Setup checklist
Here’s the whole journey at a glance. Each item is a step below.Users and branding
Vendor portfolio
Tag structure
IRQ
Scales
Control sets
Plans and cadence
Templates
Radar
Obligations
Integrations
Step 1: Organization, users, and branding
This step gets your team into the platform and makes everything vendor-facing and stakeholder-facing carry your brand.- Go to Configuration → Organization and add your users. Assign a role to each one as you go:
- Admin has full platform access.
- Reviewer can assess vendors and manage workflows.
- Requester can submit vendor requests only.
- For a broader rollout, configure a verified domain so anyone from your email domain is provisioned automatically on first login. That saves you from creating accounts by hand while you pilot.
- Under Branding, upload two logos. The Simple Logo shows up in the app header, navigation, and emails (around 200x50px works well). The Large Logo goes on generated reports and vendor-facing documents, including the portal (around 400x100px).

Organization branding. Your Simple and Large logos flow into the app, reports, emails, and the vendor portal.
Step 2: Import your vendor portfolio
Loading your existing vendor inventory gives assessments, monitoring, and redundancy checks something to work against. It becomes the library you run reassessments and continuous monitoring from. You’ll need your vendor list with attributes like name, website, description, relationship owner, and contract dates. Your Coverbase contact can hand you the bulk-upload template, along with an enrichment workflow that fills in missing fields.- Go to Actions → Bulk Create Vendors.
- Download the template to see the required fields, then map your existing data into it.
- Upload your file.
- Validate the result. Confirm the vendor count matches your source file, and spot-check a few records to make sure the field values populated correctly.

Bulk Create Vendors. Map your existing list into the template and import your whole portfolio at once.
Step 3: Create your tag structure
Tags are the routing layer of the platform. IRQ answers apply tags, and tags then decide which control sets apply, which documents are required, and which due-diligence track a vendor gets. Design the taxonomy before the IRQ, because the IRQ is what fills it in. Here’s a structure that works well in practice. Adapt it to your program.Criticality
Data
Access
Geography
Infrastructure
Size and profile

The Tags configuration screen, with grouped tags for Access, Criticality, Data, Geography, Infrastructure, Size, and Vendor Profile.
Step 4: Build and weight your IRQ
The inherent risk questionnaire is what business requesters, and Coverbase’s research agent, answer at intake. Its weights produce the inherent risk score, and its response mapping applies your tags. Aim for 15 to 25 concise questions.- Go to Configuration → Questionnaires and create your Inherent Risk Questionnaire. Use Actions → Bulk Create Questions to import an existing IRQ from the spreadsheet template instead of building it question by question.
- Weight every answer with a risk score on a 0 to 20 scale, where higher means more risk. The sum of all maximum answer scores is the risk ceiling, and a vendor’s actual answers as a percentage of that ceiling is their inherent risk score.
- Open Response Mapping (the gear icon) and map answers to tags. Data handled outside the US applies “Foreign”, card data applies “PCI”, and so on.
- Add conditional logic where a follow-on question should only appear based on a prior answer, like asking for data-flow details only if data is exchanged.
- Set per-question AI guidance to control what the research agent may use when it auto-answers. For example, “only source from the vendor’s trust center, exclude blogs and CVE chatter.”
- Mark judgment questions as Required so the AI never auto-answers them without human input.

The IRQ builder. Each answer carries a weight (right column), and Configure Response Mapping links answers to the tags that route the vendor.
Example: mapping answers to tags
The mapping is what powers automated routing. When someone answers “This vendor will process employee data,” Coverbase applies the Employee Data tag, which then triggers specific control sets and document requests.Pattern: auto-escalating vendors to Critical
A common requirement is that if a vendor answers “yes” to two or three specific questions, they should land in the strictest track regardless of overall score. Use two mechanisms together for redundancy:- Weight those questions heavily, so any “yes” pushes the score into your critical band on its own.
- Map those answers to a tag that routes the vendor to the stricter due-diligence track, with control sets and document requirements keyed to that tag.
Step 5: Configure risk and compliance scales
Scales define the bands your program scores against. There’s the vendor-level risk scale and the per-control compliance scale.- Go to Configuration → Scales → Risk Scale. The default bands are 0 to 25 low, 25 to 50 medium, 50 to 75 high, and 75 to 100 critical. Every threshold is adjustable, and you can add or remove tiers, collapse to three, or lower the critical threshold.
- Review the compliance scale used on controls. The default runs from 4 (fully compliant) down to 1 (not compliant). You can rename levels, add or remove them, or make it boolean.
- Write real criteria into each level, and don’t stop at labels. The criteria text gets used when scores are assigned, so “one or more failing conditions met” is more useful than a bare “low.”
- Add custom assessment scales if your program rates other dimensions, like RFP alignment, ESG alignment, or contractual protection.

