Skip to content

Vendor Risk Assessment

Vendor risk assessment illustration

Vendor risk assessment is a core GRC activity — understanding the security posture of your third-party relationships is essential for protecting your organisation. The SCF Controls Platform assesses vendors through a single AI-powered pipeline that follows a simple lifecycle:

Add → Assess → Decide → Review

  1. Add the vendor to your registry (see Vendor Management)
  2. Assess — run an AI assessment that researches the vendor online and produces a full risk report
  3. Decide — act on the recommendation, conditions, and action items
  4. Review — re-assess annually; the platform tracks when each vendor’s review falls due

Each vendor carries one authoritative risk score, always traceable to the assessment that produced it.

The AI assessment researches the vendor’s public security posture — certifications (ISO 27001, SOC 2), breach history, published vulnerabilities (CVEs), and regulatory enforcement actions — then evaluates the vendor against a structured framework covering the CIA triad (Confidentiality, Integrity, Availability), data protection risk, and a 5×5 risk matrix. The output is a complete assessment report with a traffic-light rating, an approval recommendation, and a defensible risk score.

Where the platform has already collected research signals for the vendor (breach data from HIBP, CVE data from NVD, CISA KEV entries, regulatory findings), these are fed into the assessment as additional context automatically.

  1. Open the vendor’s detail page from the Vendor Registry
  2. Click the primary action button in the header — labelled Run AI assessment for a first assessment, Run annual review when a review is due, or Re-run assessment otherwise
  3. Complete the short form and click Start assessment
FieldRequiredDescription
Assessment TypeYesInitial assessment, Annual review, or Ad hoc reassessment. Pre-selected based on where the vendor is in its lifecycle.
Data RoleYesThe vendor’s data role for your organisation: Processor, Controller, or Joint Controller
Services UsedYesWhat services the vendor provides to you (pre-filled from the vendor description)
Additional ContextNoAnything else the AI assessor should take into account

The assessment runs in the background and typically takes a couple of minutes. The Assess tab shows live progress — first Assessment queued, then Researching vendor online — and the page checks for completion automatically every few seconds. You can navigate away and return later; the completed report is saved to the vendor record.

If a run fails, the error is shown on the Assess tab with a Try again button. A failed run never overwrites the vendor’s existing risk score or previous reports.

When the assessment completes, the Assess tab shows the full report. The summary strip at the top displays:

  • RAG Status — a traffic-light rating:
    • GREEN — low risk: certifications current, clean record, strong controls
    • AMBER — medium risk: certifications present but concerns exist (past breaches, CVEs, gaps)
    • RED — critical or high risk: missing required certifications or active unresolved issues
  • Recommendation — Approve, Conditional Approval, or Reject
  • Risk Score — the residual risk score (1–25)
SectionContents
Executive SummaryNarrative overview of the vendor’s security posture and the key risk drivers
Key FindingsThe most significant individual findings from the research
Risk AnalysisInherent risk score and level, control effectiveness (%), and residual risk score and level, plus the individual inherent risk factors with likelihood × impact scoring
CIA Triad ControlsPer-pillar scores (out of 5) for Confidentiality, Integrity, and Availability, with the individual controls assessed under each pillar and their ratings
CertificationsCertifications found during research (ISO 27001 and SOC 2 Type II are treated as the minimum bar), with status and validity
Breach, CVE & Regulatory HistoryKnown data breaches, published vulnerabilities, and regulatory enforcement actions
Conditions for UseConditions attached to a conditional approval
Mandatory ActionsRemediation actions required, with priority, owner, and due date
Ongoing MonitoringMonitoring requirements for the vendor relationship
Research SourcesThe web sources consulted during the assessment, so every finding is traceable

You can toggle the full-text report view to read the complete report as a formatted document, and download it as Markdown for sharing, audit evidence, or version control.

