Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This guide is part of the User Guides collection. It is for the TPRM program owner or administrator setting up the environment. Once setup is done, your analysts pick up the Analyst and reviewer guide.
This guide takes you from a blank environment to a configured one. You will import vendors, build the inherent risk questionnaire (IRQ), tune scales and control sets, and configure the templates, monitoring, and integrations that everything downstream depends on. Configuration is where the AI gets its instructions. The better this upfront work, the fewer issues your reviewers triage later. Most teams finish core setup in 1 to 2 weeks with roughly 20 hours of effort, and your Coverbase contact runs live working sessions to do it alongside you.
If you are new to the platform, read the short How Coverbase thinks primer first. The quick version: Coverbase is document-first (it measures vendor evidence against your controls), tags drive most of the automation, and configuration changes apply going forward, never retroactively.

Setup checklist

Each item below is a step in this guide.
1

Users and branding

Add your team and apply your organization’s branding.
2

Vendor portfolio

Import your existing vendor inventory.
3

Tag structure

Create the tags that route everything.
4

IRQ

Build, weight, and map your intake questionnaire.
5

Scales

Configure your risk and compliance scales.
6

Control sets

Upload, tune, and map your control frameworks.
7

Plans and cadence

Set assessment plans and reassessment timing.
8

Templates

Build report and vendor-email templates.
9

Radar

Configure continuous-monitoring sources and detectors.
10

Obligations

Turn on obligations and CUEC extraction.
11

Integrations

Connect the Export API and external tools (optional).

Step 1: Organization, users, and branding

This step gets your team into the platform and makes everything vendor-facing and stakeholder-facing carry your brand.
  1. Go to Configuration → Organization, open Members, and choose Invite. Everyone in one batch of invitations gets the same role, so invite in groups:
    • Admin has full platform access, including members, roles, integrations and organization settings.
    • Member creates and edits vendors, assessments, findings and intake requests across the organization. Most of the risk team starts here.
    • Auxiliary Member answers inherent-risk questionnaires, completes tasks assigned to them, and comments on records they are assigned to.
    The other default roles (Siloed Member, Guest and Service Account) are described in Permissions and roles.
  2. For a broader rollout, add your email domain under Verified domains on General, so people with that domain can join automatically or request to join. That saves you from creating accounts by hand while you pilot.
  3. On Branding, set your brand. The Logo is a square icon shown in the app and the vendor portal header. The Full Logo is a wordmark or logotype used in reports and emails. Brand color sets the accent for the vendor portal background. Organizations on the redesigned Organization settings find members under People (choose Invite people) and the brand on General, where the square mark is the Icon and the logotype is the Wordmark.
Coverbase organization and branding settings

Configuration → Organization → Branding. Your logo and full logo flow into the app, reports, emails, and the vendor portal.

Vendors receiving an assessment request should see your brand, not Coverbase’s. Provisioning from verified domains means your pilot team can start testing right away.
Logos and colors cover the visual identity. For the domain vendor email sends from and the portal is hosted on, see White-labeling your vendor-facing domain.

Step 2: Import your vendor portfolio

Loading your existing vendor inventory gives assessments, monitoring, and redundancy checks something to work against. It becomes the library you run reassessments and continuous monitoring from. You need your vendor list with attributes like name, website, description, relationship owner, and contract dates. Your Coverbase contact can hand you the bulk-upload template, along with an enrichment workflow that fills in missing fields.
  1. On the Vendors page, open Actions → Bulk Create Vendors.
  2. Choose Download template to see the fields, then map your existing data into it. The first sheet (vendor intake) is required and the second (service intake) is optional.
  3. Upload your file.
  4. Validate the result. Confirm the vendor count matches your source file, and spot-check a few records to make sure the field values populated correctly.
Bulk create vendors import screen

Bulk Create Vendors. Map your existing list into the template and import your whole portfolio at once.

