Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This guide is part of the User Guides collection. It is for analysts, reviewers, and InfoSec SMEs doing daily vendor reviews. It assumes your environment is already configured. If you are setting it up, start with the Admin and setup guide.This page is the wide view of the job. For a screen-by-screen walkthrough of one assessment from intake to export, see How to run an assessment.
Coverbase reads vendor documents and measures them against your controls, so your job shifts from hunting through PDFs to judging results. A typical assessment measures a hundred-plus controls and raises a handful of material issues. In one real case, 111 controls produced 5. This is the loop you run:
1

Triage intake

Review enriched new-vendor requests.
2

Launch assessment

Attach control sets and let analysis run.
3

Review issues

Judge the material items, evidence in hand.
4

Correct the AI

Fix wrong or noisy results for good.
5

Follow up

Ask vendors only about genuine gaps.
6

Disposition and report

Decide, complete, and export.
7

Watch Radar

Turn monitoring signal into action.
Two habits matter most. Validate against source language: every result carries citations you can click through. Correct the AI when it is wrong: corrections are permanent, and the issue count drops with every cycle.

Step 1: Triage new vendor requests

New requests arrive from business requesters already enriched with sanctions, financials, security posture, and a redundancy check against your existing portfolio. Most IRQ questions come pre-answered by the research agent.
  1. Open the pending submission and scan the enrichment readout. A red flag on sanctions is a fuzzy match to investigate, and an unknown vendor with no public presence also flags red.
  2. Check the redundancy readout. If the vendor, or a comparable tool, already exists in your portfolio, this may be a new service on an existing record rather than a new onboarding.
  3. Review the auto-answered IRQ. A “limited information” flag means the AI could not confirm authoritatively, not that a problem exists. Click the reviewed checkbox on each answer you validate. Your name and timestamp are recorded.
  4. Answer anything flagged for manual input, usually the judgment questions your admin marked Required.
  5. If something is ambiguous, use Request Clarification to send a templated email back to the requester before approving.
  6. If the requester misidentified an existing vendor, approve the submission and use the vendor record merge function to consolidate it under the parent record.
  7. Accept to kick off onboarding. The right assessment plan attaches automatically based on tags and inherent risk.
The requester sees three steps on their side (Select Vendor, Additional Information, Review Questionnaires), and Coverbase does most of the typing for them. Two parts of that flow change what lands in your queue:
  • Pre-Qualification runs on the vendor name at step 1 and tells the requester if the vendor is already onboarded, or if an approved vendor already covers the use case. It is why some requests never reach you.
  • The autofilled IRQ at step 3 arrives with a confidence badge per answer (green High confidence, amber Review this response) and the reasoning and sources behind each one. Work the amber ones first. Amber means Coverbase was not confident, and the reasoning usually names what was missing.
The requester cannot edit responses after submission, so anything wrong is yours to correct on the way through.
Requests can also arrive from an AI assistant rather than the portal. Same session, same queue, same enrichment; see Vendor intake in chat. You can work this queue that way too, taking each pending submission in turn and approving, rejecting, or requesting follow-up with confirmation. If you want to point a requester at the requester-side walkthrough, send them Requesting a new vendor.
Intake queue of pending vendor requests

The intake queue. New requests arrive pre-enriched and pending review, each with its use case, services, and status.

Intake submission detail with enrichment and auto-answered questions

Inside a submission. The enrichment and redundancy readouts, plus the auto-answered IRQ you validate answer by answer.

Inherent risk is the vendor’s weighted answers as a percentage of the maximum possible. If a score looks wrong for the vendor type, say an API vendor scoring low, flag it to your admin. That is a weighting fix.

