Vendor risk assessments, performed by certified experts
You onboard the vendor. Our certified assessors collect the evidence, follow up with the vendor, perform the risk assessment at the depth its tier requires and follow findings through remediation. You see each vendor’s progress on the platform in near real time and keep final approval.
You make the decisions. We do the work.
The assessment runs on your own workspace, under your policy, and every step is visible to your team.
Your team
Onboard, oversee, approve
- Onboard the vendor with its business case, data types and tier
- Set the policy: tiers, evidence depth, cadence and sign-off
- Follow progress on the platform in near real time
- Approve the assessment and decide on any risk acceptance
VendRisk360 assessors
Collect, assess, follow up
- Request evidence through the vendor portal and follow up with the vendor
- Perform the risk assessment scaled to the vendor’s tier
- Second-expert quality review before delivery
- Raise findings and follow remediation with the vendor
Mix both: keep some vendors in-house on the Vendor Lifecycle Management Platform and hand others to us, by tier, business unit or backlog.
From onboarding to an approved assessment
Six steps, each one visible on the vendor record as it happens.
- 01You
Onboard the vendor
Add the vendor with its business case, the data it touches and its criticality tier. Your policy sets the scope, the evidence and the cadence.
- 02VendRisk360
We collect the evidence
We send the right requests through the vendor portal and follow up with the vendor until the evidence arrives, checking each item is complete, current and in scope.
- 03VendRisk360
A certified assessor performs the assessment
An assessor reviews the evidence against your control set at the depth the vendor’s tier requires, and records ratings, findings and notes on the vendor record.
- 04VendRisk360
A second expert checks the work
A separate reviewer quality-checks findings and ratings before anything reaches you, so no assessment rests on one person.
- 05Together
Findings go to remediation
We raise findings with the vendor and follow remediation to closure. Risk acceptance decisions stay with you.
- 06You
You approve, the record is complete
Your reviewer signs off. The assessment, evidence, work notes and audit trail live on the vendor record, ready for examiners and auditors.
The right depth for every vendor
Regulators expect diligence scaled to risk. Our assessors apply the depth and cadence your policy sets for each tier: Critical, Material or Low risk. Here is what that typically looks like.
Full assessment
- When it applies
- Supports a critical or important function or customer-facing operations, or handles regulated data at scale.
- Evidence
- SOC 1 and SOC 2 Type II reports, penetration test, BCP and DR test results, key policies, certificates, insurance and financials, with subservice and fourth-party analysis.
- Questionnaire
- Full depth, with follow-up questions where evidence is missing or exceptions were found.
- Cadence
- Set by your policy, for example every 12 months, with continuous monitoring in between.
Focused assessment
- When it applies
- Meaningful operational or data exposure, but a disruption would be contained and substitutable within tolerance.
- Evidence
- Security questionnaire, key certifications (for example ISO/IEC 27001 or a SOC 2 report) and targeted evidence for high-risk answers.
- Questionnaire
- Focused set scoped to data types and services.
- Cadence
- Set by your policy, for example every 24 months, with monitoring on key signals.
Streamlined review
- When it applies
- No access to sensitive data or systems, and low operational impact if the service stops.
- Evidence
- Vendor attestation, sanctions screening and public-source checks.
- Questionnaire
- Short attestation.
- Cadence
- Set by your policy, for example at contract renewal, or earlier if scope or data types change.
The tier definitions above are an example of common practice. Your policy sets the criteria, evidence depth, cadence and sign-off for each tier.
Every SOC report reviewed the way an auditor would
A clean opinion is the start of a SOC review, not the end. The value is in what the report excludes and what it expects you to do. Every assessment that relies on a SOC 1 or SOC 2 report covers all of it.
What the assessor covers
- Report type (SOC 1 or SOC 2, Type I or Type II), the period covered and its currency, including bridge letters
- Scope and the services covered, checked against your relationship
- Auditor opinion, including any qualification
- Exceptions and deviations noted in testing, with management’s response
- Subservice organizations, and whether the carve-out or inclusive method applies
- Complementary user entity controls (CUECs) mapped to your own controls
Exceptions
Carve-outs
Subservice organizations
CUECs
AI is an option you choose. The assessment is done by experts.
AI is off unless you opt in. Where you do, it assists our assessors in exactly two places. Every review, rating and sign-off is performed by a certified assessor, and you can choose expert-only assessments at any time.
Completeness checks and key-date extraction on evidence
Expiration and effective dates, the period covered, the issuer, the document type and the scope are extracted, and missing, expired or out-of-scope items are flagged for follow-up.
An AI-assisted first pass on SOC reports
A first pass over the SOC report that the assessor verifies, corrects and completes before anything is recorded.
People decide, always
AI does not rate risk, raise findings or sign off. The assessor, the second-expert reviewer and your approver are named in the audit trail.
Every gap followed to a decision
A finding without an owner and a date is a note. Our assessors raise each one with the vendor and follow it until it closes, or until you formally accept the risk.
Findings with severity and evidence
Each finding records the control, the evidence behind it, the severity and why.
Remediation followed up with the vendor
Plans, milestones and due dates agreed with the vendor and worked through the vendor portal, with our team following up.
Risk acceptance stays with you
Rationale, compensating controls, approver authority and an expiry date, decided by your organization.