Start with your top 100 to 200 vendors rather than the entire database. That lets you refine the configuration before scaling. You can also pre-load historical documents (SOC 2s, contracts, policies) against vendor records, so your first assessments run against real evidence instead of an empty set.

Step 3: Create your tag structure

Tags are the routing layer of the platform. IRQ answers apply tags, and tags then decide which control sets apply, which documents are required, and which due-diligence track a vendor gets. Design the taxonomy before the IRQ, because the IRQ is what fills it in. The structure below works well in practice. Adapt it to your program.

Criticality

Standard, Important, Business Critical, Mission Critical

Data

PII, PHI, Financial, Employee, plus flow and volume tags (Inbound, Outbound, Bidirectional, High Volume, Low Volume, No Data Access)

Access

Login access, PII access, On-premise, Foreign vendor

Geography

US Only, EU/EEA, UK, APAC, International

Infrastructure

Public Cloud, Private Cloud, Hybrid, On-Premise, Not Applicable

Size and profile

Startup through Enterprise, plus SaaS, Consultant, Facilities, Financial, Operations
To set this up, go to Configuration → Tags, create a tag section for each category, and add the individual tags within each section with New tag.
Tag structure configuration grouped by category

The Tags configuration screen. One card per tag section, and a search box across every tag.

A plain high/medium/low rating says a vendor is risky. Tags say why it is risky and how it should be assessed, which is what the automation needs. Almost everything you configure later keys off tags: a “Foreign” tag routes to extra controls, a “PCI” tag makes a PCI AOC required, an “AI SaaS” tag can attach a different clause set.

Step 4: Build and weight your IRQ

The inherent risk questionnaire is what business requesters, and Coverbase’s research agent, answer at intake. Its weights produce the inherent risk score, and its response mapping applies your tags. Aim for 15 to 25 concise questions.
  1. Go to Configuration → Questionnaires, stay on the Inherent Risk tab, and choose Create Questionnaire, or start from a packaged template with IRQ Library (see The IRQ library). Use Actions → Bulk Import Questions to import an existing IRQ from a spreadsheet instead of building it question by question.
  2. Give every answer a Value: its risk weight, where higher means more risk. The sum of all maximum answer values is the risk ceiling, and a vendor’s actual answers as a percentage of that ceiling is their inherent risk score.
  3. Hover a question and choose Configure write-back to map answers to tags. Data handled outside the US applies “Foreign”, card data applies “PCI”, and so on. Questions built before write-back existed show Configure Response Mapping instead.
  4. Add conditional logic where a follow-on question should only appear based on a prior answer, like asking for data-flow details only if data is exchanged.
  5. Set per-question AI guidance to control what the research agent may use when it auto-answers. For example, “only source from the vendor’s trust center, exclude blogs and CVE chatter.”
  6. Mark judgment questions as Required so the AI never auto-answers them without human input.
Inherent Risk Questionnaire builder with weighted answers

The IRQ builder. Each answer carries a value (right column), and Configure write-back links answers to the tags that route the vendor.

Weight the template before your first real intake. An answer left at zero adds nothing to the score, so an unweighted IRQ makes inherent risk read artificially low across your whole portfolio, and an API vendor can score like a stationery supplier.

Example: mapping answers to tags

The mapping is what powers automated routing. When someone answers “This vendor will process employee data,” Coverbase applies the Employee Data tag, which then triggers specific control sets and document requests.

Pattern: auto-escalating vendors to Critical

A common requirement is that if a vendor answers “yes” to two or three specific questions, they should land in the strictest track regardless of overall score. Use these mechanisms together for redundancy:
  • Set a Score override on those answers (the menu beside the option). While the answer is selected, the questionnaire’s overall score cannot fall below the percentage you enter, so a single “yes” can hold the vendor in your critical band.
  • Weight those questions heavily, so any “yes” pushes the score up on its own.
  • Map those answers to a tag that routes the vendor to the stricter due-diligence track, with control sets and document requirements keyed to that tag.
Scored multi-select questions with precedence logic also work here. A data-elements question can max the weight the moment someone selects PAN, for instance.

