How to Review Vendor Risk Scores

How to Review Vendor Risk Scores

Overview

Vendor Pulse shows vendor risk in three places, each answering a different question:

WhereQuestion it answers
Profile tab on a vendorHow risky is this vendor overall?
Manage Risk tab on a vendorWhat specific risks are open, and who is fixing them?
DashboardWhere does risk sit across my whole vendor portfolio?

This guide covers all three.


Prerequisites

  • At least one vendor on the platform
  • Permission to view vendors (vendor:view)
  • Permission to view vendor risks (vendor:risk:view) for the Manage Risk tab
  • Permission to view the dashboard for the portfolio view

The Vendor Profile Summary

Navigation: Sidebar → Vendors → [select a vendor] → Profile

The Profile tab opens by default and carries eight summary cards. Each has an information icon with an explanation of what it measures.

CardWhat it shows
Vendor CategoryThe category the vendor is classified under
Vendor's IndustryThe vendor's industry
Vendor Onboarding DateWhen the vendor was onboarded
Last Assessment DateThe date of the most recent assessment
Impact / MaterialityThe level of business impact associated with this vendor — Low, Medium or High
Risk RatingThe overall risk score assigned to the vendor based on recent assessments
Compliance StatusThe vendor's compliance level against regulatory and contractual requirements
Total RisksTotal risks identified for this vendor, broken down by status in a chart

Cards with no data available say No data found rather than showing a misleading zero. The same applies to the profile details underneath: empty revenue, employee count, location and risk manager fields read Not provided.

> Last Assessment Date now reflects only assessments that have actually started or completed. It no longer shows the date of a future, not-yet-started re-assessment cycle, so some vendors will show an earlier date, or none, compared with before.

The vendor's onboarding status sits to the right of the tab bar as a dropdown — Ongoing assessment, Onboarded, Rejected, On hold or Assessment not send. Where a remark was recorded with a status change, hovering the status shows the remark and who changed it.


Working Through Individual Risks

Navigation: Sidebar → Vendors → [select a vendor] → Manage Risk

This is where the vendor's risks live. There is no separate "Risk" or "Reviews" tab.

The status cards

Seven cards run across the top: All, Pending, Planning, In Progress, On Hold, Completed and Waived, each with a count. Click one to filter the list to that status; click it again, or click All, to clear the filter.

The risk table

ColumnMeaning
Risk TitleThe name of the risk
Evaluation DateWhen the risk was last evaluated
Risk SourceDRM, Assessment or Manual — where the risk came from
Risk SeverityInfo, Low, Medium, High or Critical
StatusPending, Planning, In Progress, On Hold, Completed or Waived
Due DateThe target date for closing the risk
Assigned ByWho raised or assigned it
Assigned ToWho owns it

Search and paging controls sit above the table.

What you can do

  • Add Risk — raise a risk manually (needs the vendor risk add permission, vendor:risk:add).
  • Open a risk from the table to work through its details, scoring, evidence and closure.
  • Mark Evaluation / Unmark Evaluation on a row — select risks to send to the vendor for their response. Only risks at Pending, Planning or In Progress can be marked.
  • Once risks are marked, a risk evaluation actions menu appears with Send Evaluation (sends the marked risks to the vendor's evaluation portal) and Reset Selected (clears the selection).
  • Delete a risk from the row menu.

Risks raised from Digital Risk findings arrive here automatically with Risk Source set to DRM.


Vendor Analysis

Navigation: Sidebar → Vendors → [select a vendor] → Vendor Analysis

The Vendor Analysis tab (marked with the ZIN AI icon) is an AI-generated external view of the vendor — financial stability, incident history, key risks, security posture and recommendations. It complements the risk score rather than feeding it. See the separate *How to Use Vendor Analysis (AI)* article for the detail.


Portfolio Risk on the Dashboard

Navigation: Sidebar → Dashboard

The dashboard opens with four headline cards:

CardWhat it means
Total VendorsThe total number of vendors being assessed or monitored
Active AssessmentsAssessments currently Ongoing, out of all assessments, with the change over the last 30 days
Average Compliance RateThe percentage of vendor assessment responses meeting compliance requirements, averaged across onboarded vendors
Average Risk ScoreCombined risk score on a 0–10 scale averaged across onboarded vendors — Low (0–3), Medium (3–5), High (5–7), Critical (7–10)

Below them are five panels:

PanelWhat it shows
Assessment StatusAssessments broken down as Pending, Ongoing and Completed
High Risk VendorsUp to five vendors with the highest average risk scores; click one to open their Manage Risk tab
Risk MatrixOnboarded vendors counted at each intersection of impact (severity) and criticality, showing where risk concentrates
Open RisksOpen risks against the total
Vendor Industry ConcentrationHow your vendors are distributed across industries

Each panel has an information icon explaining what it counts.


Troubleshooting

Risk Rating or Compliance Status shows "No data found" → Those figures come from assessment responses. Send the vendor an assessment and let it reach Completed before expecting a score.

Last Assessment Date is earlier than I expected, or has disappeared → This field now counts only assessments that have actually started or completed. A future-dated re-assessment that has not begun no longer counts.

The Manage Risk tab shows a "not authorised" screen → Viewing vendor risks requires vendor:risk:view. Ask your administrator to grant it.

I cannot see the Add Risk button → Raising risks requires vendor:risk:add, which is separate from viewing them.

The risk list looks empty but I know risks exist → A status card at the top may still be selected as a filter. Click All to clear it, and clear the search box.

Mark Evaluation is missing on a risk → Only risks at Pending, Planning or In Progress can be marked for evaluation. Risks that are On Hold, Completed or Waived cannot.

The dashboard average risk score does not match a vendor's Risk Rating → The dashboard averages across all onboarded vendors; the profile card is that single vendor's score.


Need more help? Contact support@zeron.one