Step 2: Launch an assessment

Launching an assessment opens the review. It attaches control sets, kicks off document collection, and runs the analysis.
  1. Open the vendor record, then go to Assessments → New Assessment. Choose vendor-level or service-level scope. Multiple assessments can coexist, and one assessment can carry multiple control sets at once, like SIG core plus your own InfoSec set.
  2. Pick the Assessment Plan. Control sets and questionnaires are not chosen assessment by assessment; they come from the plan. Selecting one shows a summary: how many control sets and questionnaires, manual or automatic collection, whether it targets residual risk, and who reviews it. Read that summary to catch a plan that is heavier or lighter than the vendor warrants. Leaving it on None creates an assessment with no control sets attached.
  3. Add more than one vendor if you are starting a batch. Each gets its own assessment from the same plan, which is how annual reviews are best run. The button reads Create Assessments for that reason.
  4. Let evidence collection run. The Documents tab offers five routes that combine freely, each showing how much is available before you click: Import from existing vendor docs, Request from vendor (the portal, with its current status), Request automatic collection, Import from Coverbase Library (documents Coverbase collected itself, often substantial for well-known vendors), and Retrieve from Trust Center (needs a Trust Center URL on the vendor record). Below the cards, Upload vendor documents takes files you hold yourself. In automatic mode Coverbase pulls from its library first, then scrapes the vendor’s trust center for anything ungated (it form-fills access requests for gated documents), before falling back to asking the vendor.
  5. Where the vendor has to be engaged, send the portal invitation with a due date. Reminders and the pre-signed MNDA your admin configured go out automatically. The vendor cannot submit until the required items are done, and when they upload, analysis of the affected controls starts on its own.
  6. Analysis takes roughly 5 to 10 minutes on a small evidence set and 20 to 30 minutes when there is a lot to read. A long SOC 2 takes considerably longer than a certificate of insurance. Large control sets add to it, and a full SIG core is around 300 questions. You do not need to keep the tab open.
The left panel tracks the assessment through its stages (Collecting Documents, Analyzing Controls, Review Results, then any stages your organization has added after them, such as a quality-control pass) and always tells you what it is waiting for, with a shortcut into that work.
Assessment workspace showing control sets and lifecycle

The assessment workspace. Control sets attached in the left rail, and the lifecycle (collected documents, then analyzed controls, then reviewed results) tracked as it runs.

A vendor uploading a blank or junk document does not slip through. The AI analysis fails it automatically. Trust-center scraping lands documents about 20 to 30% of the time, so the portal stays the primary path for smaller and historical vendors.

Step 3: Review the results

The AI has measured every document against every control and raised issues where evidence is missing or contradicts the expectation. Work through the results in this order.
  1. Start with the issues, not every result. The Issues tab opens filtered to the results raised as issues, so triage the material items first.
  2. Turn on Assigned to me to filter to your controls. Issues can be assigned per risk domain (InfoSec to InfoSec SMEs, and so on) or round-robin across the team.
  3. Open each issue. You see the expectation, the guidance the AI used, and the analysis citing the specific evidence. Click through to the source language to validate. Never take the summary on faith for a material item.
  4. Spot-check compliant controls too, especially early on. Passes show the same full evidence chain, plus web-sourced supporting articles, and this is how you catch false negatives while you build trust in the output.
  5. Where two control sets overlap, say SIG core and the out-of-box SOC 2 set raising the same gap twice, mark the duplicate as not an issue and tell your admin to drop the redundant set from future assessments.
Getting around the workspace. Eleven tabs run across the top; most days you need the first two. Summary carries the recommendation, the score and its compliance band, review progress, and the risk domain table: Overall Vendor Risk plus a row per domain with inherent risk, residual risk, and the assigned reviewer. Rows reading “Not set” against residual risk have not been reviewed yet, so that column is your to-do list. Issues holds one result per control, opening filtered to the ones raised as issues. The remaining nine (Controls, Findings, Emails, Work Queue, Documents, Activity, Notes, Properties, SLAs) carry supporting detail and the audit trail. Working the Issues tab. Three toggles switch between all results, issues only, and open follow-ups, each with a count. Group by defaults to Control Section, so results cluster by control set and section with that section’s reviewers on the group header. Select rows, or Select all, and an action bar appears with everything you can do at once: Resolve (mark as mitigated or accept risk), Add Finding, Create follow-ups, Delete follow-ups, Preserve, and Draft new email. On a large assessment, bulk-drafting follow-ups for every missing-document issue is one action rather than a hundred. Judging web evidence. Evidence pulled from the public web carries a credibility badge (Authoritative, Reputable, or Unreliable) naming how accountable its publisher is, with the reason on hover, plus the page’s publication date and how old it was when it was cited. Anything below the minimum your admin set was already discarded before the AI read it, so what you see has passed the bar. See Evidence quality and source credibility when a control is resting on web evidence you want to scrutinize, or when a customer asks how source quality is controlled. Inside a result. The left column shows the expectation, the question as the vendor sees it, the guidance, the source control set, and the weight, with the evaluation and its bulleted analysis beneath. Four controls sit above the evaluation: Correct the AI, Rerun (evaluates the control again as it stands), Preserve (pins a result so later runs do not overwrite it), and Edit. The right column holds Evidence, Follow-up, Findings, and Activity, with prev/next controls so you can work straight through the list without going back. Each piece of evidence names its source document and page, quotes the passage, and previews the page with the passage highlighted. The highlight is the evidence you point to when an examiner asks why a control passed.
Assessment review results grouped by control set

The review workspace. Results grouped by control set, with each issue's status, score, and reason (Missing document, Incomplete response, and so on).