Step 5: Configure risk and compliance scales

Scales define the bands your program scores against. There are two: the vendor-level risk scale and the per-control compliance scale.
  1. Go to Configuration → Scoring and open the Risk Scoring tab. The default bands are 0 to 25 low, 25 to 50 medium, 50 to 75 high, and 75 to 100 critical. Every threshold is adjustable, and you can add or remove tiers, collapse to three, or lower the critical threshold.
  2. On the Control Scoring tab, review the compliance scale used on controls. The default runs from 4 (fully compliant) down to 1 (not compliant). You can rename levels, add or remove them, or make it boolean.
  3. Write criteria into each level, not only labels. The criteria text is used when scores are assigned, so “one or more failing conditions met” is more useful than a bare “low.”
  4. Add custom assessment scales with New Scale on the Control Scoring tab if your program rates other dimensions, like RFP alignment, ESG alignment, or contractual protection.
  5. Under Risk Display on the Risk Scoring tab, choose whether residual risk is shown at all (Track residual risk) and whether numeric scores appear next to risk levels (Display numerical scores). Scores are still calculated and stored either way.
Risk scale configuration with adjustable bands

The risk scale on the Risk Scoring tab. Adjustable bands from low through critical.

Compliance scale configuration

The compliance scale on the Control Scoring tab, used on individual controls. Rename, add, remove, or make it boolean.

  • RFP alignment: Exceeds, Meets, Partially meets, Does not meet requirements
  • ESG alignment: Strong, Developing, Limited, No ESG program
  • Contractual protection: Strong (indemnification, insurance, SLAs), Standard, Limited, Inadequate
Different risk domains need different criteria. Your legal team evaluating contract terms uses a different scale than your InfoSec team evaluating technical controls. Custom scales let each domain score its own way while keeping the overall picture consistent.

Decide whether service scores set the vendor’s score

A service-scoped assessment scores the services it covers. By default it leaves the vendor’s own score alone, so a vendor can read medium while one of its services reads high. Risk Roll-up changes that. It sits under Configuration → Scoring on the Risk Scoring tab, below the risk scale. There is one switch per risk type:
  • Roll up inherent risk from services
  • Roll up residual risk from services
With a switch on, each vendor takes the highest score among its services for that risk type, not the average. Services with an inactive, discontinued, or denied status are excluded. Retiring the service that set the score moves the vendor to the next highest live one. The two risk types are set separately. You can roll up residual risk and leave inherent risk manual.
Risk Roll-up settings with inherent and residual switches and the Recalculate existing vendors action

Risk Roll-up on the Risk Scoring tab. One switch per risk type, and a separate action for the vendors you already have.

Turning a switch on does not change existing scores. It applies to scores set from that point on. To apply it to vendors you already have, use Recalculate now under Recalculate existing vendors. It rewrites the score of every vendor without an override, asks you to confirm first, and cannot be undone.
Recalculation runs in the background, so a large portfolio takes a few minutes. With both switches off, the button reports that there is nothing to recalculate. Individual vendors can override this setting. See Where a vendor’s score comes from.

Step 6: Upload and tune control sets

Control sets are what assessments measure against. They define what “good” looks like. Coverbase ships with SIG, NIST (CSF and AI RMF), ISO 27001, NYDFS, FFIEC, PCI DSS, DORA, and more out of the box, and your own frameworks import from a spreadsheet. If you buy physical goods rather than software, look under Operations & Supply Chain in the Vendor Controls Library. Those templates ask a supplier whether it can keep your production line fed (continuity testing, alternate sourcing, batch traceability, chain of custody, restricted substances) rather than how it secures a network. The Control Set library lists all of them.
Controls page with a control set open and the New Control Set menu showing Upload Spreadsheet

The Controls page. Your control sets on the left, each with its controls, versions, and applicable vendors. Vendor Controls Library opens the packaged frameworks, and New Control Set offers Upload Spreadsheet.

