WorkflowIT & Data

Third-Party Cyber Risk Assessor

Vendor security risk assessment, every rating cited to the questionnaire and the SOC 2 page behind it

Every vendor’s security evidence read and mapped to your controls, with a cited risk rating ready to sign.

See one case, screen by screen ↓
demo640answers and testsmapped to the control framework for one Tier-1 vendor — 1 contradiction found
target6.6hof analyst time per Tier-1 vendor assessment
target9daysmedian from complete evidence to a signed decision, against a 15-day target
target486vendorswatched every day for expiring reports, hosting changes and breach news
The problem

Why a Tier-1 vendor review eats a week of analyst time

A Tier-1 renewal arrives as an evidence pack: a SIG Core questionnaire with more than six hundred answers, a SOC 2 Type II report of a hundred pages or more, a pen-test summary, an incident response plan, certificates and a data processing agreement. Someone has to read all of it, find the auditor’s exceptions in Section 4, check the carve-outs and the complementary user entity controls, and map every answer to your own control framework before a rating means anything.

Most of that time is reading, not judging. And the risk sits in the gaps between documents. A questionnaire says MFA covers 100% of privileged accounts while the auditor’s sample found accounts without it, or a SOC 2 period ended six months ago and no bridge letter came. Miss one of those, and the residual rating rests on the vendor’s own word.

estimated≈20hof analyst time per Tier-1 assessment by hand
demo627questionsin one SIG Core 2026 questionnaire, each answer to check against the evidence
demo112pagesin one vendor’s SOC 2 Type II report
Where a Tier-1 assessment’s analyst hours goestimated
By hand20 days
With the solution6.6 days
  • Reading the evidence and mapping it to our controls12 → 1 d
  • Reviewing findings3.5 → 2.8 d
  • Vendor follow-up and requests3 → 1.9 d
  • Decision and sign-off1.5 → 0.9 d

Hours by hand are our estimate for a questionnaire of about 600 questions plus an 80–120-page audit report. Hours with the solution are from the working solution’s dashboard, on its sample data.

How it works

How an assessment moves

Six specialist agents file, read, map, rate and follow up every vendor’s evidence; the third-party risk analyst decides each rating.

What comes in
Evidence inVendor evidence pack · questionnaires, audit reports, tests, policies
Agents at work
Evidence classifierfiles + gaps
Then
Questionnaire readeranswers + comments
SOC report readerexceptions + pen tests
Then
Control mapper & gap findergaps + contradictions
Then
Risk raterinherent → residual
Then
Request & clause writerrequests + next review
A person decides
Third-party risk analystdecides; high risk gets a second signature
What comes out
Signed risk rating
Requests to the vendor
Next review booked
One case, step by step

One Tier-1 renewal, from evidence pack to a signed decision

Velunda Trial Cloud runs clinical data capture and patient diaries for 14 active studies. Its renewal is due on November 15 and the decision on October 9. Here is that assessment, screen by screen, in the working solution.

  1. 01Morning

    The whole vendor portfolio on one radar

    Priya Raman · Third-party risk analyst

    Priya sees 486 vendors in cyber scope, each placed by tier and by what it does for the business: 8 assessments open, 5 items that need her, 7 Tier-1 vendors at High residual, and a median of 9 days to decision. At the top of her list is Velunda: a contradiction on MFA, 6 findings, residual High, decision due in 2 days.

    Fourth-party watch: “Nimbrel Cloud hosts 9 of our vendors.”

  2. 02Opened

    The evidence pack, already read and mapped

    Priya Raman · Third-party risk analyst

    Assessment V-2417 has 9 of 10 documents in: the SIG Core 2026 questionnaire, the SOC 2 Type II report, the pen-test summary, the incident response plan, the regulatory compliance statement (21 CFR Part 11 and EU Annex 11), the BAA and DPA, the ISO 27001 certificate and the tiering form. The bridge letter is marked not received. Nimbrel Cloud’s SOC 2 is on file from an earlier assessment, so it was reused rather than requested again. Thirteen control domains show Met, Below our standard, Auditor exception or Missing evidence at a glance.

