Vendor risk management
Turn every vendor review into a traceable decision.
Keep intake, tiering, requested evidence, findings, conditions, approvals, and reassessment dates together—so vendor oversight reflects the risk and the accountable owner.
Service and data relationship
Intake
Purpose, business owner, access, criticality, and intended use.
Review depth
Tiering + evidence
Criteria, documents, questions, and context.

Service and data relationship
Begin with what the vendor does.
A useful review starts by understanding the service, information or systems it may access, criticality, and the owner of the business relationship. That context should determine the review depth.
Keep the vendor case file together.
Intake
Service purpose, business owner, data or system access, criticality, and intended use.
Tiering
The organization's documented criteria for review depth and approval path.
Evidence
Security documents, questionnaire responses, contracts, and records requested for the defined review.
Findings
Gaps, unanswered questions, compensating considerations, and follow-up owners.
Decision
Approval, conditions, treatment, exception, rejection, or escalation recorded by the accountable party.
Reassessment
A review date or event trigger based on the organization's vendor-risk process.
Automation can organize the case. It cannot accept the risk.
Structured handling
Intake, reminders, evidence routing, and consistent status reduce administrative gaps.
Authorized decision
Vendor tiering, finding severity, contract decisions, exceptions, and risk acceptance remain with authorized people.
Connect vendor oversight to the control environment.
A vendor inventory alone does not explain why a relationship was approved or what must be revisited. Link the case to the operating records that depend on it.
Vendor case
Decision + recordPolicy
Expected handlingRisk
Treatment contextVendor risk questions
How does ControlQuill handle vendor scoring?
Apply your organization's documented tiering and review criteria, preserve the inputs behind the result, and leave the approval or risk decision with the accountable owner.
Does a SOC 2 report remove the need for vendor review?
No. It may be one useful input. The organization still needs to consider scope, period, exceptions, service context, data access, contractual terms, and its own risk criteria.
Who should approve a vendor?
Approval should follow the organization's documented authority and risk process, with business, security, legal, privacy, or procurement participation as applicable.
Trace one case
Bring one vendor review with too many handoffs.
We will map the intake, evidence, reviewers, decision, and reassessment record.
Prepare a vendor workflow review