The risk scale. Adjustable bands from low through critical, each with real scoring criteria.

The compliance scale used on individual controls. Rename, add, remove, or make it boolean.
Common custom scales beyond compliance
Common custom scales beyond compliance
- RFP alignment: Exceeds, Meets, Partially meets, Does not meet requirements
- ESG alignment: Strong, Developing, Limited, No ESG program
- Contractual protection: Strong (indemnification, insurance, SLAs), Standard, Limited, Inadequate
Step 6: Upload and tune control sets
Control sets are what assessments measure against. They define what “good” looks like. Coverbase ships with SIG, NIST (CSF and AI RMF), ISO 27001, NYDFS, FFIEC, PCI DSS, DORA, and more out of the box, and your own frameworks import from a spreadsheet.
The control set library. Built-in frameworks plus your own, each with its controls, versions, and applicable vendors.
Importing your own controls
- Go to Control Sets and click + New Control Set → Upload Spreadsheet. Download the template workbook and the tips document from that dialog; that’s where the current version always lives. In the workbook, the Controls tab is the one that gets imported; the Instructions tab carries the tips, and the Document Types and Risk Domains tabs are there for reference.
- Use an LLM to convert your existing framework (from your GRC tool, a spreadsheet, wherever it lives) into the template format. Paste your controls plus the tips doc and ask for the conversion.
- Upload one control set at a time and verify the import. Start with your two or three most critical frameworks.

The Upload Control Set dialog. Download the template first, fill in the Controls sheet, and drop the file back here. The tips link opens the writing guidance.
Per-set configuration
Every control has three parts: the expectation (what you’re measuring), the question (how it would be asked of a vendor if evidence is missing), and the guidance (how the AI should evaluate it). Then, per set:- Applicability: map which tags and inherent-risk levels this set applies to. This is what makes assessment assignment automatic.
- Risk domains: assign controls to domains like InfoSec, compliance, or operational resilience, so review work can later be split across specialists.
- Strictness: set the evaluation toggle (lenient, standard, or strict) per set.
- Evidence sources: choose what the AI may draw on per control, from specific document types to web search to a vendor’s Vendor Intelligence. These combine and can be prioritized, so you might put the information security policy first and web search as a fallback.
- Minimum credibility: on each web-search source, set how accountable a publisher has to be before its page can be cited: No minimum, Reputable (the default), or Authoritative. Pages below the bar are discarded before the AI reads them. See Evidence quality and source credibility for the scale, where to tighten it, and what it doesn’t cover.
- Restrict evidence to these sources: on by default once you add evidence sources at the set level, this keeps the analysis inside the sources you listed. Turn it off when you want to ask the vendor for particular document types without narrowing what the AI may read. The sources still drive the portal request and stay the AI’s first stop, but other submitted documents remain admissible. Evidence sources set on an individual control always restrict that control.
- Document requirements: mark documents required or suggested. Required blocks portal submission until the document is uploaded, so use it sparingly.
A document-requirements pattern that works
A document-requirements pattern that works
Per-control tuning
Open any control to edit its expectation, weight, and guidance. Guidance is where conditional logic and exceptions live, like “mark fully compliant if the vendor is not a professional services company with a physical on-site presence,” or “accept an infosec training attestation as sufficient evidence.”Step 7: Assessment plans and reassessment cadence
This step decides which assessment a vendor gets, and when they get looked at again.- Build assessment plans that bundle control sets by tier, so high and critical vendors get the fuller plan. Plans can be assigned statically or dynamically off tags and inherent risk.
- Set the reassessment cadence in assessment settings. It defaults off residual risk (low might be every three years), but it can key off inherent risk instead, and it’s fully overridable per vendor.
- Layer on trigger-based reassessments so a Radar event or a risk-score change can open an off-cycle review automatically.