    “6 findings to act on · 2 high · 1 contradiction · 640 answers and tests mapped to our framework.”

  3. 03Under two minutes

    How the agents assessed it

    The agents

    One link shows the run. The evidence classifier filed 9 documents and flagged 1 missing. The questionnaire reader read 611 of 627 answers. The SOC report reader went through 112 SOC 2 pages for exceptions, carve-outs and the controls left on Northwind’s side. The control mapper mapped 640 answers and tests and found 1 contradiction, and the risk rater put residual at High, 64.

    The SOC report reader’s note: “read 112 pages · 2 exceptions · 7 controls on our side · 1 carved-out host.”

  4. 04The finding that matters

    The questionnaire says MFA everywhere. The auditor disagrees.

    Control mapper & gap finder

    On the left, SIG H.4.2: “MFA is enforced for 100% of privileged accounts.” On the right, the SOC 2 test of CC6.1 on page 48: for 3 of 25 sampled privileged accounts, MFA was not enforced during the period. Management says it was fixed in February 2026 but gave the auditor no evidence. So the request asks for an identity-provider MFA policy export, dated after February 2026, covering every privileged account.

    A contradiction needs both passages, and the SOC report reader never treats a management response as evidence.

  5. 05Next

    What the auditor assumed Northwind would do

    Priya Raman · Third-party risk analyst

    The SOC 2 lists 7 complementary user entity controls on page 24. Each one is matched to Northwind’s framework and has a named owner. Five are in place. Two need action. Access reviews for this system happen once a year, not every quarter (Dana Okafor, Identity & access), and the monthly audit-trail review runs in only 9 of 14 studies (Dr. Maya Chen). Priya assigns the first to Dana in one click.

  6. 06Rated

    Critical inherent, High residual, and what would bring it down

    Risk rater

    Inherent risk is 88, Critical, from the tiering form: patient data including protected health information (+30), GxP trial data supporting submissions (+22), ~38,000 participants in 14 studies (+18) and 9–12 months to replace (+18). The vendor’s controls bring the base to 38, and six open findings add 26, for a residual of 64, High. If the conditions are met, it drops to 38, Moderate. Ticking the MFA evidence and the pen-test retest letter shows 47 straight away.

    Every point has a reason: MFA evidence +9, retest letter for H-01 and H-02 +8, bridge letter +3, 24-hour notice +2, validation summary +2, HIPAA risk analysis +2.

  7. 07Drafted

    One request per finding, and the clauses for the renewal

    Request & clause writer

    The remediation request to Marta Lindqvist, Velunda’s CISO, lists six items, each with the evidence that would close it and a due date set by severity. It covers the MFA export and a dated fix plan, both within 14 days, with the retest letter for H-01 and H-02 by December 15. Then a bridge letter for April 1 – September 30, 2026, a 24-hour initial notice, the validation summary and the HIPAA risk-analysis summary, all within 30 days. The contract clauses use approved wording and go to Sam Patel in procurement for the renewal paper.

    Nothing goes to a vendor without the analyst.

  8. 08Decision

    Approve with conditions, recommended and explained

    Priya Raman · Third-party risk analyst

    The decision offers four choices: approve, approve with conditions, remediate before go-live or renewal, or do not approve. Approve with conditions is recommended, with six conditions tracked to closure. The full reassessment is set for October 2027 (Tier 1, every 12 months), and a triggered check for December 15, 2026, when the retest letter is due. Priya adds her note for the record.

    “Residual High — Omar Haddad co-signs after you sign.”

  9. 09Signed · Oct 7

    Signed, co-signed, sent and booked

    Omar Haddad · Head of IT Risk & Compliance

    Priya signs: approved with conditions, 6 conditions. Because residual is High, Omar Haddad co-signs. The requests go to Marta Lindqvist and the clauses to Sam Patel, and the reassessment is booked for October 2027 with the triggered check on December 15. Every step lands on the assessment’s activity record, people and agents alike.

