Skip to main content
This guide is part of the User Guides collection. It’s for analysts, reviewers, and InfoSec SMEs doing daily vendor reviews. It assumes your environment is already configured. If you’re the one setting it up, start with the Admin and setup guide.This page is the wide view of the job. For a screen-by-screen walkthrough of one assessment from intake to export, see How to run an assessment.
Welcome. Coverbase reads vendor documents and measures them against your controls, so your job shifts from hunting through PDFs to judging results. A typical assessment measures a hundred-plus controls and raises a handful of material issues. In one real case, 111 controls produced 5. No prior Coverbase experience needed. Here’s the loop you’ll run:
1

Triage intake

Review enriched new-vendor requests.
2

Launch assessment

Attach control sets and let analysis run.
3

Review issues

Judge the material items, evidence in hand.
4

Correct the AI

Fix wrong or noisy results for good.
5

Follow up

Ask vendors only about genuine gaps.
6

Disposition and report

Decide, complete, and export.
7

Watch Radar

Turn monitoring signal into action.
Two habits make the whole thing work. Validate against source language, since every result carries citations you can click through. And correct the AI when it’s wrong, because corrections are permanent and the issue count drops with every cycle.

Step 1: Triage new vendor requests

New requests arrive from business requesters already enriched with sanctions, financials, security posture, and a redundancy check against your existing portfolio. Most IRQ questions come pre-answered by the research agent.
  1. Open the pending submission and scan the enrichment readout. A red flag on sanctions is a fuzzy match to investigate, and an unknown vendor with no public presence also flags red.
  2. Check the redundancy readout. If the vendor, or a comparable tool, already exists in your portfolio, this may be a new service on an existing record rather than a new onboarding.
  3. Review the auto-answered IRQ. A “limited information” flag means the AI couldn’t confirm authoritatively, not that a problem exists. Click the reviewed checkbox on each answer you validate. Your name and timestamp get recorded.
  4. Answer anything flagged for manual input, usually the judgment questions your admin marked Required.
  5. If something’s ambiguous, use Request Clarification to send a templated email back to the requester before approving.
  6. If the requester misidentified an existing vendor, approve the submission and use the vendor record merge function to consolidate it under the parent record.
  7. Accept to kick off onboarding. The right assessment plan attaches automatically based on tags and inherent risk.
The requester sees three steps on their side (Select Vendor, Additional Information, Review Questionnaires), and Coverbase does most of the typing for them. Two parts of that flow change what lands in your queue:
  • Pre-Qualification runs on the vendor name at step 1 and tells the requester if the vendor is already onboarded, or if an approved vendor already covers the use case. It’s the cheapest risk reduction in the whole process, and it’s why some requests never reach you.
  • The autofilled IRQ at step 3 arrives with a confidence badge per answer (green High confidence, amber Review this response) and the reasoning and sources behind each one. Work the amber ones first; amber means Coverbase wasn’t confident, and the reasoning usually names exactly what was missing.
Responses can’t be edited by the requester after submission, so anything wrong is yours to correct on the way through.
Requests can also arrive from an AI assistant rather than the portal. Same session, same queue, same enrichment; see Vendor intake in chat. You can work this queue that way too, taking each pending submission in turn and approving, rejecting, or requesting follow-up with confirmation. If you want to point a requester at the requester-side walkthrough, send them Requesting a new vendor.
Intake queue of pending vendor requests

The intake queue. New requests arrive pre-enriched and pending review, each with its use case, services, and status.

Intake submission detail with enrichment and auto-answered questions

Inside a submission. The enrichment and redundancy readouts, plus the auto-answered IRQ you validate answer by answer.

Inherent risk is the vendor’s weighted answers as a percentage of the maximum possible. If a score looks wrong for the vendor type, say an API vendor scoring low, flag it to your admin. That’s a weighting fix, not a you problem.

