Vendor risk and questionnaire AI

What triggers a vendor risk assessment, how public security documents are gathered, how the risk level is derived, and how questionnaire answers and reviews are drafted by AI.

Summary

  • Every vendor gets one AI risk assessment when it is created, when its name, description, category, or website changes, and from a daily sweep that picks up vendors never assessed. A fingerprint of those four fields stops the assessment from running again when nothing changed.
  • The risk level shown in the register is not stored. It is derived from the likelihood and impact you set: 15 or more is High, 8 to 14 is Medium, 7 or less is Low.
  • Questionnaire AI drafts, it does not decide. Suggested answers come from the vendor's own published documents, and the review score is a proposal a reviewer approves, rejects, or sends back, question by question.

Concepts

TermMeaning
Assessment inputsThe vendor's name, description, category, and website. Only these four fields feed the AI assessment and only a change to them triggers a new one.
Assessment dateWhen the AI last assessed the vendor. A vendor without one is "unassessed" and is what the daily sweep looks for.
StatusNot Assessed, In Progress, or Assessed on the vendor record. This is your workflow field; the AI assessment never changes it.
Vendor evidenceDocuments on the vendor's Evidence tab, with source Assessment, Manual upload, or AI-gathered.
AssignmentOne questionnaire template sent to one vendor: PendingIn ProgressSubmittedReviewed, or Expired when the portal link lapses.
Fulfillment scoreThe AI review's 0–100 estimate of how completely the answers address the questions.

How it works

What triggers a risk assessment

TriggerWhat happens
Vendor createdAn assessment is queued immediately.
Vendor edited with a change to name, description, category, or websiteAn assessment is queued. Other edits (contacts, evidence, DPA status, owner) queue nothing.
Daily sweepEvery vendor with no assessment date, in every organization, is queued once.
Regenerate risks on the vendor's hero menuThe AI first extracts vendors from your organization context and creates any that are missing, then assesses every unassessed vendor in the organization. It is skipped entirely when the context has no questions and answers.

Only one assessment per vendor is in flight at a time; a second trigger joins the existing run. Failed runs are retried automatically.

The change-detection gate

Each assessment stores, alongside its date, a fingerprint of the four input fields. Every trigger recomputes the fingerprint and compares it with the stored one; when they match, the run ends without calling the AI and without changing the record. This is deliberately change-only: an assessment is never redone because it is old, only because its inputs moved. Correcting a vendor's website is enough to get a fresh one.

Gathering public security documents

Before drafting, the assessment looks for the vendor's public security material starting from the Website field: trust or security pages, published certifications and report summaries, privacy and security policies. Everything is fetched from the vendor's own site. Each document found is stored as vendor evidence with an AI-gathered source, together with the text that was read, so later questionnaire suggestions can cite it as a Source Document. The step never signs in, never requests documents behind an NDA portal, and never contacts the vendor. A vendor with no website is still assessed from its name and description; expect a thinner narrative.

Drafting the risk narrative

The AI drafts the five text fields on the Risk tab (Risk Summary, Security Posture, Compliance Status, Risk Mitigation, Monitoring Requirements) and sets the assessment date. The Inherent Risk and Residual Risk probability and impact selectors are yours; the text informs that judgement, it does not replace it. A later Regenerate risks run overwrites the drafted text, including your edits.

How the risk level is computed

Vendors use the same 1–5 likelihood and impact scales as the risk register, with their own cut-offs:

Vendor risk levelLikelihood × impact
High15 or more
Medium8–14
Low7 or less

The level is recomputed whenever the record is read, so changing either selector changes the level everywhere at once; inherent and residual are computed from their own pair. A pair that is high on a risk can be medium on a vendor; see Risk scoring and reports.

Questionnaire answer suggestions

When a questionnaire is assigned, the AI reads the vendor's AI-gathered documents and proposes an answer per question, each with High, Medium, or Low Confidence and the Source Documents it drew on. Proposals below a confidence floor are not shown. The vendor sees them in the portal as "AI-suggested answers" and can accept, edit, or ignore each one. Nothing is submitted on the vendor's behalf.

Review scoring

On submission, and whenever you rerun it from the review dialog, the AI scores the submission against the questions and the gathered documents, producing the Fulfillment Score, an Analysis, and Concerns. That output is advisory. The assignment only reaches Reviewed when a person has decided every question:

DecisionEffect
ApproveThe answer is accepted as evidence.
ClarifyThe vendor is emailed; the assignment returns to In Progress and only the clarified questions reopen.
RejectThe answer is recorded as unacceptable; nothing is sent.

Vendor documents, answers, and your review notes are never used to train a model, and every AI call runs under zero data retention at the model layer. The commitments are in the Terms and the DPA.

Edge cases and failure modes

  • A stale assessment does not refresh itself. If the inputs have not changed, neither has the assessment. Edit an input or use Regenerate risks.
  • The sweep only finds never-assessed vendors. A vendor assessed once and never edited is not picked up again.
  • The score measures completeness, not truth. A confident, well-cited answer can still be false; the AI has not read the contract or verified the certification.
  • Regeneration rewrites the narrative. Copy anything you want to keep out of the five fields before running it.

What you can influence

  • The four assessment inputs, which are the only way to trigger a fresh assessment short of Regenerate risks.
  • The Website field and at least one contact, which gathering and the questionnaire flow depend on.
  • Likelihood and impact on the Risk tab, which decide the level in the register.
  • Every review decision and its notes.

Last updated on