  10. 10Also today

    A notice at the host, checked across nine vendors

    The monitoring workflow

    On October 5, Nimbrel Cloud reported credential-stuffing on its support portal. Nine of Northwind’s vendors run on Nimbrel, Velunda among them. The check asks each vendor’s file three questions: does it use Nimbrel’s support portal, with shared credentials, and is Northwind data in a Nimbrel environment? It found no impact for any of the nine, recorded the result on each file and asked Nimbrel for written confirmation.

Who it’s for

Built for everyone who signs off a vendor.

One renewal, seen by the five people it touches: the analyst, the co-signer, procurement, a control owner and the business owner.

PR
Priya RamanThird-party risk analyst
Analyst
Before
Spends most of a Tier-1 review reading the questionnaire and the SOC 2 before she can judge anything.
Now
Opens an assessment already mapped to the control framework, with the contradictions side by side and every finding cited to its page.
OH
Omar HaddadHead of IT Risk & Compliance
Co-signer
Before
Co-signs High-residual decisions from a summary he cannot trace back to the evidence.
Now
Co-signs with the rating’s reasons, point by point, and sees residual risk by tier across all 486 vendors.
SP
Sam PatelProcurement category manager
Procurement
Before
Waits for security to say which terms the renewal needs.
Now
Receives the contract clauses with the decision, in approved wording, one per domain with a finding.
DO
Dana OkaforIdentity & access lead
Control owner
Before
Rarely hears which controls a vendor’s auditor assumed her team runs.
Now
Gets a task for each control on Northwind’s side that is not in place, such as adding a system to the quarterly access review.
MC
Dr. Maya ChenClinical operations
Business owner
Before
Learns about a vendor’s risk late in the renewal.
Now
Is informed on every decision for her vendor, and owns the controls on her side, like the audit-trail review across all 14 studies.
Built on the engine

6 agents. Each with one job, and hard limits.

Six specialist agents file, read, map, rate and follow up every vendor’s evidence; the third-party risk analyst decides each rating.

Evidence classifier

Files each document a vendor sends into the right assessment: questionnaire, SOC 2, bridge letter, pen-test summary, certificate, policy, BAA. It also flags what is missing.

  • Never opens password-protected files without the vendor’s key
  • Vendor documents stay in the vendor’s assessment
Questionnaire reader

Reads SIG Core, SIG Lite and CAIQ answers with their comments, keeping each answer’s reference and cell.

  • Cites the questionnaire reference for every answer it uses
  • Treats blank or “N/A” answers as unanswered unless a reason is given
SOC report reader

Reads SOC 2 reports in the order reviewers use: opinion, scope and criteria, carve-outs, controls on your side, Section 4 exceptions and management responses. It also reads pen-test summaries and policies.

  • Quotes exceptions word for word
  • Never treats a management response as evidence
Control mapper & gap finder

Maps answers and tests to your control framework and finds contradictions, missing evidence, stale periods, missing criteria and carved-out fourth parties. It reuses reports already on file.

  • Every finding cites at least one passage
  • A contradiction needs both passages
Risk rater

Scores inherent risk from the tiering form and residual risk from controls and findings, with the reason for every point and the score if the conditions are met.

  • Scores are explained, never bare
  • High or Critical residual goes to the co-signer
Request & clause writer

Drafts the remediation request to the vendor and the contract clauses for procurement from the findings, and books reassessments by tier.

  • Sends nothing to a vendor without the analyst
  • Uses approved clause wording only
Third-party risk analyst

Decides; high risk signed twice. The agents propose; a named person decides.

Ask in plain words

Ask about any vendor, finding or rule

The assessment team can ask in plain words, or tell it what to change. Answers point to the passages behind them.

Why is Velunda rated High?

Velunda is Critical inherent (88): patient data for 14 studies, GxP trial data, 9–12 months to replace. Its controls bring the base to 38; six findings add 26. The biggest driver: the auditor found 3 of 25 admin accounts without MFA while the questionnaire says 100%. With the conditions met it drops to Moderate (38).