Assessment plans bundle control sets by tier and assign automatically from tags and inherent risk.

Reassessment cadence. A default per risk tier, fully overridable per vendor, with trigger-based off-cycle reviews.
A sensible starting cadence
A sensible starting cadence
- Critical: every 12 months
- High: every 24 months
- Medium: every 36 months
- Low: manual only
Step 8: Report and email templates
This step makes every output, whether an assessment readout or a vendor email, land in your organization’s format and voice. For report templates, go to Configuration → Assessment Settings → Assessment Report Templates. Build a branded template using tokens (fields from the assessment and vendor record) plus custom AI prompts for freeform sections, like “give a meaningful analysis of the limitation of liability as it relates to their DPA.” If you don’t have a house format yet, start from the Coverbase best-practice template with your branding.
The report template builder. Tokens pull structured fields, and custom AI prompts fill freeform sections in your voice.
.docx will want the full reference open alongside it. Tokens are called placeholders in those pages.
Custom Word report templates
.docx: placeholder syntax, AI prompt sections, repeating findings tables, signature anchors, and what happens when a placeholder cannot be filled.Placeholder reference

Vendor email templates. Sender identity, instructions, reminder cadence, and an attached pre-signed MNDA.
Step 9: Configure Radar (continuous monitoring)
Radar is the external intelligence layer. Sources feed detectors, and detectors raise alerts on your third and fourth parties.- Review the out-of-the-box sources: SEC filings, CVE feeds, CISA advisories, and security and financial news, all pulled several times a day. Add any public RSS feed at no extra cost, or connect a ratings platform like Black Kite as an API source.
- Create detectors around what you actually act on, such as breaches and vulnerabilities, supply-chain disruption, or SEC and regulatory actions. Each detector takes plain-language guidance, example events to hone in on, impacted risk domains, and a severity threshold.
- Test each detector before you enable it, and start with tight severity thresholds.

Radar detectors. Each one is scoped to what you'll act on, with categories, reviewers, and an enable toggle.

Radar sources. Built-in feeds plus any public RSS feed or connected ratings API.
Step 10: Enable obligations extraction
This step turns on extraction of what vendors require of you: CUECs from SOC reports (pulled verbatim) and shared responsibilities from contracts, DPAs, and terms.- In settings, enable auto-create for CUECs and obligations from uploaded documents, and confirm which document types trigger extraction (SOC 1 Type 2, SOC 2 Type 2, contracts).
- Re-trigger analysis on documents you uploaded before you enabled this. Extraction only runs on documents processed after the setting is on.
- Optionally, upload your internal control set so extracted obligations can be checked automatically against controls you already have in place.

Obligations extraction settings. Auto-create CUECs and shared responsibilities from the document types you choose.
Step 11: Integrations and Export API (optional)
This step exposes Coverbase data to external systems like GRC platforms, ticketing, and data warehouses.- Go to Organization → API Keys → Add new key, name it, set an expiration, and store the bearer token securely.
- Go to Configuration → Export API and map which Coverbase objects and fields to expose. Note the source schema and GET endpoint shown on screen.
- For GRC integrations (findings out to your audit platform, controls back in), scope what needs to flow with your Coverbase contact, whether that’s findings, residual-risk ratings, or control-environment scores.

The Export API configuration. Map objects and fields, then read the source schema and GET endpoint right on screen.
Admin quick reference
Five rules that save the most grief:Changes aren't retroactive
Weight before you launch
Tags drive everything
Required means blocking
Guidance beats strictness
Frequently asked questions
How long does initial setup take?
How long does initial setup take?
Do we need to configure all control frameworks at once?
Do we need to configure all control frameworks at once?
What if we don't have an existing IRQ?
What if we don't have an existing IRQ?
How does AI assessment actually work?
How does AI assessment actually work?
What if the AI makes a mistake?
What if the AI makes a mistake?