Triage intake
Launch assessment
Review issues
Correct the AI
Follow up
Disposition and report
Watch Radar
Step 1: Triage new vendor requests
New requests arrive from business requesters already enriched with sanctions, financials, security posture, and a redundancy check against your existing portfolio. Most IRQ questions come pre-answered by the research agent.- Open the pending submission and scan the enrichment readout. A red flag on sanctions is a fuzzy match to investigate, and an unknown vendor with no public presence also flags red.
- Check the redundancy readout. If the vendor, or a comparable tool, already exists in your portfolio, this may be a new service on an existing record rather than a new onboarding.
- Review the auto-answered IRQ. A “limited information” flag means the AI couldn’t confirm authoritatively, not that a problem exists. Click the reviewed checkbox on each answer you validate. Your name and timestamp get recorded.
- Answer anything flagged for manual input, usually the judgment questions your admin marked Required.
- If something’s ambiguous, use Request Clarification to send a templated email back to the requester before approving.
- If the requester misidentified an existing vendor, approve the submission and use the vendor record merge function to consolidate it under the parent record.
- Accept to kick off onboarding. The right assessment plan attaches automatically based on tags and inherent risk.
- Pre-Qualification runs on the vendor name at step 1 and tells the requester if the vendor is already onboarded, or if an approved vendor already covers the use case. It’s the cheapest risk reduction in the whole process, and it’s why some requests never reach you.
- The autofilled IRQ at step 3 arrives with a confidence badge per answer (green High confidence, amber Review this response) and the reasoning and sources behind each one. Work the amber ones first; amber means Coverbase wasn’t confident, and the reasoning usually names exactly what was missing.

The intake queue. New requests arrive pre-enriched and pending review, each with its use case, services, and status.

Inside a submission. The enrichment and redundancy readouts, plus the auto-answered IRQ you validate answer by answer.
Step 2: Launch an assessment
Launching an assessment opens the review. It attaches control sets, kicks off document collection, and runs the analysis.- Open the vendor record, then go to Assessments → New Assessment. Choose vendor-level or service-level scope. Multiple assessments can coexist, and one assessment can carry multiple control sets at once, like SIG core plus your own InfoSec set.
- Pick the Assessment Plan. This is the whole of the setup: control sets and questionnaires aren’t chosen assessment by assessment, they come from the plan. Selecting one shows a summary: how many control sets and questionnaires, manual or automatic collection, whether it targets residual risk, and who reviews it. Read that summary; it’s the fastest way to catch a plan that’s heavier or lighter than the vendor warrants. Leaving it on None creates an assessment with no control sets attached.
- Add more than one vendor if you’re starting a batch. Each gets its own assessment from the same plan, which is how annual reviews are best run. The button reads Create Assessments for that reason.
- Let evidence collection run. The Documents tab offers five routes that combine freely, each showing how much is available before you click: Import from existing vendor docs, Request from vendor (the portal, with its current status), Request automatic collection, Import from Coverbase Library (curated documents Coverbase already holds, often substantial for well-known vendors), and Retrieve from Trust Center (needs a Trust Center URL on the vendor record). Below the cards, Upload vendor documents takes files you hold yourself. In automatic mode Coverbase pulls from its library first, then scrapes the vendor’s trust center for anything ungated (it form-fills access requests for gated documents), before falling back to asking the vendor.
- Where the vendor has to be engaged, send the portal invitation with a due date. Reminders and the pre-signed MNDA your admin configured go out automatically. The vendor can’t submit until the required items are done, and when they upload, analysis of the affected controls starts on its own.
- Analysis takes roughly 5 to 10 minutes on a small evidence set and 20 to 30 minutes when there’s a lot to read. A long SOC 2 takes considerably longer than a certificate of insurance. Large control sets add to it, and a full SIG core is around 300 questions. You don’t need to keep the tab open.