The assessment scores risk on a 5×5 matrix: each risk factor is rated for likelihood (1–5) and impact (1–5), and the overall score is likelihood × impact (1–25).

Score RangeRisk LevelMeaning
1–7LowAccept with standard monitoring
8–14MediumAccept with compensating controls
15–19HighRemediation required before engagement
20–25CriticalDo not proceed without executive approval

The report distinguishes the vendor’s raw exposure from the risk that remains after their controls are taken into account:

Risk TypeDefinition
Inherent RiskThe vendor’s risk exposure before considering their security controls
Control EffectivenessHow effectively the vendor’s controls and certifications mitigate that exposure (0–100%)
Residual RiskThe remaining risk after controls — this is the vendor’s authoritative risk score

See Risk Management for more on the inherent vs residual risk concept.

Each vendor has exactly one risk score, shown consistently in the vendor registry and in the vendor detail header. It is updated only when an assessment completes successfully, and the platform records where it came from:

  • The header shows the score with its RAG colour (for example, Risk 12 · AMBER)
  • The provenance line underneath reads Assessed <date> · Review due <date> — so you always know how current the score is and which assessment produced it

A pending, running, or failed assessment never changes the score.

The Decide tab collects everything needed to make and manage the engagement decision.

The recommendation from the latest completed assessment is shown with its executive summary and, for conditional approvals, the conditions for use — the specific terms under which the vendor should be engaged.

RecommendationTypical Basis
ApproveGREEN status, required certifications in place, no significant concerns
Conditional ApprovalAMBER status — certifications present but conditions attach to continued use
RejectRED status, missing required certifications, or unacceptable risk

The recommendation is advisory. Record your organisation’s actual decision by setting the vendor’s status (for example, Approved or Suspended) — see Vendor Status Lifecycle.

Mandatory actions from the assessment report are created automatically as action items, each with a priority, owner, and due date. You can also add your own manually.

PriorityDescription
CriticalRequires immediate attention — blocking risk
HighShould be addressed within days
MediumAddress within the normal review cycle
LowAddress when resources allow

Use the status dropdown in the table to move items through OpenIn ProgressCompleted.

Where the vendor cannot fully meet a requirement, document the gap and the compensating control your organisation has put in place, with an effectiveness rating:

RatingDescription
FullCompensating control fully addresses the gap
PartialGap is partially mitigated — some residual risk remains
MinimalLimited mitigation — significant residual risk

When an assessment completes, the platform automatically schedules the next annual review for 12 months later. The review date drives visible status badges:

StatusMeaning
(no badge)Review is more than 30 days away
Due soon (amber)Review falls due within the next 30 days
Overdue (red)The review date has passed

Badges appear in the vendor registry’s review column and in the vendor detail header, so vendors needing attention are visible at a glance. When a review is due, the header action becomes Run annual review — running it produces a fresh report, updates the risk score, and schedules the next review.

The Review tab also shows the full assessment history: every assessment with its type, date, status, risk score, RAG status, and recommendation, so you can see how the vendor’s posture has changed over time.

  • All vendors — run an initial assessment when the vendor is added, and let the annual review cycle keep it current
  • Critical vendors — run an ad hoc reassessment after any security incident, major breach disclosure, or significant contract change
  • Due soon / overdue badges — treat these as your review work queue; clear them by running the annual review
  1. Describe services accurately — the Services Used field frames the whole assessment
  2. Set the correct data role — Controller vs Processor materially changes the data protection analysis
  3. Use additional context — contract specifics, data volumes, or known concerns sharpen the findings
  4. Record certifications you hold evidence for — tracked certifications complement what the assessment finds online
  1. Track action items to completion — open remediation tasks represent unmanaged risk
  2. Document compensating controls — show auditors how you mitigate vendor gaps
  3. Download reports for your audit trail — the Markdown report is suitable for evidence packs and board reporting
  4. Reflect decisions in vendor status — keep the lifecycle status aligned with the latest recommendation