Skip to content
Comprehensive Vendor Risk Assessment Services

Vendor risk assessments, performed by certified experts

You onboard the vendor. Our certified assessors collect the evidence, follow up with the vendor, perform the risk assessment at the depth its tier requires and follow findings through remediation. You see each vendor’s progress on the platform in near real time and keep final approval.

Who does what

You make the decisions. We do the work.

The assessment runs on your own workspace, under your policy, and every step is visible to your team.

Your team

Onboard, oversee, approve

  • Onboard the vendor with its business case, data types and tier
  • Set the policy: tiers, evidence depth, cadence and sign-off
  • Follow progress on the platform in near real time
  • Approve the assessment and decide on any risk acceptance

VendRisk360 assessors

Collect, assess, follow up

  • Request evidence through the vendor portal and follow up with the vendor
  • Perform the risk assessment scaled to the vendor’s tier
  • Second-expert quality review before delivery
  • Raise findings and follow remediation with the vendor

Mix both: keep some vendors in-house on the Vendor Lifecycle Management Platform and hand others to us, by tier, business unit or backlog.

How it works

From onboarding to an approved assessment

Six steps, each one visible on the vendor record as it happens.

  1. 01
    You

    Onboard the vendor

    Add the vendor with its business case, the data it touches and its criticality tier. Your policy sets the scope, the evidence and the cadence.

  2. 02
    VendRisk360

    We collect the evidence

    We send the right requests through the vendor portal and follow up with the vendor until the evidence arrives, checking each item is complete, current and in scope.

  3. 03
    VendRisk360

    A certified assessor performs the assessment

    An assessor reviews the evidence against your control set at the depth the vendor’s tier requires, and records ratings, findings and notes on the vendor record.

  4. 04
    VendRisk360

    A second expert checks the work

    A separate reviewer quality-checks findings and ratings before anything reaches you, so no assessment rests on one person.

  5. 05
    Together

    Findings go to remediation

    We raise findings with the vendor and follow remediation to closure. Risk acceptance decisions stay with you.

  6. 06
    You

    You approve, the record is complete

    Your reviewer signs off. The assessment, evidence, work notes and audit trail live on the vendor record, ready for examiners and auditors.

Scaled to the tier

The right depth for every vendor

Regulators expect diligence scaled to risk. Our assessors apply the depth and cadence your policy sets for each tier: Critical, Material or Low risk. Here is what that typically looks like.

Critical

Full assessment

When it applies
Supports a critical or important function or customer-facing operations, or handles regulated data at scale.
Evidence
SOC 1 and SOC 2 Type II reports, penetration test, BCP and DR test results, key policies, certificates, insurance and financials, with subservice and fourth-party analysis.
Questionnaire
Full depth, with follow-up questions where evidence is missing or exceptions were found.
Cadence
Set by your policy, for example every 12 months, with continuous monitoring in between.
Material

Focused assessment

When it applies
Meaningful operational or data exposure, but a disruption would be contained and substitutable within tolerance.
Evidence
Security questionnaire, key certifications (for example ISO/IEC 27001 or a SOC 2 report) and targeted evidence for high-risk answers.
Questionnaire
Focused set scoped to data types and services.
Cadence
Set by your policy, for example every 24 months, with monitoring on key signals.
Low risk

Streamlined review

When it applies
No access to sensitive data or systems, and low operational impact if the service stops.
Evidence
Vendor attestation, sanctions screening and public-source checks.
Questionnaire
Short attestation.
Cadence
Set by your policy, for example at contract renewal, or earlier if scope or data types change.

The tier definitions above are an example of common practice. Your policy sets the criteria, evidence depth, cadence and sign-off for each tier.

SOC reports, read properly

Every SOC report reviewed the way an auditor would

A clean opinion is the start of a SOC review, not the end. The value is in what the report excludes and what it expects you to do. Every assessment that relies on a SOC 1 or SOC 2 report covers all of it.

What the assessor covers

  • Report type (SOC 1 or SOC 2, Type I or Type II), the period covered and its currency, including bridge letters
  • Scope and the services covered, checked against your relationship
  • Auditor opinion, including any qualification
  • Exceptions and deviations noted in testing, with management’s response
  • Subservice organizations, and whether the carve-out or inclusive method applies
  • Complementary user entity controls (CUECs) mapped to your own controls

Exceptions

Deviations the service auditor found are recorded with the control, the test and management’s response, and raised as findings sized to their relevance to you.

Carve-outs

Where a subservice organization’s controls are carved out, the gap is flagged so assurance is obtained over it instead of assumed.

Subservice organizations

Data centers, cloud platforms and processors named in the report are added as fourth parties on the vendor’s relationship map.

CUECs

The controls the report assumes you operate are listed and mapped to your own controls, with owners and gaps tracked.
Need one report reviewed? See Report-Specific Reviews
Where AI helps (optional)

AI is an option you choose. The assessment is done by experts.

AI is off unless you opt in. Where you do, it assists our assessors in exactly two places. Every review, rating and sign-off is performed by a certified assessor, and you can choose expert-only assessments at any time.

Completeness checks and key-date extraction on evidence

Expiration and effective dates, the period covered, the issuer, the document type and the scope are extracted, and missing, expired or out-of-scope items are flagged for follow-up.

An AI-assisted first pass on SOC reports

A first pass over the SOC report that the assessor verifies, corrects and completes before anything is recorded.

People decide, always

AI does not rate risk, raise findings or sign off. The assessor, the second-expert reviewer and your approver are named in the audit trail.

