Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Evaluate Vendor Responses

Prev Next

Who can use this feature

  • Supported on Foundation, Growth, and Scale plans

Once a vendor submits their questionnaire, you review their responses, assess risk, and finalize the assessment in Scrut. This guide covers the complete evaluation workflow, from accessing the submitted questionnaire to reviewing the final risk scorecard. Whether you used Scrut Teammates to create the questionnaire or created it manually, the evaluation process is the same.

Note:

Only questionnaires in Submitted status can be evaluated.

Step 1: Access the Submitted Questionnaire

You can access the submitted questionnaire in two ways:

Method #1: Via the Vendor Details Page

  1. Navigate to Risk → Vendors on the left navigation panel.

  2. Go to the Vendors tab and click the vendor you want to evaluate.

  3. Scroll to the Questionnaires tab and click the questionnaire you want to evaluate.

Method #2: Via the Questionnaires Tab

  1. Navigate to Risk → Vendors on the left navigation panel.

  2. Go to the Questionnaires tab and click the questionnaire you want to evaluate.

  3. Use the search bar at the top to quickly find the questionnaire you want to evaluate.

Step 2: Assign Reviewers for Each Question (Optional)

Before you begin reviewing responses, assign a Reviewer to each question. The Reviewer is the team member responsible for evaluating that question's response. Select them from the Reviewer dropdown on the question card.

Step 3: Evaluate Responses

The questionnaire page displays all vendor-answered questions. For each response, you have up to five actions available.

Action 1: Accept Answer

Use this when the vendor's response meets your requirements.

  • Click Accept next to the question.

  • In the Accept Question modal:

    • Confirm the Weightage setting.

    • Select a Risk Score for the response. 0 represents the lowest risk, and 5 represents the highest.

  • Click Accept.

The question status changes to Accepted.

Note:

Accidentally accepted a response? No worries! Click Undo Accept to reverse the action.

Action 2: Flag as Issue

Use this when a response is inadequate, incorrect, or requires vendor attention.

  1. Click Flag as Issue next to the question.

  2. Enter the reason for flagging in the Flagging Reason field.

  3. Select Notify Vendor to send an automatic email notification to the vendor.

  4. Select the vendor Point of Contact (POC) who should receive the notification.

Note: Only the flagging reason is shared with the vendor POC. Risk scores are not shared.

  1. Click Flag.

  2. The question status changes to Flagged, and an email notification is sent to the vendor.

Heads Up! To reverse this decision, click Undo Flag.

Action 3: Add a Comment

Use this to communicate with vendors about their responses or document internal notes.

  1. Click Add Comment below the question.

  2. Enter your comment and click Add Comment to submit.

The comment is added below the response, and an email notification is sent to the vendor.

Pro Tip!

Use comments for clarification requests, feedback, or collaborative discussions with the vendor POC or with your team. Keeping communication within Scrut eliminates back-and-forth emails and maintains a clear audit trail.

Action 4: Create a Mitigation Task

Use this when a response identifies a risk that requires specific action.

  1. Click Add Mitigation Task below the question.

  2. Enter:

    • Task Name: A clear title describing the mitigation action.

    • Description: (Optional) Detailed context about the risk and required actions.

    • Assignee: The team member responsible for completing the task.

    • Due Date: The deadline for task completion.

  3. Click Save.

A mitigation task is created and linked to the question. To view it, click the task name within the question, or access all mitigation tasks from the Mitigation Tasks tab on the vendor page.

Important:

Creating a mitigation task does not complete the question review. You must still Accept or Flag as Issue to move forward.

Action 5: Create a Risk

Use this when a vendor's response reveals a potential security, compliance, or operational risk that needs to be tracked in your risk register.

  1. Click Add Risk below the question.

  2. In the Create Risk modal, enter:

    • Risk Name: A clear, concise description of the identified risk.

    • Risk Description: Detailed explanation of the risk, its potential impact, and relevant context.

    • Assignees: Team members responsible for monitoring and managing this risk.

    • Category: Select the appropriate category (e.g., Security, Compliance, Operational, Financial).

    • Department: Select the department to which the risk belongs.

    • Entities: Select the organizational entity or entities to which this risk applies. By default, all risks are organization-wide. However, you can change this setting and limit it to one or more entities.

