Scrut's Vendor Management module helps you track, assess, and manage your third-party vendors through their full lifecycle, from initial evaluation to offboarding. This guide walks you through the end-to-end workflow.
Step 1: Add Vendors
By default, Scrut automatically adds vendors when you connect to any integration. Additionally, you can also add vendors using any of the following methods:
Add vendors through the Onboarding → Discovery tab, where Scrut surfaces potential vendors from your connected SSO integrations.
Share the Intake Form with employees so they can submit vendor requests directly.
Manually create a vendor and fill in the relevant details.
Import vendors in bulk using the Scrut-provided CSV template.
When adding a vendor, select one of the following vendor lifecycle stages:
Prospective: The vendor is under evaluation and has not yet been approved for active use.
Active: You are currently using services from this vendor.
Pro Tip!
Use the Prospective status to run your full due diligence workflow before formally onboarding a vendor as Active.
Step 2: Collect Documents
Gather the documentation you need to assess the vendor's security and compliance posture.
Upload documents manually to the Documents tab on the vendor profile.
If you're using Scrut Teammates, publicly available documents such as the Consensus Assessments Initiative Questionnaire (CAIQ) are fetched automatically, if available.
If the vendor has a Scrut-hosted Trust Portal, fetch their documents directly from the vendor’s Trust Portal to the Documents tab.
Step 3: Create a Vendor Questionnaire
Send the vendor a questionnaire to collect information relevant to your assessment. You have two ways to do this:
Leverage AI: Use Scrut Teammates to generate a custom questionnaire based on the vendor's risk level and other attributes.
Manually: Create a questionnaire template and then create a vendor questionnaire from the template.
Step 4: Assess the Vendor
Review all collected material to evaluate the vendor's risk.
Review the vendor's responses to the questionnaire.
Review the documents collected from the vendor.
Use Scrut Teammates to identify risks across documents and questionnaire responses.
Create risks directly from the assessment to log any gaps or concerns uncovered during your review.
Create mitigation tasks to assign follow-up actions and track remediation for each identified risk.
Step 5: Update the Vendor Status
After completing your assessment, update the vendor's status to reflect your decision.
If the vendor was added as Prospective and has been approved, mark them as Active.
If the vendor does not meet your requirements and you no longer want to evaluate or engage them, mark them as Archived.
Step 6: Run Reassessments
Repeat Steps 2 through 5 when the vendor is due for their periodic or annual reassessment.
Step 7: Offboard a Vendor
When you are no longer working with a vendor, archive them to remove them from your active vendor list.
Navigate to the vendor profile.
Click Archive and provide a justification for offboarding.
Note:
You can unarchive a vendor at any time if you need to reactivate or re-evaluate them.