What do we have to run on our side for Velunda?

Velunda’s auditor assumed we run 7 controls. Five are in place. Two need action: quarterly access review (yearly today — Dana Okafor) and audit-trail review, running in 9 of 14 studies (Dr. Maya Chen).

Which vendors run on Nimbrel Cloud?

9 of our vendors run on Nimbrel Cloud. Nimbrel’s own SOC 2 Type II (Jul 2025 – Jun 2026) is clean and on file, so carve-outs are covered by reuse. The Oct 5 security notice is waiting for a dependency check.

Add a rule: Tier 1 high pen-test findings fixed in 30 days

Done — “Tier 1: high pen-test findings fixed and retested within 30 days” is added to the evidence rules. It matches our standard VM-06. Right now it flags Velunda (H-01 and H-02, retest after the renewal). The change is recorded in the audit trail.

Every screen

The working solution, as it ships.

13 screens from the working solution, on its sample data. Pick one to see it large.

The third-party radarEvery vendor in cyber scope by tier and service, coloured by residual risk, with what needs the analyst today and the fourth-party watch.
The assessmentThe evidence pack, 13 control domains at a glance, and the findings to act on, with the source document open beside them.
How the agents assessedEach agent’s step and what it found: documents filed, answers read, SOC 2 pages read, answers and tests mapped, residual rated.
A contradiction, side by sideWhat the questionnaire says against what the auditor found, each with its citation, and the SOC 2 exception highlighted on its page.
Controls on our sideThe complementary user entity controls from the SOC 2, matched to your framework with a named owner, and each gap one click from its owner.
Inherent and residual riskInherent from the tiering form, residual after controls and findings, a reason for every point, and a what-if for the conditions.
Requests and clausesThe remediation request to the vendor, one item per finding with a due date, and the contract clauses for the renewal.
The decisionFour choices with one recommended, the conditions, the next full reassessment and the triggered check.
Signed and co-signedSigned by the analyst, co-signed for High residual, requests and clauses sent, reassessment booked.
MonitoringReassessments booked by tier, who runs on each fourth party, and the signals that open a review early.
Fourth-party checkA security notice at a hosting provider checked across every vendor that runs on it.
The dashboardAssessments completed, median days to decision, analyst hours, residual risk by tier, evidence freshness and who is waiting on vendors.
Your rulesTiering, evidence rules, reassessment cadence, approvers and the control framework, all settings.
Governance

Built for decisions you can defend: cited, co-signed, on the record.

No citation, no findingEvery finding cites the passage behind it, the questionnaire cell or the report page, and a contradiction shows both passages side by side. Click either one to open the document at that line.
The vendor’s word is not evidenceManagement responses in a SOC 2 are shown, but never count as evidence. A claim the auditor did not test becomes a request for the evidence that would close it.
High residual is signed twiceThe analyst proposes and signs the decision. Residual High or Critical needs a co-signature from the Head of IT Risk, and accepting a high finding on a Tier-1 vendor needs his confirmation and a note.
Nothing reaches a vendor on its ownRequests and clauses are drafted for the analyst. Nothing is sent to a vendor without her, and clauses use approved wording only.
Vendor documents stay privateVendor documents are visible only to the assessment team and the business owner, and the agents never use them to train models.
Every step on the recordEach agent step and each human decision is on the assessment’s activity record. Decisions and rule changes are versioned and kept for 7 years.
Configuration

Your risk program’s rules, not ours

Tiering, evidence rules, cadence and approvers are settings. Changes apply to open assessments and are versioned.