Issue detail view with cited evidence and source document

An issue in detail. The expectation, question, and guidance on the left; the AI's cited analysis and the actual source evidence on the right.


Step 4: Correct the AI

Correct the AI turns a wrong or noisy result into a permanent change. You edit the control’s guidance, rerun it on the spot, and if you accept, the change applies to every future assessment.
  1. On the issue, choose Correct the AI.
  2. Write the missing condition into the guidance. Be specific.
  3. Rerun the control and confirm the result changes as expected.
  4. Accept to save globally, or discard.
Correct the AI guidance editor

Correct the AI. Edit the guidance, rerun the control, and accept to make the fix permanent across all future assessments.

  • A clean desk policy flagged for a SaaS vendor. Added “mark fully compliant if the vendor is not a professional services or contracting company with a physical on-site presence.” The rerun resolved to no issue.
  • SOC 2 currency. Tightened the default 12-month window to 6 months on the control, and the draft vendor follow-up regenerated itself to reflect the new window.
  • Employment contractual agreements. Added “accept an information security training attestation as sufficient evidence.” The issue resolved and saved for all future assessments.
Be specific, not lenient. Distinguish a public company from a startup, or a SaaS vendor from professional services, rather than broadly relaxing a control. Specific guidance is defensible to a regulator, and it keeps the same false positive from coming back.

Step 5: Follow up with the vendor

For genuine gaps, you send the vendor a contextualized question that references what they already submitted, through the portal.
  1. On an issue, choose Draft Follow-up and use AI Autofill. It writes the question in context (“we reviewed your SOC 2 and it doesn’t address X”) rather than pasting raw control text, which vendors respond to far better.
  2. For volume, select all issues, then Create Follow-ups. AI Autofill runs across the batch. Set the portal due date and send in one step.
  3. Pick the email template and add any vendor-specific instructions. The internal requester is CC’d automatically.
  4. The vendor answers and uploads new evidence directly in the portal, and responses flow back onto the issues.
The mechanics:
  • Saving a follow-up creates a draft. It does not send. Follow-ups are drafted individually and sent together, so the vendor gets one consolidated request instead of a trickle of emails. The bar at the top of the Issues tab shows how many drafts are waiting, alongside Configure portal (what the vendor sees) and Manage sent follow-ups (what is already out).
  • Name the evidence you want. Under Required document types, say what the vendor should attach, so the request is specific rather than “please send evidence”. Use control question and response reuses the original control wording if the autofilled version is not right.
  • Some vendors prefer a spreadsheet. Download workbook and Import responses on the Issues tab let a vendor work offline and come back in.
  • Reanalysis is narrow. When the vendor submits, only the controls selected for follow-up run again. A result that comes back reads Response received and its analysis is rewritten to account for what the vendor said, often moving from Not Compliant to Fully Compliant where the gap was documentation rather than practice. To re-evaluate everything from scratch, say after changing the plan or control sets, use the rerun option from the assessment Actions menu instead.
Draft follow-up with AI autofill

Create Follow-ups for the selected issues. AI Autofill drafts each question in the context of what the vendor already submitted.

Pace yourself. Go one by one for your first assessments, since reviewing each drafted follow-up is how you tune guidance and tone. Switch to bulk once you trust the output.

Step 6: Reviews, disposition, and reporting

This closes the review. Domain reviewers sign off, every remaining issue gets a decision, the vendor gets a status and a reassessment date, and the record becomes a report.

Domain reviews and quality control

Each risk domain can carry its own reviewer, which is what lets several teams work one assessment: InfoSec on the security domains, Legal on the contractual ones, Compliance on regulatory. The Summary tab reports progress as a count of completed reviews. A reviewer opens their domain with Start review. Until someone does, the domain shows Not started and its residual risk stays “Not set”.
  • Reviewers are set per domain or control set and can be changed at any time.
  • Reviewers are notified when results are ready for them, and risk analysts and administrators can resend reminders.
  • Your organization can optionally prevent anyone who is not a risk analyst or administrator from completing assessments.
Once the reviews are in, the assessment moves on to any stage your organization added after Review Results (a quality-control pass, for example) before it is completed.
Depending on configuration, Complete Assessment stays disabled until the domain reviews are finished. If the button is grayed out, look at the review column rather than the score.

Dispositioning issues

You have three dispositions per issue:

Accept the risk

Records a timestamped rationale on the record, audit-backed.

Keep the follow-up open

The issue stays pending vendor response.

Promote to a finding

Use Action, then Add Finding, with AI autofill for consistent language. Assign a named owner and a due date. Findings persist beyond the assessment.