    • Application Name: Enter the application name associated with this risk.

    • Linked Assets: Select the assets impacted by this risk.

  3. Click Create Risk.

A risk entry is created, linked to the questionnaire, and tracked in your organization's risk register. Click the risk name within the question to view full details, or access all vendor-related risks from the Risk module.

Important:

Creating a risk does not complete the question review. You must still Accept or Flag as Issue to move forward.

Pro Tip!

When to use each action:

  • Create a Risk when you've identified a potential threat that requires ongoing monitoring and strategic management.

  • Create a Mitigation Task when specific actions are needed to address or reduce an identified issue.

  • You can create both for the same question when the situation warrants tracking and immediate action.

Step 4: Request and Update Attachments (Optional)

During your review, you may need additional documentation or find that submitted attachments are insufficient or outdated. Vendors can update attachments after submission as long as the questionnaire is still under review.

To request updated attachments:

  1. Use Add Comment or Flag as Issue to notify the vendor about the attachment requirement.

  2. Specify which documentation is required or why the current attachments are insufficient.

The vendor receives an email notification with your request.

Once notified, the vendor can:

  1. Access the submitted questionnaire via the vendor portal at vendor.scrut.io.

  2. Navigate to the specific question with the attachment requirement.

  3. Re-upload or replace attachments directly within the platform.

You receive a notification when the vendor updates their attachments.

Important:

Attachments can only be updated while the questionnaire is still under review. Once you mark a question as Accepted or the questionnaire as Assessed, attachment updates are no longer possible. Address all documentation requirements before completing the assessment.

Step 5: Complete the Assessment

Once you've reviewed all questions and received all necessary documentation:

  1. Click Complete Assessment at the top of the questionnaire.

  2. (Optional) Enter an Assessment Summary to capture your key observations about the vendor.

Note: The assessment summary appears in the final vendor assessment report, right after the vendor details. It gives executives and external stakeholders a quick view of your findings without requiring them to read through each question and response. You can edit the summary at any time, even after completing the assessment, by clicking the edit icon next to it.

  1. Confirm your completion.

The questionnaire status changes to Assessed, indicating the evaluation is finalized.

Heads Up!

Once you mark as Assessed, vendors can no longer update attachments or responses, so ensure all requirements are met before completing.

Step 6: Review the Risk Scorecard

After completing the assessment, review the vendor's overall risk profile.

  1. Click Scorecard at the top of the questionnaire.

  2. Review the risk scores broken down by domain in the Scorecard window.

Use the scorecard to make informed decisions about vendor relationships, onboarding approvals, or risk mitigation actions.

Common Scenarios and Recommended Workflows

Scenario 1: Requesting Additional Documentation

  1. Review vendor response and identify missing documentation

  2. Add a Comment specifying required attachments

  3. Optionally, Flag as Issue if the documentation is critical

  4. Vendor receives notification and uploads updated attachments

  5. Review new attachments and Accept the response

Scenario 2: Replacing Outdated Certificates

  1. If you notice that a compliance certificate has expired or is outdated

  2. Flag as Issue with reason: "Please provide the current certificate."

  3. Vendor uploads updated certificate

  4. Verify the new attachment and Accept the response

Scenario 3: Insufficient Evidence

  1. The vendor provides a generic policy document instead of specific evidence

  2. Add Comment: "Please provide evidence of implementation, such as screenshots, audit reports, or configuration examples."

  3. Vendor updates the attachment with appropriate evidence

  4. Review evidence, Accept response, and update risk score accordingly

Best Practices

For Collaboration:

  • Use comments to facilitate discussion with vendors and internal teams

  • Keep Vendor POCs updated on flagged issues

  • Leverage the platform's centralized communication features instead of external email

During Evaluation:

  • Document your reasoning in comments for future reference

  • Request all necessary attachments before completing the assessment

For Attachment Requests:

  • Be specific about what documentation is required

  • Explain why current attachments are insufficient

For Risk Management:

  • Assign appropriate weightage based on your organization's risk priorities

  • Involve domain experts as reviewers for technical questions

  • Track mitigation tasks diligently through to completion

  • Regularly review scorecards to monitor vendor risk profiles over time


Need help? Contact support@scrut.io or your CSM.