Importing your own controls

  1. Go to Configuration → Controls and click New Control Set → Upload Spreadsheet. Download the template workbook and the tips document from that dialog, which always holds the current version. In the workbook, the Controls tab is the one that gets imported; the Instructions tab carries the tips, and the Document Types and Risk Domains tabs are there for reference.
  2. Use an LLM to convert your existing framework (from your GRC tool, a spreadsheet, wherever it lives) into the template format. Paste your controls plus the tips doc and ask for the conversion.
  3. Upload one control set at a time and verify the import. Start with your two or three most critical frameworks.
Upload Control Set dialog with a Download template button and a tips link

The Upload Control Set dialog. Download the template first, fill in the Controls sheet, and drop the file back here. The tips link opens the writing guidance.

Per-set configuration

Every control has three parts: the expectation (what you are measuring), the question (how it would be asked of a vendor if evidence is missing), and the guidance (how the AI should evaluate it). Then, per set:
  • Applicability: map which tags and inherent-risk levels this set applies to. This is what makes assessment assignment automatic.
  • Risk domains: assign controls to domains like InfoSec, compliance, or operational resilience, so review work can later be split across specialists.
  • Strictness: set the evaluation toggle (lenient, standard, or strict) per set.
  • Evidence sources: choose what the AI may draw on per control, from specific document types to web search to a vendor’s Vendor Intelligence. These combine and can be prioritized, so you might put the information security policy first and web search as a fallback.
  • Minimum credibility: on each web-search source, set how accountable a publisher has to be before its page can be cited: No minimum, Reputable (the default), or Authoritative. Pages below the bar are discarded before the AI reads them. See Evidence quality and source credibility for the scale, where to tighten it, and what it does not cover.
  • Restrict evidence to these sources: on by default once you add evidence sources at the set level, this keeps the analysis inside the sources you listed. Turn it off when you want to ask the vendor for particular document types without narrowing what the AI may read. The sources still drive the portal request and stay the AI’s first stop, but other submitted documents remain admissible. Evidence sources set on an individual control always restrict that control.
  • Document requirements: mark documents required or suggested. Required blocks portal submission until the document is uploaded, so use it sparingly.
SOC 2 and pen test required. PCI AOC required only for PCI-tagged vendors. A bridge letter left as a suggested remediation when a SOC 2 is past your currency window. Everything else suggested. Default to suggested unless it is a hard gate.

Per-control tuning

Open any control to edit its expectation, weight, and guidance. Guidance is where conditional logic and exceptions live, like “mark fully compliant if the vendor is not a professional services company with a physical on-site presence,” or “accept an infosec training attestation as sufficient evidence.”
You do not have to write guidance up front. Reviewers refine it from real results using Correct the AI (see the Analyst and reviewer guide), and every accepted correction applies to all future assessments. Specific guidance is more effective than raising the global strictness toggle, and easier to defend to a regulator.
Not every framework covers every topic. NIST CSF, for example, does not explicitly cover penetration testing. When your program cares about something a framework does not name, add a control for it and point the guidance at the specific evidence.

Step 7: Assessment plans and reassessment cadence

This step decides which assessment a vendor gets, and when they get looked at again.
  • Build assessment plans that bundle control sets by tier, so high and critical vendors get the fuller plan. Plans can be assigned statically or dynamically off tags and inherent risk.
  • Set the reassessment cadence under Periodic Re-assessment Settings in Configuration → Assessment Settings. The Timeline sets how many days before the reassessment date stakeholder reminders go out, document collection starts, and the assessment should be ready for review. Each Reassessment rule names an assessment plan, the risk levels it covers, and the Months between reassessments. Rules match suppliers on inherent risk level by default; set Match suppliers on to residual risk level to key off residual instead (a supplier with no residual level yet falls back to inherent). A vendor’s next reassessment date can still be changed by hand.
  • Layer on trigger-based reassessments so a Radar event or a risk-score change can open an off-cycle review automatically.
Assessment plans configuration

Assessment plans on Configuration → Assessment Settings. Each plan bundles control sets and questionnaires with its scope, collection mode and assignee.

