How to Use Vendor Analysis (AI)

How to Use Vendor Analysis (AI)

Overview

Vendor Analysis is an AI-generated briefing on a vendor, built from publicly available information about their domain. It is background research — useful before onboarding, or as context when reading a questionnaire — and it is generated fresh, not drawn from the vendor's own answers.


Prerequisites

  • A vendor whose profile has a primary domain set — the analysis is keyed on the domain and cannot run without one
  • The vendor add permission (vendor:add), which is what the analysis service checks
  • A cloud (SaaS) deployment — the tab is not available on on-premises installations

Opening Vendor Analysis

Navigation: Sidebar → Vendors → [select a vendor] → Vendor Analysis

  1. Click Vendors in the sidebar.
  2. Click the vendor you want to research.
  3. Open the Vendor Analysis tab. It is marked with the ZIN AI icon.

The analysis starts as soon as the tab opens.


While It Is Running

You see an AI Analysis in Progress card that steps through what it is doing:

  1. Analysing vendor financial stability and business continuity.
  2. Evaluating security posture and incident history.
  3. Assessing data privacy compliance and third-party dependencies.
  4. Identifying key strengths, risks, and market position.
  5. Analysing technology stack and generating recommendations.
  6. Compiling comprehensive vendor analysis report.

Leave the tab open until it finishes.


What the Report Contains

The report opens with a note that the content was generated using ZIN and asks you to verify it independently before acting on it. Take that seriously — this is research material, not an audited finding.

The report is then organised into these sections. A section only appears if the AI found something for it, so a low-profile vendor may show fewer of them.

SectionWhat it covers
Financial StabilityThe vendor's financial standing
Business ContinuityTheir resilience and continuity position
Incident HistoryPast incidents affecting the vendor
Cyber Attacks & IncidentsIndividual incidents, each with a date, an Impact note and a View Source link to the original reporting
Data Privacy ComplianceTheir data privacy and regulatory position
Third Party DependenciesWho the vendor themselves depends on
Key StrengthsWhat the vendor does well
Key RisksWhat to be cautious about
Market PositionWhere they sit in their market
Security PostureTheir overall security maturity
RecommendationsSuggested next steps

Use View Source on any incident to read the underlying report before you rely on it.


How to Use It

  • Before onboarding — read Key Risks and Incident History alongside the vendor's questionnaire response.
  • During assessment review — if the analysis reports an incident the vendor did not disclose, raise it as a comment on the relevant question.
  • For risk context — Third Party Dependencies is a useful prompt for fourth-party risk questions.

Anything you decide to track should be raised as a risk on the vendor's Manage Risk tab. Vendor Analysis is read-only; it does not create risks by itself.


Troubleshooting

The Vendor Analysis tab shows a "not authorised" screen → Vendor Analysis is not available on on-premises deployments.

The tab is blank, or the analysis never starts → The analysis runs against the vendor's primary domain. Open the Profile tab and check a domain is recorded; if it is missing, edit the vendor to add it.

The analysis is taking a long time → Generation is allowed several minutes before it times out. If nothing appears after that, reload the tab to run it again.

The report is very thin → The AI works from public information. Small or privately held vendors, and vendors with little web presence, genuinely produce less material.

Something in the report looks wrong → Follow the View Source link where one is given, and treat the disclaimer at the top of the report as the rule: verify independently before making a decision.

A colleague cannot open the tab → The analysis service checks the vendor add permission (vendor:add). Someone with view-only access to vendors will not be able to run it.


Need more help? Contact support@zeron.one