The assessment workspace. Control sets attached in the left rail, and the lifecycle (collected documents, then analyzed controls, then reviewed results) tracked as it runs.
Step 3: Review the results
The AI has measured every document against every control and raised issues where evidence is missing or contradicts the expectation. Your job is judgment, in a deliberate order.- Start in the Critical Findings view, not the full issue list. Triage the material items first.
- Toggle Assign to Me to filter to your controls. Issues can be assigned per risk domain (InfoSec to InfoSec SMEs, and so on) or round-robin across the team.
- Open each issue. You’ll see the expectation, the guidance the AI used, and the analysis citing the specific evidence. Click through to the source language to validate. Never take the summary on faith for a material item.
- Spot-check compliant controls too, especially early on. Passes show the same full evidence chain, plus web-sourced supporting articles, and this is how you catch false negatives while you build trust in the output.
- Where two control sets overlap, say SIG core and the out-of-box SOC 2 set raising the same gap twice, mark the duplicate as not an issue and tell your admin to drop the redundant set from future assessments.

The review workspace. Results grouped by control set, with each issue's status, score, and reason (Missing document, Incomplete response, and so on).

An issue in detail. The expectation, question, and guidance on the left; the AI's cited analysis and the actual source evidence on the right.
Step 4: Correct the AI
This is how you turn a wrong or noisy result into a permanent improvement. You edit the control’s guidance, rerun it on the spot, and if you accept, the change applies to every future assessment.- On the issue, choose Correct the AI.
- Write the missing condition into the guidance. Be specific.
- Rerun the control and confirm the result changes as expected.
- Accept to save globally, or discard.

Correct the AI. Edit the guidance, rerun the control, and accept to make the fix permanent across all future assessments.
Real corrections from live reviews
Real corrections from live reviews
- A clean desk policy flagged for a SaaS vendor. Added “mark fully compliant if the vendor is not a professional services or contracting company with a physical on-site presence.” The rerun resolved to no issue.
- SOC 2 currency. Tightened the default 12-month window to 6 months on the control, and the draft vendor follow-up regenerated itself to reflect the new window.
- Employment contractual agreements. Added “accept an information security training attestation as sufficient evidence.” The issue resolved and saved for all future assessments.
Step 5: Follow up with the vendor
For genuine gaps, you send the vendor a contextualized question that references what they already submitted, through the portal.- On an issue, choose Draft Follow-up and use AI Autofill. It writes the question in context (“we reviewed your SOC 2 and it doesn’t address X”) rather than pasting raw control text, which vendors respond to far better.
- For volume, select all issues, then Create Follow-ups. AI Autofill runs across the batch. Set the portal due date and send in one step.
- Pick the email template and add any vendor-specific instructions. The internal requester is CC’d automatically.
- The vendor answers and uploads new evidence directly in the portal, and responses flow back onto the issues.
- Saving a follow-up creates a draft, it doesn’t send. Follow-ups are drafted individually and sent together, so the vendor gets one consolidated request instead of a trickle of emails. The bar at the top of the Issues tab shows how many drafts are waiting, alongside Configure portal (what the vendor sees) and Manage sent follow-ups (what’s already out).
- Name the evidence you want. Under Required document types, say what the vendor should attach, so the request is specific rather than “please send evidence”. Use control question and response reuses the original control wording if the autofilled version isn’t right.
- Some vendors prefer a spreadsheet. Download workbook and Import responses on the Issues tab let a vendor work offline and come back in.
- Reanalysis is narrow. When the vendor submits, only the controls selected for follow-up run again. A result that comes back reads Response received and its analysis is rewritten to account for what the vendor said, often moving from Not Compliant to Fully Compliant where the gap was documentation rather than practice. To re-evaluate everything from scratch, say after changing the plan or control sets, use the rerun option from the assessment Actions menu instead.