Step 2: Launch an assessment

Launching an assessment opens the review. It attaches control sets, kicks off document collection, and runs the analysis.
  1. Open the vendor record, then go to Assessments → New Assessment. Choose vendor-level or service-level scope. Multiple assessments can coexist, and one assessment can carry multiple control sets at once, like SIG core plus your own InfoSec set.
  2. Pick the Assessment Plan. This is the whole of the setup: control sets and questionnaires aren’t chosen assessment by assessment, they come from the plan. Selecting one shows a summary: how many control sets and questionnaires, manual or automatic collection, whether it targets residual risk, and who reviews it. Read that summary; it’s the fastest way to catch a plan that’s heavier or lighter than the vendor warrants. Leaving it on None creates an assessment with no control sets attached.
  3. Add more than one vendor if you’re starting a batch. Each gets its own assessment from the same plan, which is how annual reviews are best run. The button reads Create Assessments for that reason.
  4. Let evidence collection run. The Documents tab offers five routes that combine freely, each showing how much is available before you click: Import from existing vendor docs, Request from vendor (the portal, with its current status), Request automatic collection, Import from Coverbase Library (curated documents Coverbase already holds, often substantial for well-known vendors), and Retrieve from Trust Center (needs a Trust Center URL on the vendor record). Below the cards, Upload vendor documents takes files you hold yourself. In automatic mode Coverbase pulls from its library first, then scrapes the vendor’s trust center for anything ungated (it form-fills access requests for gated documents), before falling back to asking the vendor.
  5. Where the vendor has to be engaged, send the portal invitation with a due date. Reminders and the pre-signed MNDA your admin configured go out automatically. The vendor can’t submit until the required items are done, and when they upload, analysis of the affected controls starts on its own.
  6. Analysis takes roughly 5 to 10 minutes on a small evidence set and 20 to 30 minutes when there’s a lot to read. A long SOC 2 takes considerably longer than a certificate of insurance. Large control sets add to it, and a full SIG core is around 300 questions. You don’t need to keep the tab open.
The left panel tracks the assessment through four stages (Collecting Documents, Analyzing Controls, Review Results, Quality Control) and always tells you what it’s waiting for, with a shortcut into that work.
Assessment workspace showing control sets and lifecycle

The assessment workspace. Control sets attached in the left rail, and the lifecycle (collected documents, then analyzed controls, then reviewed results) tracked as it runs.

A vendor uploading a blank or junk document doesn’t slip through. The AI analysis fails it automatically. Trust-center scraping lands documents about 20 to 30% of the time, so the portal stays the primary path for smaller and historical vendors.

Step 3: Review the results

The AI has measured every document against every control and raised issues where evidence is missing or contradicts the expectation. Your job is judgment, in a deliberate order.
  1. Start in the Critical Findings view, not the full issue list. Triage the material items first.
  2. Toggle Assign to Me to filter to your controls. Issues can be assigned per risk domain (InfoSec to InfoSec SMEs, and so on) or round-robin across the team.
  3. Open each issue. You’ll see the expectation, the guidance the AI used, and the analysis citing the specific evidence. Click through to the source language to validate. Never take the summary on faith for a material item.
  4. Spot-check compliant controls too, especially early on. Passes show the same full evidence chain, plus web-sourced supporting articles, and this is how you catch false negatives while you build trust in the output.
  5. Where two control sets overlap, say SIG core and the out-of-box SOC 2 set raising the same gap twice, mark the duplicate as not an issue and tell your admin to drop the redundant set from future assessments.
Getting around the workspace. Eleven tabs run across the top; most days you need the first two. Summary carries the recommendation, the score and its compliance band, review progress, and the risk domain table: Overall Vendor Risk plus a row per domain with inherent risk, residual risk, and the assigned reviewer. Rows reading “Not set” against residual risk haven’t been reviewed yet, so that column is your to-do list. Issues holds one result per control, opening filtered to the ones raised as issues. The remaining nine (Controls, Findings, Emails, Work Queue, Documents, Activity, Notes, Properties, SLAs) carry supporting detail and the audit trail. Working the Issues tab. Three toggles switch between all results, issues only, and open follow-ups, each with a count. Group by defaults to Control Section, so results cluster by control set and section with that section’s reviewers on the group header. Select rows, or Select all, and an action bar appears with everything you can do at once: Accept risk, Add Finding, Create follow-ups, Delete follow-ups, Lock, and Draft new email. On a large assessment this is the single biggest time-saver: bulk-drafting follow-ups for every missing-document issue is one action rather than a hundred. Judging web evidence. Evidence pulled from the public web carries a credibility badge (Authoritative, Reputable, or Unreliable) naming how accountable its publisher is, with the reason on hover, plus the page’s publication date and how old it was when it was cited. Anything below the minimum your admin set was already discarded before the AI read it, so what you see has passed the bar. See Evidence quality and source credibility when a control is resting on web evidence you want to scrutinise, or when a customer asks how source quality is controlled. Inside a result. The left column shows the expectation, the question as the vendor sees it, the guidance, the source control set, and the weight, with the evaluation and its bulleted analysis beneath. Three controls sit above the evaluation: Correct the AI, Preserve (pins a result so later runs don’t overwrite it), and Edit. The right column holds Evidence, Follow-up, Findings, Emails, and Activity, with prev/next controls so you can work straight through the list without going back. Each piece of evidence names its source document and page, quotes the passage, and previews the page with the passage highlighted. That highlight is what makes a result defensible when an examiner asks why a control passed.
Assessment review results grouped by control set

