Skip to main content

Vendor assessments

TPRM → Assessments

A TPRM assessment is not an analyst dragging a slider to a number. It is a chain a regulator can follow:

inherent risk → control effectiveness → residual → rating
(tiering) (validated questionnaire) (rollup) (band)

Control effectiveness is derived from questionnaire answers — it is never typed in. Every domain score traces back to the weighted answers that produced it.

1. Create the assessment

New Assessment, choosing the vendor and the type:

TypeWhen
InitialFirst time you assess this vendor.
PeriodicThe scheduled re-assessment.
Event drivenSomething happened — a breach, a change of ownership.
ReassessmentRe-running after remediation.

2. Attach a questionnaire

On the Domains tab, attach a questionnaire. This freezes a published template version onto the assessment, so later edits to the template never change an assessment already under way. What you assessed against stays what you assessed against.

3. Collect the answers

Two routes, and you can mix them.

Answer internally — work through the runner yourself, attaching evidence as you go.

Send to the vendor — from the Collection tab, issue a tokenised magic link. The vendor opens it with no login, fills the questionnaire (drafts autosave) and submits.

The magic link is the credential

Anyone holding the link can answer the questionnaire. Send it to the named contact, not to a shared mailbox, and re-issue rather than forward.

4. Validate every vendor answer

This is the control that makes the score defensible. Vendor-submitted answers arrive as vendor_submitted and do not count toward the score. On the Collection tab you accept or reject each one:

  • Accept → the answer counts.
  • Reject → it is excluded, and the vendor's claim stays on the record alongside your rejection.
Only accepted answers move the score

An assessment where the vendor answered everything and the assessor validated nothing scores as though nothing was answered. That is deliberate — a vendor's self-assertion is not assurance until someone checked it.

5. Scores recompute

Accepting or rejecting recomputes automatically: answers roll into section scores, sections into domains, domains into residual, residual into a rating band. Nothing to press.

6. Sign off

Preparer → reviewer → approver, the same chain as compliance, and it freezes the record as a point-in-time assessment.

Assessment states

scoping → collection → review → scoring → pending_approval → completed

with expired when it ages out and superseded when a newer assessment replaces it. A superseded assessment is kept, not deleted — it is the evidence of what you knew at the time.