A risk assessment of a vendor is a common procurement/compliance exercise that CAUDIT members typically undertake individually. Risk assessments are being requested:
There is no cost for the risk assessment to vendors that are providing or renewing an offer to CAUDIT members.
The risk assessment is conducted using the Higher Education Community Vendor Assessment Toolkit™ (HECVAT).
This is a self‑reported, spreadsheet‑based questionnaire developed by the Higher Education Information Security Council (HEISC) (opens in new tab), specifically for use within the higher education sector.
Download the HECVAT at Higher Education Community Vendor Assessment Toolkit (HECVAT) (opens in new tab).
The risk assessment should be completed/updated using the latest version available from Higher Education Community Vendor Assessment Toolkit (HECVAT) (opens in new tab).
It should be completed when a vendor begins engaging with CAUDIT to provide sponsorship, partnership or value to CAUDIT members, and should be updated on an annual basis.
CAUDIT acknowledges the Traditional Owners of the lands where we live, learn and work. We pay our respects to Elders past and present and celebrate the stories, culture and traditions of all First Nations people.