Vendor risk assessment
Third-party reviews with the evidence collected
How a run goes
The steps this agent takes, in order, and what each one leaves behind.
Reads the vendor's submission and supporting documents
Runs the third-party risk questionnaire for a new or renewing vendor and collects the evidence for each answer
Scores each control area against the policy
Scores the vendor against the risk tiers and lists the gaps that need a remediation plan
Drafts the assessment and the follow-up schedule
Drafts the assessment for the risk committee and sets the next review date
Works in

ServiceNow, Box, Okta
What it does
- Runs the third-party risk questionnaire for a new or renewing vendor and collects the evidence for each answer
- Scores the vendor against the risk tiers and lists the gaps that need a remediation plan
- Drafts the assessment for the risk committee and sets the next review date
Connects to
Need it to work differently?
Every agent can be changed: the steps it takes, the systems it uses and who approves what.