The review workspace. Results grouped by control set, with each issue's status, score, and reason (Missing document, Incomplete response, and so on).

Issue detail view with cited evidence and source document

An issue in detail. The expectation, question, and guidance on the left; the AI's cited analysis and the actual source evidence on the right.


Step 4: Correct the AI

This is how you turn a wrong or noisy result into a permanent improvement. You edit the control’s guidance, rerun it on the spot, and if you accept, the change applies to every future assessment.
  1. On the issue, choose Correct the AI.
  2. Write the missing condition into the guidance. Be specific.
  3. Rerun the control and confirm the result changes as expected.
  4. Accept to save globally, or discard.
Correct the AI guidance editor

Correct the AI. Edit the guidance, rerun the control, and accept to make the fix permanent across all future assessments.

  • A clean desk policy flagged for a SaaS vendor. Added “mark fully compliant if the vendor is not a professional services or contracting company with a physical on-site presence.” The rerun resolved to no issue.
  • SOC 2 currency. Tightened the default 12-month window to 6 months on the control, and the draft vendor follow-up regenerated itself to reflect the new window.
  • Employment contractual agreements. Added “accept an information security training attestation as sufficient evidence.” The issue resolved and saved for all future assessments.
Be specific, not lenient. Distinguish a public company from a startup, or a SaaS vendor from professional services, rather than broadly relaxing a control. Specific guidance is what makes an exception defensible to a regulator, and it’s what keeps the same false positive from coming back.

Step 5: Follow up with the vendor

For genuine gaps, you send the vendor a contextualized question that references what they already submitted, through the portal.
  1. On an issue, choose Draft Follow-up and use AI Autofill. It writes the question in context (“we reviewed your SOC 2 and it doesn’t address X”) rather than pasting raw control text, which vendors respond to far better.
  2. For volume, select all issues, then Create Follow-ups. AI Autofill runs across the batch. Set the portal due date and send in one step.
  3. Pick the email template and add any vendor-specific instructions. The internal requester is CC’d automatically.
  4. The vendor answers and uploads new evidence directly in the portal, and responses flow back onto the issues.
A few things worth knowing about the mechanics:
  • Saving a follow-up creates a draft, it doesn’t send. Follow-ups are drafted individually and sent together, so the vendor gets one consolidated request instead of a trickle of emails. The bar at the top of the Issues tab shows how many drafts are waiting, alongside Configure portal (what the vendor sees) and Manage sent follow-ups (what’s already out).
  • Name the evidence you want. Under Required document types, say what the vendor should attach, so the request is specific rather than “please send evidence”. Use control question and response reuses the original control wording if the autofilled version isn’t right.
  • Some vendors prefer a spreadsheet. Download workbook and Import responses on the Issues tab let a vendor work offline and come back in.
  • Reanalysis is narrow. When the vendor submits, only the controls selected for follow-up run again. A result that comes back reads Response received and its analysis is rewritten to account for what the vendor said, often moving from Not Compliant to Fully Compliant where the gap was documentation rather than practice. To re-evaluate everything from scratch, say after changing the plan or control sets, use the rerun option from the assessment Actions menu instead.
Draft follow-up with AI autofill

Draft Follow-up with AI Autofill. A question written in the context of what the vendor already submitted.