SettingDefaultChoose from
Patient or health dataTier 1Tier 1 · Tier 2
Ask for a bridge letter when a SOC 2 period ended more than3 months3 · 6 · 9 months
High pen-test findings fixed and retested within30 days30 · 45 · 60 days
Accept ISO 27001 in place of SOC 2 for Tier 2 and 3OnOn · Off
Tier 1 full reassessmentEvery 12 monthsEvery 6 · 12 · 18 months
Tier 2 full reassessmentEvery 24 monthsEvery 12 · 24 months
Open a review early whenExpiry, fourth-party notice, breach, scope changeReport or certificate expiry · Fourth-party notice · Breach disclosure · Scope change
Co-signs residual High or CriticalOmar HaddadOmar Haddad · Priya Raman
Connections

Works with the evidence and systems you already use

Security questionnairesSIG Core and SIG Lite 2026, CAIQ v4
Assurance reportsSOC 2 Type I and Type II, bridge letters, ISO 27001 certificates
Pen-test summaries and policiesincident response plans, compliance statements, BAAs and DPAs
Procurement intakethe tiering form that sets inherent risk
Your control frameworkmapped to ISO 27001:2022, NIST CSF 2.0, NIS2 Art. 21 and SOC 2 criteria
Supplier portal and mailboxevidence in, requests and reminders out
What it changes

The difference, in numbers.

Every figure is labelled: a target the solution is built to, an estimate, a typical published result, or a proven one.

target
6.6h
of analyst time per Tier-1 vendor assessment
By hand≈ 20 h
With agents6.6 h
target
9days
median from complete evidence to a signed decision
Decided on day 9
target is 15 days
target
486vendors
vendors watched every day for expiring reports, hosting changes and breach news

“demo” = seen in the working solution, on its sample vendor data · “target” = the design goal, measured in the live solution · “estimated” = our estimate; by-hand hours assume a questionnaire of about 600 questions plus an 80–120-page audit report per vendor. People and companies named on this page are characters in the working solution.

Questions

What third-party risk teams ask us.

What is a third-party cyber risk assessment?

It is the review of a vendor’s security evidence: its questionnaire answers, SOC 2 report, pen-test results and policies. The review rates the risk the vendor brings, decides what you must ask of it, and sets which controls you keep on your side. The Third-Party Cyber Risk Assessor reads that evidence, maps it to your control framework and rates inherent and residual risk with a cited reason for every point. The analyst decides.

How does it read a SOC 2 report?

In the order reviewers do: the opinion, the period and type, the criteria in scope, carve-outs, the complementary user entity controls, the Section 4 exceptions with their sample sizes, and the management responses. It quotes exceptions word for word and never treats a management response as evidence.

Does it catch questionnaire answers the evidence contradicts?

Yes. That check is always on for Tier 1. When a questionnaire answer and a report passage disagree, it raises a contradiction with both passages side by side. One example is MFA “enforced for 100% of privileged accounts” against an auditor’s sample that found accounts without it.

How is the risk rating calculated?

Inherent risk comes from the tiering form: data, GxP, access, scale and replaceability. Residual starts from a base after the vendor’s controls and adds points for each open finding, with the reason for each. It also shows the score if the conditions are met, and you can tick conditions to see the effect.

Does it handle fourth parties and carve-outs?

Yes. When a SOC 2 carves out a hosting provider, it looks for that provider’s own report on file and reuses it across every vendor that runs on it. When the provider issues a security notice, it checks each dependent vendor and records the result.

Do people stay in control?

Yes. The agents propose, and the third-party risk analyst decides and signs. Residual High or Critical needs a co-signature from the Head of IT Risk, and nothing is sent to a vendor without the analyst.

Can we use our own control framework and questionnaires?

Yes. Findings map to your own framework. In the working solution that is 13 domains and 214 controls, mapped to SIG 2026, CAIQ v4, ISO 27001:2022, NIST CSF 2.0 and NIS2 Art. 21. Tiering, evidence rules, reassessment cadence and approvers are all settings.

How long does it take to go live?

The Agentic Solution Engine builds and deploys it from your requirements and documents: such as your control framework, tiering form and contract clause library. It goes live once every quality gate has passed. We will run it on a few of your own vendors’ evidence packs first.

See it on
your vendors.

We’ll run the Third-Party Cyber Risk Assessor on evidence packs from a few of your own vendors.