This quick reference is part of the User Guides collection. Keep it open in a tab while you work. For the screen-by-screen walkthrough, see How to run an assessment. For the wider daily loop, see the Analyst and reviewer guide.
Creating and running an assessment
1
Initiate the assessment
Go to Assessments → + New Assessment, add the vendor (add several to start a batch), and pick the Assessment Plan. The plan carries the control sets and questionnaires, so that single choice is most of the setup. Check the summary under the dropdown before you continue, and don’t leave it on None.
2
Get the evidence in
On the Documents tab, five routes combine freely: existing vendor docs, request from vendor (portal), request automatic collection, the Coverbase Library, and the vendor’s trust center. Analysis starts on its own and runs 20 to 30 minutes on a heavy document set. The left panel tracks four stages: Collecting Documents, Analyzing Controls, Review Results, Quality Control.
3
Review the findings
You’ll see passes (control met with evidence) and issues (gaps that need your review). Your job is to validate the AI’s findings and review the flagged issues. Every result cites the source document and page, with the passage highlighted.
4
Address each issue
Review the evidence the AI found, then accept its assessment or override with your judgment. Use Correct the AI to fix a wrong result permanently, and Preserve to pin a result against future runs. Select rows for bulk Accept risk, Add Finding, or Create follow-ups. Add notes for the audit trail.
5
Generate follow-up questions
If needed, click Draft Follow-ups. The AI writes targeted questions for only the gaps. Saving creates a draft; the vendor sees nothing until the batch goes out through the portal. Only the followed-up controls are reanalyzed when they respond.
6
Final review and approval
Domain reviewers sign off (residual risk reads “Not set” until they do), then Complete Assessment: action, vendor status, next reassessment date, and recommendation. Export as PDF, Excel, CSV, or Word.
Quick tips
The AI does most of the work
It searches vendor websites, trust centers, and docs, pulls integrated data, and analyzes uploaded documents like SOC 2 reports and contracts.
You focus on judgment calls
Validate the AI’s findings, review flagged issues, and override when the AI is wrong.
Speed matters
Don’t re-read what the AI already found. Focus on the yellow and red flags, and use bulk actions for similar issues.
Common scenarios
Vendor has comprehensive security docs (ISO, SOC 2, etc.)
Vendor has comprehensive security docs (ISO, SOC 2, etc.)
Upload the documents during the assessment. The AI extracts the relevant controls, and most technical controls auto-pass based on the report, with exceptions flagged. You review any gaps.Typical time: 15 to 20 minutes.
Small vendor, limited docs
Small vendor, limited docs
The AI searches public info, so more issues get flagged because there’s less evidence. Generate a targeted questionnaire and let the vendor complete it through the portal.Typical time: 30 to 45 minutes, plus vendor response time.
Troubleshooting
Control frameworks at a glance
Your organization may have custom frameworks. Check Configuration → Controls.
Need help?
Platform support
Full walkthrough
How to run an assessment, screen by screen.
The daily loop
The complete Analyst and reviewer guide.