Key shift: Moves from periodic questionnaires to .
| Practice | Why | |----------|-----| | | Focus deep assessments on critical vendors only | | Combine ratings + questionnaires | Ratings catch issues questionnaires miss | | Use the API | Automate vendor onboarding/offboarding from your CRM/ERP | | Set threshold alerts | e.g., Alert if vendor rating drops below 500 | | Review evidence | Don’t just accept uploaded documents – check timestamps & relevance |
It’s a to assess, monitor, and manage the security posture of third-party vendors, partners, and suppliers. It uses external security ratings (ratings from 250–900) combined with vendor self-assessments, document exchange, and remediation workflows.