Findings and remediation

Every gap followed to a decision

A finding without an owner and a date is a note. Our assessors raise each one with the vendor and follow it until it closes, or until you formally accept the risk.

Findings with severity and evidence

Each finding records the control, the evidence behind it, the severity and why.

Remediation followed up with the vendor

Plans, milestones and due dates agreed with the vendor and worked through the vendor portal, with our team following up.

Risk acceptance stays with you

Rationale, compensating controls, approver authority and an expiry date, decided by your organization.

Reassessment on your cadence

Vendors are reassessed on the cadence your policy sets, or earlier when a monitoring signal or a scope change calls for it.

Near real-time visibility

Never ask for a status update again

An assessment service should not be a black box. Every vendor shows where it is, what is outstanding and who is working on it, on the same platform your team and your board already use.

  • Stage for every vendor: requested, collected, assessing, quality review, delivered
  • Open evidence requests and vendor follow-ups, with dates
  • Assigned assessor and their credentials
  • Findings and remediation status as soon as they are raised
  • Portfolio view across tiers, business units and regions for executive reporting
Your vendor assessments are in the right hands

Certified, experienced assessors

Our assessors combine security, audit and risk credentials with hands-on experience in regulated programs, so the questions your examiners ask are answered before they ask them.

CISSP

Security architecture, operations and engineering across all domains

CISA

Information systems audit, control testing and evidence evaluation

CISM

Security program management and governance

CRISC

IT risk identification, assessment and response

ISO/IEC 27001 Lead Auditor

Auditing information security management systems

ISO/IEC 27001 Lead Implementer

Designing and operating ISMS controls

PCI DSS implementation

Cardholder data environments and service provider controls

Industry experience

Banking, credit unions, payments, healthcare and SaaS programs, plus other relevant credentials such as cloud security and privacy

Quality and sign-off

Built to stand up to an examiner

Examiners and internal audit ask who performed the work, who checked it and who approved it. The answer is on the record.

  • Second-expert quality review on every assessment, with segregation of duties recorded
  • Your reviewer approves the assessment; the same person cannot complete two stages
  • Sign-off certificate recording each approver, timestamp and evidence set
  • Assessment report exported as PDF for the file and the committee

You keep accountability

Your reviewers approve assessments and risk acceptances. We do the work; you make the decisions regulators hold you to.

Second-expert review

A separate assessor quality-checks every assessment before delivery.

Evidence stays in your tenant

Evidence, notes and reports live on your vendor records, protected by SSO, MFA and tenant isolation.

Complete work papers

Every request, review, rating and approval is in the audit trail and exportable for internal audit.

What the service covers

Scoped to your policy, your tiers and your backlog

Start with the vendors that matter most, clear a backlog before an exam, or hand over the whole cycle. Scope and cadence follow the policy configured in your workspace.

  • Evidence requests, collection and completeness checks
  • Vendor follow-up through the vendor portal
  • Security and risk questionnaires administered and reviewed
  • SOC 1 and SOC 2 report review: exceptions, carve-outs, subservice organizations and CUEC mapping
  • Risk assessment and residual risk rating against your control set, scaled to the tier
  • Second-expert quality review before delivery
  • Findings raised and remediation followed up with the vendor
  • Reassessments on the cadence your policy sets for each tier
FAQ

Assessment services questions

Who stays accountable for our third-party risk?

You do. Regulators are consistent that accountability for third-party risk cannot be outsourced, whether under the US Interagency guidance, DORA, APRA CPS 230 or RBI and MAS outsourcing rules. VendRisk360 assessors do the work, and your reviewers approve every assessment and every risk acceptance on the platform.

What does the assessment cover for each tier?

Depth scales with the vendor’s tier. Critical vendors typically get a full assessment with SOC reports, penetration tests, BCP and DR tests and financials. Material vendors get a focused assessment. Low-risk vendors get a streamlined review. Your own policy sets the evidence depth, cadence and sign-off for each tier, and our assessors work to it.

Can we run some vendors ourselves and hand others to you?

Yes. You decide the scope: the whole portfolio, a tier such as your Critical vendors, a business unit, or a backlog you need cleared. Vendors your team assesses on the Vendor Lifecycle Management Platform and vendors we assess sit side by side in the same records and the same reporting.

How do we see progress?

Every vendor in scope shows its stage on the platform in near real time: evidence requested, evidence received, assessment in progress, quality review and delivered, with open requests, the assigned assessor and the latest activity.

Is AI used in our assessments?

Only if you choose it. AI is an optional capability. Where you opt in, it assists in two places: completeness checks and key-date extraction on vendor evidence, and an AI-assisted first pass on SOC reports that the assessor verifies. Every review, rating and sign-off is performed by a certified assessor, and you can choose expert-only assessments.

What if we only need one report reviewed?

Order a Report-Specific Review instead: a SOC Report Review, an Information Security Program Review or a Business Continuity Program Review, each with a written review report. They are available standalone or alongside the platform and these services.

What do our vendors experience?

A single, professional request through the VendRisk360 vendor portal, with clear instructions and follow-ups from our team. Vendors answer once, upload evidence once, and see what is still outstanding.

Can our internal auditors and examiners review the work?

Yes. The evidence, assessor notes, quality review, findings, approvals and the full audit trail stay on the vendor record in your tenant, and can be exported as an examiner package.

Get started

Hand us the vendors. Keep the visibility.

Tell us about your portfolio, your regulators and your backlog, and we will propose an assessment scope built around your policy.