Pace yourself. Go one by one for your first assessments, since reviewing each drafted follow-up is how you tune guidance and tone. Switch to bulk once you trust the output.

Step 6: Reviews, disposition, and reporting

This closes the review. Domain reviewers sign off, every remaining issue gets a decision, the vendor gets a status and a reassessment date, and the record becomes a report.

Domain reviews and quality control

Each risk domain can carry its own reviewer, which is what lets several teams work one assessment: InfoSec on the security domains, Legal on the contractual ones, Compliance on regulatory. The Summary tab reports progress as a count of completed reviews. A reviewer opens their domain with Start review. Until someone does, the domain shows Not started and its residual risk stays “Not set”.
  • Reviewers are set per domain or control set and can be changed at any time.
  • Reviewers are notified when results are ready for them, and risk analysts and administrators can resend reminders.
  • Your organization can optionally prevent anyone who isn’t a risk analyst or administrator from completing assessments.
Once the reviews are in, the assessment moves to Quality Control, the last stage on the tracker, for a final pass.
Depending on configuration, Complete Assessment stays disabled until the domain reviews are finished. If the button is greyed out, look at the review column rather than the score.

Dispositioning issues

You have three dispositions per issue:

Accept the risk

Records a timestamped rationale on the record, audit-backed.

Keep the follow-up open

The issue stays pending vendor response.

Promote to a finding

Use Action, then Add Finding, with AI autofill for consistent language. Assign a named owner and a due date. Findings persist beyond the assessment.

Completing and exporting

Click Complete Assessment on the Summary tab. The dialog asks for four things:
  1. Action: approve, reject, or whichever outcomes your organization uses.
  2. Vendor Status: where this leaves the vendor in its lifecycle, for example Active. Custom statuses are supported.
  3. Next Vendor Reassessment Date: set for you from the risk tier and the completion date, typically a year out, and fully overridable if this vendor needs watching sooner. Anything unresolved converts to findings rather than getting deleted.
  4. Recommendation: the written conclusion that carries into exports, so write it properly rather than leaving it thin.
Risk Scoring Changes expands to show how this assessment moved the vendor’s scores. Worth a look before you confirm. Then export. Export Report offers four formats: PDF, Excel, CSV, and Word. Match the format to the audience: PDF for anything leaving the company, Excel or CSV when someone wants to sort and filter the results themselves, and Word when the output has to drop into an existing house template. Your organization’s branded Word template fills itself in automatically; see Custom Word report templates if you need to change what it pulls in. Scope matters as much as format: Standard for most reviews, Executive Summary for leadership, and Full (every control with all evidence) when an examiner asks. The fullest export includes every result, all document evidence, the activity log, follow-ups, and notes, and can run to hundreds of pages.
Completed assessment summary with risk scores and recommendation

A completed assessment. Inherent risk, assessment score, and residual risk side by side, with the AI-generated executive summary and a recommendation.


Step 7: Contracts and clause reviews

The contracts module extracts key terms from MSAs, SOWs, and DPAs (value, effective date, term and renewal, indemnity, billing, data return) and compares vendor paper against your preferred language.
  1. Upload the contract to the vendor’s Documents, setting the document type manually for MSAs, SOWs, and order forms.
  2. Open the Contracts module to review extracted terms and the clause inventory. You can also just ask in natural language: “what does this agreement say about insurance?” queries across all of the vendor’s agreements at once.
  3. Run a clause review against your organization’s clause sets. The output shows deltas from your acceptable, fallback, and unacceptable tiers, by severity. This is materiality analysis, not redlining. Actual redlines stay in Word.
  4. Triage each flagged clause: no action, accepted risk, false positive, or create a finding. Triaging is the review, and it’s what clears the flag list.
  5. Generate follow-up drafts for negotiation points, export the review to Excel, or assign it to legal in-platform.

Contract Guardian guide

The full walkthrough: building clause sets from the library or your own paper, writing risk-tier variants, and working a review end to end.

