How to Send Risk Assessments to Vendors

How to Send Risk Assessments to Vendors

Prerequisites

  • At least one vendor with identified risks in the Manage Risk tab
  • Access to the vendor's risk section

  • Sending Risks to a Vendor

    Navigation: Sidebar > Vendors > [Select Vendor] > Manage Risk Tab

    Step 1: Select Risks to Send

  • Open a vendor's detail page.
  • Navigate to the Manage Risk tab.
  • Browse the list of risks for this vendor.
  • Select the risks you want to send to the vendor using the checkboxes or selection mechanism.
  • You can select multiple risks for batch sending.
  • Step 2: Send Selected Risks

  • Click the Send Risks button.
  • The selected risks are packaged into a risk assessment and sent to the vendor's SPOC.
  • The vendor receives an email notification with a link to the risk assessment portal.

  • What the Vendor Sees

    When the vendor clicks the link and logs in via OTP:

  • They see a list of risk cards — each showing a risk that needs their attention.
  • For each risk, the vendor can:
  • View the risk details — description, severity, and what is expected
  • Provide a response strategy — describe how they plan to address the risk
  • Upload evidence — attach documents proving remediation actions
  • Add comments — communicate with your team about the risk
  • Once all risks are addressed, the vendor clicks Submit to finalize their responses.

  • Reviewing Vendor Risk Responses

    After the vendor submits:

  • Return to the vendor's Manage Risk tab.
  • Open the risk entries that were sent.
  • Review:
  • The vendor's response strategy
  • Uploaded evidence documents
  • Comments from the vendor
  • Update the risk status (move through the risk lifecycle stages) based on the vendor's response.

  • How This Differs from Questionnaire Assessments

    FeatureQuestionnaire AssessmentRisk Assessment
    What is sentA template with questionsSpecific identified risks
    Vendor actionAnswer questionsProvide remediation strategy + evidence
    PurposeEvaluate vendor's compliance postureGet vendor response to specific risk findings
    Template requiredYes (from MasterVault)No — uses existing risk entries

    Troubleshooting

    IssueSolution
    Cannot send risksVerify your role has Risk Send permission. Ensure risks are created and selected.
    Vendor did not receive the linkCheck the vendor's SPOC email address. Verify the email was not caught by spam filters.
    Vendor cannot log inThe vendor uses OTP-based authentication. Ensure they are entering the correct email address.
    Vendor responses not visibleThe vendor must click Submit to finalize. Check if the risk assessment status shows as submitted.