-party oversight everywhere.

Pre-built questionnaires

SAMA-aligned security and outsourcing questionnaires that adapt by supplier criticality with reviewer routing and risk scoring.

Risk-rated supplier register

One register of all material vendors with concentration risk views, geographies, and SAMA notification status.

Right-to-audit & exit tracking

Track right-to-audit clauses, exit plans, sub-outsourcing chains, and contractual security obligations across all critical suppliers.

FAQ

Frequently asked questions

Is the SAMA Third-Party Risk assessment really free?
Yes. No credit card, no sign-up to start, no commitment. Your full results — score, domain breakdown and priority gaps — appear immediately after the 15 questions. Optionally enter your email to receive the report in your inbox.
Who is this assessment for?
CROs, Heads of Procurement, Vendor Risk Managers, IT Audit Managers, and Compliance Officers at any SAMA-licensed entity managing material outsourcing arrangements.
Does it cover sub-outsourcing (4th-party) risk?
Yes. The Pre-Contract Due Diligence and Ongoing Monitoring domains both ask about sub-processor visibility — a fast-rising SAMA examination concern, especially for cloud and offshore IT.
How does it differ from PDPL or NCA CCC assessments?
PDPL focuses on personal data handling. NCA CCC covers cloud security controls. This assessment scores the SAMA outsourcing-governance lifecycle: policy, materiality classification, due diligence, contracts, and ongoing oversight.
Get started

Start your SAMA Third-Party Risk assessment now — under 5 minutes.

Free. Instant results. No commitment. Built for vendor risk and procurement teams across Saudi banking and finance.

Take the assessment