Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Create a Vendor Intake Form

Prev Next

Who can use this feature

  • Included in the Scale plan

  • Available in the Vendor Advanced Add-on for Foundation and Growth plans

The vendor intake form is the starting point for onboarding new vendors through the Scrut Employee Portal. Once you build and save it, employees in your organization can log in to the portal and submit vendor procurement requests by filling it out.

Pro Tip: Before You Begin

Plan the questions you want to include before building the form. See Best Practices and Sample Questions below for guidance on what to ask.

How to Create a Vendor Intake Form

  1. Navigate to Risk → Vendors using the left navigation panel.

  2. Click the Settings icon at the top right.

  3. Go to the Intake Form tab and click Add Question.

  4. Enter your question and select a question type:

    • Subjective: an open text field for written responses.

    • Objective (Single Select): a single-choice question.

      Note: You can include conditional follow-up questions for this question type, as needed.

    • Objective (Multi Select): a multiple-choice question allowing more than one selection.

  5. Click Save.

  6. Click Add Question again to add more questions to the form.

The intake form is now available in the Vendor Onboarding tab of the Scrut Employee Portal. Employees in your organization can log in to the portal and submit a new vendor request by filling out the form.

Adding Conditional Follow-Up Questions

For Objective (Single Select) questions, you can add conditional follow-up questions that appear based on the answer an employee selects. Use this to collect additional context only when it's relevant, without making the form longer for everyone.

  1. Scroll to an Objective (Single Select) question and click Add Follow-Up Question under it.

  2. Select the condition for which to trigger the follow-up question.

  3. Enter the follow-up question and select a question type.

  4. Click Save.

Note: Repeat for any other answer options that require a follow-up question. Follow-up questions are only shown to employees who select the corresponding answer.

Best Practices

A well-structured intake form gives your team the information needed to assess a vendor quickly and consistently. Consider including questions across these areas:

  • Basic company information: legal name, headquarters location, website, year established, and primary point of contact.

  • Services and products: a description of what the vendor offers and how it will be used within your organization.

  • Security posture: whether the vendor has MFA enabled, how they manage authentication, and whether they have a documented security policy.

  • Compliance and certifications: the compliance frameworks they adhere to, such as SOC 2, ISO 27001, GDPR, or HIPAA, and whether they have current certifications.

  • Data handling: the types of data the vendor will access or process, and where that data is stored.

  • Contractual and legal: whether the vendor has signed an NDA, data processing agreement, or other relevant contracts.

Pro Tip!

Use conditional follow-up questions to go deeper on high-risk answers without lengthening the form for everyone. For example, if an employee selects that the vendor will access personal data, trigger a follow-up asking which data types are involved.

Sample Questions

Use the following as a starting point when building your intake form. Adapt or expand them based on your organization's vendor assessment requirements.

Basic Vendor Information

  1. What is the vendor's legal name?

  2. Where is the vendor headquartered?

  3. What year was the vendor founded?

  4. What is the vendor's website?

  5. Who is the primary point of contact at the vendor? (Name, title, and email)

Services and Products

  1. What product or service are you proposing this vendor for?

  2. How will this vendor's product or service be used within our organization?

  3. Which teams or departments will use this vendor?

Security Posture

  1. Does the vendor have multi-factor authentication (MFA) enabled?

  2. How does the vendor manage user authentication?

  3. Does the vendor have a documented information security policy?

  4. When did the vendor last conduct a security audit or penetration test?

Compliance and Certifications

  1. Which of the following compliance frameworks does the vendor adhere to? (HIPAA / SOC 2 / ISO 27001 / GDPR / Others)

  2. Does the vendor hold any active compliance certifications? If yes, which ones?

  3. Is the vendor willing to share their most recent audit report or compliance certificate?

Data Handling

  1. Will this vendor access, process, or store any of our organization's data?

  2. What types of data will this vendor handle? (Personal data / Financial data / Health data / Other)

  3. Where does the vendor store data, and in which regions?

  4. Does the vendor have a data breach notification process in place?

Contractual and Legal

  1. Has the vendor signed a Non-Disclosure Agreement (NDA) with your organization?

  2. Is the vendor willing to sign a Data Processing Agreement (DPA) if required?

  3. Does the vendor carry cyber liability insurance? If yes, what is the coverage amount?

Note: Questions 13 and 17 work well as Objective (Multi Select). Questions 9, 11, 16, and 21 work well as Objective (Single Select) with conditional follow-ups triggered on specific answers to collect supporting detail. The remaining questions are best set as Subjective.


Reach out to support@scrut.io or contact your CSM for further assistance.