Edit assessment plan dialog with default control sets, conditional rules and the Configure reassessment rules link

Editing an assessment plan. Default control sets and questionnaires, conditional rules that add control sets by risk score, and Configure reassessment rules to set this plan's cadence.

  • Critical: every 12 months
  • High: every 24 months
  • Medium: every 36 months
  • Low: manual only
Manual reassessment tracking goes stale at scale and vendors slip through. Automated schedules keep the oversight consistent without the admin overhead.

Step 8: Report and email templates

This step makes every output, whether an assessment readout or a vendor email, land in your organization’s format and voice. For report templates, go to Configuration → Assessment Settings and turn on Assessment report templates. Build a branded template using tokens (fields from the assessment and vendor record) plus custom AI prompts for freeform sections, like “give a meaningful analysis of the limitation of liability as it relates to their DPA.” If you do not have a house format yet, start from the Coverbase best-practice template with your branding.
Assessment report template builder

The report template builder. Tokens pull structured fields, and custom AI prompts fill freeform sections in your voice.

Whoever writes the .docx will want the full reference open alongside it. Tokens are called placeholders in those pages.

Custom Word report templates

How to author the .docx: placeholder syntax, AI prompt sections, repeating findings tables, signature anchors, and what happens when a placeholder cannot be filled.

Placeholder reference

Every placeholder available, what it resolves to, and how each value is formatted.
Three exports come built in: Standard PDF, Executive Summary, and Full (every control with all evidence, the one examiners like).
For vendor email, go to Configuration → Communications. Organization identity at the top sets the sender name, the sender address and the inbound contact vendors should reach. The Templates list holds the wording of portal invitations and follow-ups: each template carries AI instructions, default CC and BCC recipients (add the internal requester here), and attachments. Attach a pre-signed MNDA to invitations so legal back-and-forth does not stall document sharing. The reminder cadence (every two days, for example) lives on the portal template under Configuration → Portals.
Communications settings with the organization identity and the email templates list

Configuration → Communications. Organization identity sets who vendor email comes from; the Templates list below holds the wording.


Step 9: Configure Radar (continuous monitoring)

Radar is the external intelligence layer. Sources feed detectors, and detectors fire on the events that matter, which reach your analysts as signals. Sources and detectors live under Configuration → Radar. The Configurations menu on the Radar page opens its Detectors, Sources and Reassessments tabs.
  1. Review the out-of-the-box sources: SEC filings, CVE feeds, CISA advisories, and security and financial news, all pulled several times a day. Add any public RSS feed at no extra cost, or connect a ratings platform like Black Kite as an API source.
  2. Create detectors around what you act on, such as breaches and vulnerabilities, supply-chain disruption, or SEC and regulatory actions. Each detector takes plain-language guidance, example events to focus on, impacted risk domains, and a severity threshold. Switch on its risk impact, and set the point range, if acting on its signals should move residual risk (see risk propagation).
  3. Test each detector before you enable it, and start with tight severity thresholds.
Radar detector configuration list

Radar detectors, under Configuration → Radar. Each one is scoped to what you will act on, with its categories and reviewers.

Radar sources configuration

Radar sources, under Configuration → Radar. Built-in feeds plus any public RSS feed or connected ratings API.

The failure mode of continuous monitoring is noise. One event makes one signal however many detectors fire, but a loose detector still fires on every routine patch note, and a single well-covered vendor can produce a dozen of those in a week. Keep detectors narrow and severities high at first, watch what fires for two weeks, then loosen. Fourth-party relationships are extracted automatically from SOC 2s and subprocessor lists, so one event can implicate many vendors at once.