Reassessment on your cadence
Vendors are reassessed on the cadence your policy sets, or earlier when a monitoring signal or a scope change calls for it.
Never ask for a status update again
An assessment service should not be a black box. Every vendor shows where it is, what is outstanding and who is working on it, on the same platform your team and your board already use.
- Stage for every vendor: requested, collected, assessing, quality review, delivered
- Open evidence requests and vendor follow-ups, with dates
- Assigned assessor and their credentials
- Findings and remediation status as soon as they are raised
- Portfolio view across tiers, business units and regions for executive reporting
Certified, experienced assessors
Our assessors combine security, audit and risk credentials with hands-on experience in regulated programs, so the questions your examiners ask are answered before they ask them.
Security architecture, operations and engineering across all domains
Information systems audit, control testing and evidence evaluation
Security program management and governance
IT risk identification, assessment and response
Auditing information security management systems
Designing and operating ISMS controls
Cardholder data environments and service provider controls
Banking, credit unions, payments, healthcare and SaaS programs, plus other relevant credentials such as cloud security and privacy
Built to stand up to an examiner
Examiners and internal audit ask who performed the work, who checked it and who approved it. The answer is on the record.
- Second-expert quality review on every assessment, with segregation of duties recorded
- Your reviewer approves the assessment; the same person cannot complete two stages
- Sign-off certificate recording each approver, timestamp and evidence set
- Assessment report exported as PDF for the file and the committee
You keep accountability
Your reviewers approve assessments and risk acceptances. We do the work; you make the decisions regulators hold you to.
Second-expert review
A separate assessor quality-checks every assessment before delivery.
Evidence stays in your tenant
Evidence, notes and reports live on your vendor records, protected by SSO, MFA and tenant isolation.
Complete work papers
Every request, review, rating and approval is in the audit trail and exportable for internal audit.
Scoped to your policy, your tiers and your backlog
Start with the vendors that matter most, clear a backlog before an exam, or hand over the whole cycle. Scope and cadence follow the policy configured in your workspace.
- Evidence requests, collection and completeness checks
- Vendor follow-up through the vendor portal
- Security and risk questionnaires administered and reviewed
- SOC 1 and SOC 2 report review: exceptions, carve-outs, subservice organizations and CUEC mapping
- Risk assessment and residual risk rating against your control set, scaled to the tier
- Second-expert quality review before delivery
- Findings raised and remediation followed up with the vendor
- Reassessments on the cadence your policy sets for each tier
Works with the rest of VendRisk360
Vendor Lifecycle Management Platform
Manage vendors, request evidence, review, record and sign off
Learn moreVendor lifecycle
Intake to offboarding in one governed record
Learn moreNth-Party Intelligence
Fourth parties, concentration and systemic risk, CUECs
Learn moreBoard & Executive Reporting
Board packs, executive briefings and examiner-ready exports
Learn moreContinuous Monitoring
Outside-in monitoring: attack surface, shadow infrastructure, compromise
Learn moreReport-Specific Reviews
SOC report, information security and business continuity reviews
Learn moreAssessment services questions
Who stays accountable for our third-party risk?
You do. Regulators are consistent that accountability for third-party risk cannot be outsourced, whether under the US Interagency guidance, DORA, APRA CPS 230 or RBI and MAS outsourcing rules. VendRisk360 assessors do the work, and your reviewers approve every assessment and every risk acceptance on the platform.
What does the assessment cover for each tier?
Depth scales with the vendor’s tier. Critical vendors typically get a full assessment with SOC reports, penetration tests, BCP and DR tests and financials. Material vendors get a focused assessment. Low-risk vendors get a streamlined review. Your own policy sets the evidence depth, cadence and sign-off for each tier, and our assessors work to it.
Can we run some vendors ourselves and hand others to you?
Yes. You decide the scope: the whole portfolio, a tier such as your Critical vendors, a business unit, or a backlog you need cleared. Vendors your team assesses on the Vendor Lifecycle Management Platform and vendors we assess sit side by side in the same records and the same reporting.
How do we see progress?
Every vendor in scope shows its stage on the platform in near real time: evidence requested, evidence received, assessment in progress, quality review and delivered, with open requests, the assigned assessor and the latest activity.
Is AI used in our assessments?
Only if you choose it. AI is an optional capability. Where you opt in, it assists in two places: completeness checks and key-date extraction on vendor evidence, and an AI-assisted first pass on SOC reports that the assessor verifies. Every review, rating and sign-off is performed by a certified assessor, and you can choose expert-only assessments.
What if we only need one report reviewed?
Order a Report-Specific Review instead: a SOC Report Review, an Information Security Program Review or a Business Continuity Program Review, each with a written review report. They are available standalone or alongside the platform and these services.
What do our vendors experience?
A single, professional request through the VendRisk360 vendor portal, with clear instructions and follow-ups from our team. Vendors answer once, upload evidence once, and see what is still outstanding.
Can our internal auditors and examiners review the work?
Yes. The evidence, assessor notes, quality review, findings, approvals and the full audit trail stay on the vendor record in your tenant, and can be exported as an examiner package.
Hand us the vendors. Keep the visibility.
Tell us about your portfolio, your regulators and your backlog, and we will propose an assessment scope built around your policy.