Completing and exporting

Click Complete Assessment on the Summary tab. The dialog asks for four things:
  1. Action: approve, reject, or whichever outcomes your organization uses.
  2. Vendor Status: where this leaves the vendor in its lifecycle, for example Active. Custom statuses are supported.
  3. Next Vendor Reassessment Date: set for you from the risk tier and the completion date, typically a year out, and fully overridable if this vendor needs watching sooner. Anything unresolved converts to findings rather than getting deleted.
  4. Recommendation: the written conclusion that carries into exports, so write it properly rather than leaving it thin.
Risk Scoring Changes expands to show how this assessment moved the vendor’s scores. Check it before you confirm. On a service-scoped assessment the change applies to the services. It reaches the vendor only if your organization rolls service scores up. Then export. Export Report offers four formats: PDF, Excel, CSV, and Word. Match the format to the audience: PDF for anything leaving the company, Excel or CSV when someone wants to sort and filter the results themselves, and Word when the output has to drop into an existing house template. Your organization’s branded Word template fills itself in automatically; see Custom Word report templates if you need to change what it pulls in. Scope matters as much as format: Standard for most reviews, Executive Summary for leadership, and Full (every control with all evidence) when an examiner asks. The fullest export includes every result, all document evidence, the activity log, follow-ups, and notes, and can run to hundreds of pages.
Completed assessment summary with risk scores and recommendation

Complete Assessment. The outcome, the vendor's status, the next reassessment date and the recommendation, with a checkbox that accepts the risk on any issues still open.


Step 7: Contracts and clause reviews

The contracts module extracts key terms from MSAs, SOWs, and DPAs (value, effective date, term and renewal, indemnity, billing, data return) and compares vendor paper against your preferred language.
  1. Upload the contract to the vendor’s Documents, setting the document type manually for MSAs, SOWs, and order forms.
  2. Open the Contracts module to review extracted terms and the clause inventory. You can also ask in natural language: “what does this agreement say about insurance?” queries across all of the vendor’s agreements at once.
  3. Run a clause review against your organization’s clause sets. The output shows deltas from your acceptable, fallback, and unacceptable tiers, by severity. Each clause that needs a decision comes with a suggested redline against your playbook, and when the agreement is a Word file the review can produce a redlined copy.
  4. Triage each flagged clause: no action, accepted risk, false positive, or create a finding. Triaging is the review, and it clears the flag list.
  5. Generate follow-up drafts for negotiation points, export the review to Excel, or assign it to legal in-platform.

Contract Guardian guide

The full walkthrough: building clause sets from the library or your own paper, writing risk-tier variants, and working a review end to end.

Document Insights guide

Defining the fields pulled out of every document, with a starter library and guidance on Extract vs Synthesize.
Contract overview with extracted terms and AI summary

A contract record: the facts read from its documents, what needs attention, the AI summary, and the terms.

Clause review of a single clause with its analysis and the highlighted source language

One flagged clause in review. Your playbook positions on the left, the suggested redline and your decision in the middle, and the clause's severity, matched variant and AI analysis on the right.

Clause review showing deltas from preferred language

A clause review. Vendor language scored against your acceptable, fallback, and unacceptable tiers, by severity.

Contract findings can fold into assessment reports, for example an FFIEC control set applied to the contract, unified through a custom report template. Supersession is tracked too, so the record reflects what is currently in force.

