How to Generate Vendor Risk Reports

How to Generate Vendor Risk Reports

Overview

Vendor Pulse produces two kinds of report, and both are generated per vendor:

ReportFormatHow it is produced
ExecutivePDFYou add a remark and optional recipients, then generate
DetailedExcel workbookGenerated immediately, no extra input

Reports are built in the background and emailed to you when they are ready. You can also collect them later from the History tab. There is no portfolio-wide, all-vendors report.


Prerequisites

  • The report view permission (report:view)
  • The vendor you want to report on, with the assessment or risk data you expect to see in it
  • The digital risk permission (vendor:digital:view) if you want external attack surface data included

Generating a Report

Navigation: Sidebar → Reports

The Reports page has two tabs: Reports and History.

Step 1: Find the vendor

On the Reports tab you get a card for each vendor showing their logo, name and onboarding status. Use the search box to find a vendor, or the Onboarding Status filter to narrow the list.

Step 2: Choose the report

Each vendor card has two buttons.

Detailed produces the Excel workbook. Click it and generation starts straight away.

Executive produces the PDF. Clicking it opens a dialog where you:

  1. Enter your remark — free text that is carried into the report.
  2. Optionally enter one or more recipient email addresses. A maximum of five is allowed.
  3. Click Generate Report.

Step 3: Wait for the email

Generation is asynchronous. The platform confirms that the report is being generated and that you will receive it by email shortly.

The email goes to you, and copies go to the vendor's relationship manager and business owner where they are recorded, plus any addresses you entered in the Executive dialog.


Collecting Reports Later

Navigation: Sidebar → Reports → History

The History tab lists every report generated for your organisation:

ColumnMeaning
Vendor NameThe vendor the report covers
TypeExecutive or Detailed
StatusGenerating, Completed or Failed
Generated ByWho requested it
Generated OnWhen it was requested
RemarksThe remark entered at generation time (hover to read it in full)

Click a row with status Completed to open the report. Use the Report Type filter to show only Executive or only Detailed reports.

> The download link is time-limited. If an emailed link has stopped working, come back to the History tab and click the row again to get a fresh one.


What Is in the Detailed (Excel) Report

The workbook opens on a Report Summary sheet and then carries:

SheetContents
Report SummaryVendor Name, Primary Domain and Location, followed by an Overall Findings block counting vendor risks by severity, assessments completed, and — where digital risk is included — findings, discovered assets and GitHub patches
Vendor RisksOne row per risk, with Title, Description, Due Date, Status, Source, Likelihood, Impact, Exposure Score, Response Plan, Strategy, Mitigation, Control, Finding Name, Mitigation Plan and Risk Severity
One sheet per assessmentThe questions and responses for each assessment

Only assessments that are Ongoing or Completed are included — assessments that have not started yet are left out.

If you hold the digital risk permission and the vendor has external scan data, three further sheets are added:

SheetContents
FindingsExternal security findings
Discovered AssetsThe vendor's discovered internet-facing assets
Github PatchesPublic code references found for the vendor's domains, as clickable links

When digital risk is not included, the summary sheet says so explicitly rather than leaving the section blank.


Troubleshooting

I cannot see Reports in the sidebar, or the page is blocked → Generating and viewing reports requires report:view. Ask your administrator to grant it.

The report never arrived → Check the History tab. If the row says Generating, it is still being built. If it says Completed, click the row to open the report directly rather than waiting for the email, and check your spam folder.

The status says Failed → Regenerate the report. If it fails again, contact support with the vendor name and the time you tried.

The report has no external attack surface data → Those sheets only appear when you hold the digital risk permission (vendor:digital:view) and the vendor has scan data. Check the vendor has a primary domain and that a scan has completed on their Digital Risk tab.

An assessment is missing from the workbook → Only Ongoing and Completed assessments are included. An assessment that has been scheduled but not started will not appear.

The emailed download link no longer works → Links expire. Open the History tab and click the report row to get a new one.

I want one report covering all my vendors → Reports are generated per vendor. Generate them individually from each vendor's card.

A colleague received the report and I did not expect them to → Copies automatically go to the vendor's relationship manager and business owner in addition to any addresses typed into the Executive dialog.


Need more help? Contact support@zeron.one

    • Related Articles

    • Getting Started with Vendor Pulse

      Overview Vendor Pulse is Zeron's third-party risk management product. You add the vendors you work with, send them assessment questionnaires, review what comes back, and track the risks you find through to closure. This guide takes you from your ...
    • How to Review Vendor Risk Scores

      Overview Vendor Pulse shows vendor risk in three places, each answering a different question: Where Question it answers Profile tab on a vendor How risky is this vendor overall? Manage Risk tab on a vendor What specific risks are open, and who is ...
    • How to Use Vendor Analysis (AI)

      Overview Vendor Analysis is an AI-generated briefing on a vendor, built from publicly available information about their domain. It is background research — useful before onboarding, or as context when reading a questionnaire — and it is generated ...
    • Vendor Pulse: Frequently Asked Questions (FAQ)

      Overview Answers to the questions we hear most often about Vendor Pulse, Zeron's third-party risk management (TPRM) product. Prerequisites A Vendor Pulse account For anything involving permissions, an administrator who can change your group Getting ...
    • How to Manage the Vendor Risk Lifecycle

      Overview Every vendor has a Manage Risk tab where you record the risks that vendor represents and work each one through four stages, from initiation to closure. Prerequisites At least one vendor in the platform vendor:risk:view to open the tab; ...