Step 10: Enable obligations extraction

This step turns on extraction of what vendors require of you: CUECs from SOC reports (pulled verbatim) and shared responsibilities from contracts, DPAs, and terms.
  1. Go to Configuration → Obligations and turn on Auto-create obligations from vendor CUECs (from SOC reports) and Auto-create obligations from contract shared responsibilities (from contracts).
  2. Re-trigger analysis on documents you uploaded before you enabled this. Extraction only runs on documents processed after the setting is on.
  3. Optionally, upload your internal control set so extracted obligations can be checked automatically against controls you already have in place. If a matched obligation should wait for a business unit to confirm it before it counts as satisfied, also turn on Require business-unit acknowledgement.
Obligations settings with the two auto-create switches and the business-unit acknowledgement switch

Configuration → Obligations. One switch each for CUECs and contract shared responsibilities, and one for business-unit acknowledgement.

The full obligations workflow (validation, ownership, and business-unit acknowledgement) is in the Obligations guide.

Step 11: Integrations and Export API (optional)

This step exposes Coverbase data to external systems like GRC platforms, ticketing, and data warehouses.
  1. Go to Configuration → Organization → API keys and choose Add new key. Name it, set an expiration, and store the bearer token securely: a key is shown once, when it is created.
  2. Go to Configuration → Coverbase API, stay on the Export API tab, and choose New Export Report. Pick the object the report returns and map which fields to expose. Note the GET endpoint shown on screen.
  3. For GRC integrations (findings out to your audit platform, controls back in), scope what needs to flow with your Coverbase contact, whether that is findings, residual-risk ratings, or control-environment scores.
Export API configuration

The Export API configuration. Map objects and fields, then read the source schema and GET endpoint right on screen.

Coverbase uses a pull model. External systems request data via the API, and there is no automatic push. You can also connect vendor status pages for SLA-adjacent monitoring. For the full developer reference, see the Export API concepts.

Admin quick reference

Five rules:

Changes are not retroactive

IRQ and control-set edits apply going forward. Use a bulk reassessment to apply new standards to existing vendors. Control sets are version-controlled, so an edit creates a new version.

Weight before you launch

Zero-value IRQ scores are the most common cause of “why is everything low risk?”

Tags drive everything

Control-set applicability, document requirements, clause sets, and escalation tracks all key off tags. Keep the taxonomy clean.

Required means blocking

A required document stops portal submission entirely. Default to suggested unless it is a hard gate like a PCI AOC.

Guidance beats strictness

Specific control guidance (who is exempt, what evidence counts) is more effective than the global strictness toggle, and easier to defend to a regulator.

Frequently asked questions

Most organizations finish core configuration in 1 to 2 weeks with roughly 20 hours of effort. Organizations with complex control sets or a lot of integrations may need 4 to 6 weeks.
No. Start with your two or three most critical frameworks, usually NIST CSF and one industry-specific standard. Add more as your program matures.
Use Coverbase’s enhanced template. It includes industry best practices and can be customized to your requirements.
When you start an assessment, Coverbase searches the vendor’s website, trust center, and security documentation, analyzes uploaded documents like SOC 2 reports and contracts, pulls data from integrated services, and evaluates all of it against your control requirements. It surfaces gaps as issues for human review and generates follow-up questions only for what it could not verify.
Coverbase assumes the AI will make errors. Every assessment includes a human review phase where your team validates findings before finalizing, and every result carries citations, so errors are easy to spot and correct. In practice the AI drafts most of the assessment and your team quality-checks the rest.

You’re set up. Now run the work

With the environment configured, your analysts can start assessing vendors.

Analyst and reviewer guide

The day-to-day: triage, assess, review, correct, follow up, and report.

Assessment quick reference

A one-page cheat sheet to keep open while you work.

Need help?

Email support@coverbase.ai, or ask your Coverbase contact to run a live working session with your team.