Vendor Risk
An inventory of vendors with access to your data or systems, a questionnaire sent by link, and exportable evidence for audits.
Last reviewed:
This is the module worth starting with: it produces something you can show a client or an auditor sooner than any other.
What it measures
Who has access to your data or systems from outside your company, and how well protected each one is. ISO 27001, SOC 2, and GDPR all require documented due diligence on vendors; this module produces it.
Each vendor receives a security questionnaire. They answer it through a link, with no account and nothing to install, and the system calculates a score from their answers.
How to set it up
- 1
Add the vendor
Name, contact email, access type (Data, Systems, or Both), criticality (Low, Medium, or High), and the internal owner — the person at your company who answers for that relationship.
- 2
Send the questionnaire
From the vendor's detail view. It reaches their contact email as a link with an expiry date. If it expires unanswered, you send a new one from the same screen.
- 3
Wait for the answer
The questionnaire moves through *Sent*, *In progress*, and *Completed*. On completion the score is calculated automatically and appears in the overview.
How to read the result
The score runs from 0 to 100 and maps to one of three labels:
| Score | Label | What it means |
|---|---|---|
| 80 – 100 | Low risk | The vendor reports reasonable controls on what was asked. |
| 50 – 79 | Medium risk | There are reported gaps worth discussing before widening their access. |
| 0 – 49 | High risk | Basic controls are missing. This is the group you handle first. |
Until a questionnaire is completed, the vendor shows as Not assessed — which is not the same as low risk. Each completed assessment also stores a plain-language executive summary of two or three lines, so you do not have to interpret answer by answer. The history keeps every prior assessment, which is what an auditor asks for when they want to see a program rather than a snapshot.
What to do with a finding
- Start with High criticality at high risk. That intersection is your real work list; the rest can wait for the next pass.
- Take the conversation to the internal owner, not straight to the vendor. Whoever signed that relationship has the leverage to ask for a change.
- Use the executive summary as your starting text for the email or the meeting. It is written for someone who is not in IT.
- Do not delete a vendor to "clean up" the board. An inactive vendor gets marked inactive: their history is part of your evidence.
The system alerts you on its own when an assessment approaches expiry — at 14 and 3 days — and when a High-criticality vendor's score degrades compared to the previous assessment.