Document Insights guide

Defining the fields pulled out of every document, with a starter library and guidance on Extract vs Synthesize.
Contract overview with extracted terms and AI summary

A contract record. Extracted lifecycle, value, and term dates, plus an AI summary of parties, billing, SLAs, liability, and termination.

Extracted contract terms

Extracted contract terms. Value, effective date, term and renewal, and more, pulled straight from the paper.

Clause review showing deltas from preferred language

A clause review. Vendor language scored against your acceptable, fallback, and unacceptable tiers, by severity.

Contract findings can fold into assessment reports, for example an FFIEC control set applied to the contract, unified through a custom report template. Supersession is tracked too, so the record reflects what’s currently in force.

Step 8: Work Radar alerts

Radar watches external sources for events touching your third and fourth parties. Your job is to turn signal into action, and keep noise out of the program.
  1. Review the alerts feed for your detectors. Fourth-party mapping means one event, say a compromised identity provider, surfaces every vendor exposed through it.
  2. Open a case on anything worth investigating (a case is preliminary, not yet a confirmed problem) and tag the affected vendors.
  3. Send a vendor inquiry from the case if you need their confirmation or remediation plan.
  4. Close the case if the vendor is unaffected. Promote it to a finding (owner and due date) if confirmed. Trigger an off-cycle reassessment straight from the event when warranted.
  5. If a detector keeps firing on non-actionable items, flag it. Detector guidance and severity thresholds are quick admin fixes.
Radar dashboard with event timeline and alerts feed

The Radar dashboard. Events, incidents, assessments, and reassessments over time, with the alerts feed grouped by detector below.

Radar cases view

Radar cases. Preliminary investigations tagged to affected vendors, ready to close, promote to a finding, or trigger a reassessment.


Step 9: Obligations at a glance

Alongside what you require of vendors, Coverbase extracts what vendors require of you: CUECs pulled verbatim from SOC reports, and shared responsibilities from contracts and terms. As a reviewer, you’ll validate extractions against source language, assign owners and due dates, and send attestation requests to business stakeholders through a trimmed-down portal.
Obligations overview

Obligations. CUECs and shared responsibilities extracted from documents, ready to validate, assign, and send for attestation.

The full obligations workflow (validation, ownership, and stakeholder attestations) gets its own dedicated guide, which we’ll add to this collection.

Frequently asked questions

Roughly 5 to 10 minutes for a typical assessment once evidence is collected, and 20 to 30 minutes when the document set is large. A long SOC 2 report takes considerably longer to read than a certificate of insurance. Very large control sets run longer still, and a full SIG core is around 300 questions. You don’t need to keep the tab open. Issue counts drop over time as guidance is tuned, and the first-pass reduction is typically around 80% versus reviewing every control by hand.
Not exactly. AI models are non-deterministic, so two runs can differ slightly at the margins. Extraction is deliberately tuned to over-surface rather than miss. Specific control guidance narrows the variance, and results are stable on well-tuned sets.
That’s what review is for. Every result carries citations to source language, so errors are visible fast. Use Correct the AI to fix it permanently rather than just dismissing it. Your corrections become the record.
A bare portal invite lands around 50%. Contextualized follow-ups, the pre-signed MNDA, and automatic reminder cadences push that meaningfully higher, and the automated collection paths mean many vendors never need to be asked at all.
It downloads anything ungated automatically and form-fills access requests for gated documents. It doesn’t log into credentialed portals or read your inbox, so documents that arrive by email get uploaded manually.
PDF. Citations and evidence highlighting are strongest there. DOCX is supported for extraction, and for web-based terms, download them and upload for parsing.

Ready to go?

Pick a vendor you know well, launch an assessment, and judge the results against a document set you could grade in your sleep. That’s the fastest way to build trust in the output.

How to run an assessment

The screen-by-screen walkthrough of one assessment, intake to export.

Assessment quick reference

A one-page cheat sheet to keep open while you work.

Admin and setup guide

How the environment behind these workflows is configured.

Need help?

Email support@coverbase.ai, or ask your Coverbase contact to run a live working session with your team.