When the vendor clicks the link and logs in via OTP:
After the vendor submits:
| Feature | Questionnaire Assessment | Risk Assessment |
|---|---|---|
| What is sent | A template with questions | Specific identified risks |
| Vendor action | Answer questions | Provide remediation strategy + evidence |
| Purpose | Evaluate vendor's compliance posture | Get vendor response to specific risk findings |
| Template required | Yes (from MasterVault) | No — uses existing risk entries |
| Issue | Solution |
|---|---|
| Cannot send risks | Verify your role has Risk Send permission. Ensure risks are created and selected. |
| Vendor did not receive the link | Check the vendor's SPOC email address. Verify the email was not caught by spam filters. |
| Vendor cannot log in | The vendor uses OTP-based authentication. Ensure they are entering the correct email address. |
| Vendor responses not visible | The vendor must click Submit to finalize. Check if the risk assessment status shows as submitted. |