Vendor risk assessments your vendors actually complete.
Send SIG, CAIQ, or custom security assessments through a portal built for the vendor on the other end, with AI-assisted responses when they opt in. Responses are auto-scored against your criteria, validated by your reviewers, and carried straight into remediation on the same vendor record. Built to cut assessment cycle time by more than half compared to spreadsheet and email chases, an illustrative target.
From sent to scored to remediated, on one record.
SIG, CAIQ, and custom templates
Start from industry-standard SIG or CAIQ templates or build custom assessments matched to your own criteria and vendor tiers. Scope the depth to the vendor's criticality so a low-risk supplier is not answering 300 questions.
- SIG and CAIQ templates ready to send
- Custom questionnaires built to your criteria
- Assessment depth scoped by vendor tier
A portal vendors want to finish
Vendors respond in a dedicated portal with clear progress and the ability to attach evidence inline. When a vendor opts in, AI-assisted drafting helps them answer faster from their own documentation. Faster completion for them means faster closure for you.
- Dedicated vendor portal with progress tracking
- AI-assisted vendor responses, strictly opt-in
- Evidence attached inline as they answer
Automatic scoring against your criteria
Every response is scored automatically against the criteria you defined, not a generic rubric. Weak or contradictory answers are flagged for follow-up, and the assessed posture feeds the vendor's three-layer risk score alongside criticality and live exposure.
- Scoring runs against your defined criteria
- Weak and contradictory answers flagged
- Assessed posture feeds the vendor risk score
Evidence collected, not just claimed
Assessments collect the artifacts behind the answers: certifications, reports, policies, attestations. Evidence attaches to the specific response and to the vendor record, so a claim and its proof never separate. Once linked to an approved assessment, evidence is immutable.
- Evidence requested per question, not per email
- Artifacts linked to both response and vendor record
- Immutable once linked to an approved assessment
Reviewer validation with final say
AI scoring accelerates the read, but your reviewers hold precedence. A reviewer can override any AI score, and the override always wins. Every decision is attributed and audit-logged, which is what makes the result defensible when someone asks how a vendor was approved.
- Reviewer decisions always override AI scores
- Every override attributed and audit-logged
- Approval trail defensible to auditors
Remediation and reassessment, connected
Failed criteria generate remediation tasks that vendors track and close in the same portal. When a reassessment completes, it resets the continuous monitoring baseline, so assessments and monitoring stay one connected program instead of two disconnected calendars.
- Remediation tasks generated from failed criteria
- Vendors close tasks in the same portal
- Completed reassessments reset the monitoring baseline
Three steps from setup to value.
Build and send
Pick SIG, CAIQ, or a custom template, scope it to the vendor's tier, and send it through the vendor portal. The vendor gets a clear task list, not a spreadsheet attachment.
Score and validate
Responses are auto-scored against your criteria as they arrive, with evidence attached inline. Your reviewers validate the results, and their decisions always override the AI.
Remediate and reassess
Findings become remediation tasks on the same vendor record, tracked to closure in the portal. Each completed reassessment re-anchors continuous monitoring, so the next year is covered too.
This page covers the assessments you send to vendors. For the security questionnaires your customers send to you, see the Questionnaire Engine, which drafts cited answers from your own controls and evidence. And for what happens in the months after an assessment closes, see Continuous Vendor Monitoring.