Vendor assessments
TPRM → Assessments
A TPRM assessment is not an analyst dragging a slider to a number. It is a chain a regulator can follow:
inherent risk → control effectiveness → residual → rating
(tiering) (validated questionnaire) (rollup) (band)
Control effectiveness is derived from questionnaire answers — it is never typed in. Every domain score traces back to the weighted answers that produced it.
1. Create the assessment
New Assessment, choosing the vendor and the type:
| Type | When |
|---|---|
| Initial | First time you assess this vendor. |
| Periodic | The scheduled re-assessment. |
| Event driven | Something happened — a breach, a change of ownership. |
| Reassessment | Re-running after remediation. |
2. Attach a questionnaire
On the Domains tab, attach a questionnaire. This freezes a published template version onto the assessment, so later edits to the template never change an assessment already under way. What you assessed against stays what you assessed against.
3. Collect the answers
Two routes, and you can mix them.
Answer internally — work through the runner yourself, attaching evidence as you go.
Send to the vendor — from the Collection tab, issue a tokenised magic link. The vendor opens it with no login, fills the questionnaire (drafts autosave) and submits.
Anyone holding the link can answer the questionnaire. Send it to the named contact, not to a shared mailbox, and re-issue rather than forward.
4. Validate every vendor answer
This is the control that makes the score defensible. Vendor-submitted answers
arrive as vendor_submitted and do not count toward the score. On the
Collection tab you accept or reject each one:
- Accept → the answer counts.
- Reject → it is excluded, and the vendor's claim stays on the record alongside your rejection.
An assessment where the vendor answered everything and the assessor validated nothing scores as though nothing was answered. That is deliberate — a vendor's self-assertion is not assurance until someone checked it.
5. Scores recompute
Accepting or rejecting recomputes automatically: answers roll into section scores, sections into domains, domains into residual, residual into a rating band. Nothing to press.
6. Sign off
Preparer → reviewer → approver, the same chain as compliance, and it freezes the record as a point-in-time assessment.
Assessment states
scoping → collection → review → scoring → pending_approval → completed
with expired when it ages out and superseded when a newer assessment
replaces it. A superseded assessment is kept, not deleted — it is the evidence
of what you knew at the time.