Draft Follow-up with AI Autofill. A question written in the context of what the vendor already submitted.
Step 6: Reviews, disposition, and reporting
This closes the review. Domain reviewers sign off, every remaining issue gets a decision, the vendor gets a status and a reassessment date, and the record becomes a report.Domain reviews and quality control
Each risk domain can carry its own reviewer, which is what lets several teams work one assessment: InfoSec on the security domains, Legal on the contractual ones, Compliance on regulatory. The Summary tab reports progress as a count of completed reviews. A reviewer opens their domain with Start review. Until someone does, the domain shows Not started and its residual risk stays “Not set”.- Reviewers are set per domain or control set and can be changed at any time.
- Reviewers are notified when results are ready for them, and risk analysts and administrators can resend reminders.
- Your organization can optionally prevent anyone who isn’t a risk analyst or administrator from completing assessments.
Dispositioning issues
You have three dispositions per issue:Accept the risk
Keep the follow-up open
Promote to a finding
Completing and exporting
Click Complete Assessment on the Summary tab. The dialog asks for four things:- Action: approve, reject, or whichever outcomes your organization uses.
- Vendor Status: where this leaves the vendor in its lifecycle, for example Active. Custom statuses are supported.
- Next Vendor Reassessment Date: set for you from the risk tier and the completion date, typically a year out, and fully overridable if this vendor needs watching sooner. Anything unresolved converts to findings rather than getting deleted.
- Recommendation: the written conclusion that carries into exports, so write it properly rather than leaving it thin.

A completed assessment. Inherent risk, assessment score, and residual risk side by side, with the AI-generated executive summary and a recommendation.
Step 7: Contracts and clause reviews
The contracts module extracts key terms from MSAs, SOWs, and DPAs (value, effective date, term and renewal, indemnity, billing, data return) and compares vendor paper against your preferred language.- Upload the contract to the vendor’s Documents, setting the document type manually for MSAs, SOWs, and order forms.
- Open the Contracts module to review extracted terms and the clause inventory. You can also just ask in natural language: “what does this agreement say about insurance?” queries across all of the vendor’s agreements at once.
- Run a clause review against your organization’s clause sets. The output shows deltas from your acceptable, fallback, and unacceptable tiers, by severity. This is materiality analysis, not redlining. Actual redlines stay in Word.
- Triage each flagged clause: no action, accepted risk, false positive, or create a finding. Triaging is the review, and it’s what clears the flag list.
- Generate follow-up drafts for negotiation points, export the review to Excel, or assign it to legal in-platform.
Contract Guardian guide
Document Insights guide

A contract record. Extracted lifecycle, value, and term dates, plus an AI summary of parties, billing, SLAs, liability, and termination.

Extracted contract terms. Value, effective date, term and renewal, and more, pulled straight from the paper.

A clause review. Vendor language scored against your acceptable, fallback, and unacceptable tiers, by severity.
Step 8: Work Radar alerts
Radar watches external sources for events touching your third and fourth parties. Your job is to turn signal into action, and keep noise out of the program.- Review the alerts feed for your detectors. Fourth-party mapping means one event, say a compromised identity provider, surfaces every vendor exposed through it.
- Open a case on anything worth investigating (a case is preliminary, not yet a confirmed problem) and tag the affected vendors.
- Send a vendor inquiry from the case if you need their confirmation or remediation plan.
- Close the case if the vendor is unaffected. Promote it to a finding (owner and due date) if confirmed. Trigger an off-cycle reassessment straight from the event when warranted.
- If a detector keeps firing on non-actionable items, flag it. Detector guidance and severity thresholds are quick admin fixes.

The Radar dashboard. Events, incidents, assessments, and reassessments over time, with the alerts feed grouped by detector below.

Radar cases. Preliminary investigations tagged to affected vendors, ready to close, promote to a finding, or trigger a reassessment.
Step 9: Obligations at a glance
Alongside what you require of vendors, Coverbase extracts what vendors require of you: CUECs pulled verbatim from SOC reports, and shared responsibilities from contracts and terms. As a reviewer, you’ll validate extractions against source language, assign owners and due dates, and send attestation requests to business stakeholders through a trimmed-down portal.
Obligations. CUECs and shared responsibilities extracted from documents, ready to validate, assign, and send for attestation.
Frequently asked questions
How long does analysis take?
How long does analysis take?
Will the same assessment give identical results twice?
Will the same assessment give identical results twice?
What if the AI is wrong?
What if the AI is wrong?
Do vendors actually respond to the portal?
Do vendors actually respond to the portal?
Can Coverbase get documents from gated trust centers?
Can Coverbase get documents from gated trust centers?
What file formats work best?
What file formats work best?