Step 8: Work Radar signals

Radar watches external sources for events touching your third and fourth parties, and turns each one your organization is exposed to into a signal. Your job is to decide which signals become work, and to keep the rest out of the program.
  1. Open Radar. The Signals tab opens on All Signals; switch to the In Alert view for the signals in alert and awaiting review. Each signal shows the highest severity any detector assigned, the vendors involved, the detectors that fired, and when it was last alerted. One event is one signal, however many detectors hit it.
  2. Open a signal. The status card shows where it stands on the path from Open through Tracked and In alert to Closed, and the Vendors card lists which of your vendors were exposed, with View full exposure for the rest. The summary says what happened, and the timeline under it shows when it happened and when you were alerted. The Detectors tab lists each detector that fired, with its reasoning and confidence, Exposure lists every exposed vendor and why it matched, Sources holds the articles and advisories behind it, and Timeline shows the order things happened.
  3. Act on it from the Actions menu. Open case for anything that needs investigation or vendor outreach (a case is preliminary, not yet a confirmed problem). New finding when it is confirmed, with an owner and a due date. Start reassessment when the vendor’s risk picture has changed enough to re-run the plan. Acknowledge when you have seen it and nothing more is needed beyond a risk update: the signal is marked Triaged and Radar updates the vendor’s risk. Dismiss when no action is needed at all. If the signal is irrelevant, dismissing also lets you teach your detectors not to alert on events like it.
  4. Work the case. Send a vendor inquiry if you need their confirmation or remediation plan. Close it if the vendor is unaffected, or promote it to a finding once confirmed.
  5. Check the risk update. When the detectors that fired are set to update risk, acknowledging the signal, creating a finding, starting a reassessment, or closing a case as Resolved or Won’t fix raises the affected vendors’ residual risk. Review vendor risk profile updates opens with the new numbers. Adjust any of them, then Save and continue, or Continue to accept. Dismissing never moves risk, and neither does closing a case as False positive. How the size of the move is decided is on the Supplier Radar page.
  6. Dismiss what does not matter. Tick Also dismiss future similar alerts and the detectors that fired learn from it, so the next event like it stays quiet.
  7. If a detector keeps firing on non-actionable items, say so. Detector guidance and severity thresholds are quick admin fixes.
No detector has fired on a Tracked signal. A vendor you depend on is linked to the event, so Radar shows the exposure and waits. It becomes work only when a detector fires or you act on it.
Radar Signals tab listing signals with status, severity, vendors, and detectors

The Signals tab. One signal per event, with the highest severity any detector assigned, the vendors involved, and the detectors that fired.

Radar signal page showing the status card, generated summary, and the detectors that fired

A signal. On the left, its status, the vendors exposed, and any reviews. On the right, the generated summary, Ask Coverbase AI, the time from event to alert, and the detectors that put the signal in alert.

Radar cases tab

The Cases tab. Preliminary investigations tagged to affected vendors, each with its status, progress and assignee, ready to close, promote to a finding, or trigger a reassessment.


Step 9: Obligations at a glance

Alongside what you require of vendors, Coverbase extracts what vendors require of you: CUECs pulled verbatim from SOC reports, and shared responsibilities from contracts and terms. As a reviewer, you validate extractions against source language, assign owners and due dates, and send attestation requests to business stakeholders through a trimmed-down portal.
Obligations overview

Obligations. CUECs and shared responsibilities extracted from documents, ready to validate, assign, and send for attestation.

The full obligations workflow (validation, ownership, and business-unit acknowledgement) is in the Obligations guide.

Frequently asked questions

Roughly 5 to 10 minutes for a typical assessment once evidence is collected, and 20 to 30 minutes when the document set is large. A long SOC 2 report takes considerably longer to read than a certificate of insurance. Very large control sets run longer still, and a full SIG core is around 300 questions. You do not need to keep the tab open. Issue counts drop over time as guidance is tuned, and the first-pass reduction is typically around 80% versus reviewing every control by hand.
Not exactly. AI models are non-deterministic, so two runs can differ slightly at the margins. Extraction is tuned to over-surface rather than miss. Specific control guidance narrows the variance, and results are stable on well-tuned sets.
The score landed on the service. An assessment writes its residual risk to whatever it was scoped to, so a service-scoped assessment leaves the vendor’s score alone unless your organization has Risk Roll-up turned on. With it on, the vendor takes the highest score among its live services. See Where a vendor’s score comes from.
That is what review is for. Every result carries citations to source language, so errors are visible fast. Use Correct the AI to fix it permanently rather than dismissing it.
A bare portal invite lands around 50%. Contextualized follow-ups, the pre-signed MNDA, and automatic reminder cadences push that meaningfully higher, and the automated collection paths mean many vendors never need to be asked at all.
Coverbase collects them itself: our agent requests documentation directly from the vendor and retrieves what the vendor publishes on its trust center, and a Coverbase reviewer approves each one before it appears. We do not scrape arbitrary web sources, because that material tends to be outdated and low quality. Nothing your organization uploads, and nothing a vendor sends you through the portal, is ever added to the library. See Document library.
It downloads anything ungated automatically and form-fills access requests for gated documents. It does not log into credentialed portals or read your inbox, so documents that arrive by email get uploaded manually.
PDF. Citations and evidence highlighting are strongest there. DOCX is supported for extraction, and for web-based terms, download them and upload for parsing.

Ready to go?

Pick a vendor you know well, launch an assessment, and judge the results against a document set you already know well. That is the fastest way to build trust in the output.

How to run an assessment

The screen-by-screen walkthrough of one assessment, intake to export.

Assessment quick reference

A one-page cheat sheet to keep open while you work.

Admin and setup guide

How the environment behind these workflows is configured.

Need help?

Email support@coverbase.ai, or ask your Coverbase contact to run a live working session with your team.