Who can use this feature
Supported on Foundation, Growth, and Scale plans
Scrut's vendor risk assessment workflow gives you a structured way to evaluate third-party vendors, identify risks, and track mitigation — all within the platform. Each step in the workflow can be completed manually or with the help of Scrut Teammates, Scrut's AI-powered assessment assistant.
The Vendor Risk Assessment Workflow
Step 1: Create a Questionnaire
Build the questionnaire you'll send to the vendor for assessment.
Manually: Choose from Scrut's predefined question library, use an existing template from your organization, or build a custom questionnaire from scratch.
With Scrut Teammates: Let AI generate a tailored questionnaire based on the vendor's profile — including their type, data access, and your compliance requirements. Scrut Teammates uses the CAIQ framework and automatically maps questions to relevant risk domains.
Next Reads: Sending Questionnaires to Vendors | Vendor Risk Assessment with Scrut Teammates
Step 2: Send the Questionnaire to the Vendor
Send the questionnaire to the vendor's Point of Contact (POC) directly from Scrut. Scrut prefills the email subject and body, which you can customize before sending. The vendor POC receives an email with a link to the Scrut Vendor Portal, where they can log in and submit their responses.
Note: Scrut sends questionnaires only to vendors with an assigned POC. Add a POC to the vendor profile before sending.
Step 3: Vendor Submits the Questionnaire
The vendor completes and submits their responses through the Scrut Vendor Portal. If you're using Scrut Teammates, it acts as a real-time quality checker during submission — flagging vague or incomplete answers and prompting the vendor to provide more specific information before they submit.
Once the vendor submits, the questionnaire status changes to Submitted and becomes available for your review.
Step 4: Evaluate Vendor Responses
Review each vendor response, assign risk scores, and take action where needed. For each question, you can accept the response, flag it as an issue, add comments, create a mitigation task, or log a risk.
Manually: Work through each question and evaluate responses one by one.
With Scrut Teammates: Click Start Check to let AI analyze the submitted responses, identify potential risks based on vague or insufficient answers, and suggest mitigation steps.
Next Reads: Evaluating Vendor Questionnaire Responses | Creating Risks from Vendor Questionnaires
Step 5: Export the Assessment Report
Export the completed assessment as a PDF report. The report includes vendor details, an assessment summary, risk scores, questionnaire responses, mitigation tasks, and identified risks. You can share it with team members and stakeholders directly from Scrut.
Next Read: Exporting the Vendor Risk Assessment Report
Setting Up Recurring Assessments
For vendors you assess on a regular cycle, you can set a recurrence schedule and next assessment date directly on the vendor's profile. Scrut automatically updates the vendor's status to Needs Reassessment on the due date and notifies the assigned reviewer one week in advance.
Next Read: Vendor Reassessment
Reach out to support@scrut.io or contact your CSM for further assistance.