Skip to main content
This guide is part of the User Guides collection. It follows one vendor through the whole assessment lifecycle, screen by screen. For the shorter version, see the Assessment quick reference. For the wider analyst workflow (Radar, contracts, obligations), see the Analyst and reviewer guide.

What’s in this guide

Each part stands on its own, so you can jump to the stage you need.

Part 1: Get the vendor into Coverbase

Intake, or the manual New Vendor wizard.

Part 2: Create the assessment

One dialog: vendors, plan, name.

Part 3: Collect the evidence

Five routes into the document set.

Part 4: Find your way around

The panel, the tabs, the Summary.

Part 5: Work the issues

Bulk actions and individual results.

Part 6: Run follow-up cycles

Draft, send, reanalyze.

Part 7: Reviews and quality control

Per-domain reviewers and gating.

Part 8: Complete and export

Outcome, status, reassessment date, report.

Before you start

You will move faster with these to hand:
  • The vendor name, website, and a security contact email address.
  • Any evidence you already hold: SOC 2 report, policies, pen test results, certificates of insurance.
  • The vendor’s Trust Center URL if they publish one. Adding it to the vendor record lets Coverbase pull documents straight from the trust center later, saving a round trip.
  • An Assessment Plan that matches the depth of review you need. Plans bundle the control sets, questionnaires, and collection method, so choosing the right one is most of the setup.
  • Permission to create vendors and assessments. If a button described here is missing, check your role with an administrator.

Two terms worth pinning down

Inherent risk vs residual risk

Inherent risk is the risk a vendor introduces based on what they do: the data they touch, the systems they connect to, the scope of the engagement. It is established before any evidence is reviewed.Residual risk is what remains once their controls, certifications, and documentation have been evaluated. The assessment is what moves you from one to the other.
An Assessment Plan is a reusable template defining what an assessment evaluates. Plans are managed centrally, so most users pick one rather than building an assessment up field by field.

Part 1: Get the vendor into Coverbase

An assessment attaches to a vendor record, so the vendor has to exist first. There are two ways to get one in, and the difference between them matters more than it first appears.
  • The Intake module: the standard path. A requester submits the vendor through a portal, answers a short set of questions, and Coverbase produces an inherent risk score as a by-product. You end up with a vendor record and a risk profile in one pass.
  • Manual creation: the New Vendor wizard in the dashboard. Faster if you only need the record, but it does not establish inherent risk on its own.
If the vendor is already in Coverbase. Check whether it already carries an inherent risk score. If it does, you need neither path. Skip straight to Part 2 and create the assessment. Re-running intake on a vendor that already has a current risk profile just duplicates work.
Intake determines how much risk a vendor introduces before anyone looks at their documentation. It answers two questions: what is the use case, and what is the scope? Why this is the better path. The inherent risk result drives which control sets apply and how deep the assessment goes. A consulting vendor with no system access should not be assessed like a core processor, and intake is what tells Coverbase the difference. Intake is completed by the requester (the business owner asking for the vendor) through a portal separate from the main dashboard. It runs in three steps: Select Vendor, Additional Information, Review Questionnaires.
You need your organization’s intake link. Opening the intake path without it returns “Unable to identify intake portal. Please use the link provided by your organization.” Find the link under Intake → Request new vendor.
1

Name the vendor and describe the use case

Enter the vendor name, or use Help Me Choose if you are still comparing options, then pick the use cases that apply. Coverbase generates these suggestions for the specific vendor, and you can add your own in the custom answer field.Below, Pre-Qualification runs a quick analysis and, importantly, checks whether you are about to duplicate a vendor you already have. If it finds a match it says so plainly and offers Not my vendor if it has guessed wrong. It also surfaces existing vendors in good standing that might already cover the use case, along with their current use cases, services, and tags.
Intake step 1 with use case selection and pre-qualification results

1 Use cases tailor the questions that follow. 2 Pre-Qualification catches duplicates before you onboard.

Worth pausing here. The duplicate check is the cheapest risk reduction in the whole process. If Coverbase says the vendor is already onboarded, or that an approved vendor already covers the need, that is usually the end of the request. It is also the same check that tells you whether you can skip intake entirely.
2

Scope it to services, if relevant

Select Services or Product Lines is optional. Choose the specific services you will be evaluating, or add one with + New Service. Scoping here keeps the assessment focused on what you are actually buying.The Confirm section follows, where you can check the details Coverbase gathered and attach any supporting documents you already hold: email threads, proposals, SOWs.
Optional service scoping and the confirm section in intake

Optional scoping, with the Confirm section beneath it.

3

Answer the clarification questions

Step 2 is headed Additional Information. Coverbase asks roughly four questions, generated for this vendor and deliberately narrow. They cover only what cannot be determined from public sources. In practice they establish whether personal data is involved, the size of the spend, whether you are in a regulated industry, and how deeply the vendor will integrate.Each has a few preset answers plus a free-text option if none fits.
Additional information step with generated clarification questions

Clarification questions, generated for this vendor and limited to what public sources can't answer.

4

Review the autofilled questionnaire

Step 3 is headed Review Questionnaires. Rather than making the requester complete a long inherent risk questionnaire, Coverbase fills it in, often twenty or more responses, and tells you which ones need a human.Three tabs across the top split the work: all responses, the ones still needing an answer, and the ones flagged for review. Work the flagged ones first.Every response carries:
  • A confidence badge: green High confidence where the evidence was clear, amber Review this response where it was not.
  • Reasoning: why Coverbase chose that answer, with links to the sources it used. Expand it with Read more.
  • Answered / Reviewed checkboxes: track your way through the list.
  • Select supporting documents: optionally attach evidence to a response.
Autofilled inherent risk questionnaire with confidence badges and reasoning

1 Tabs split answered from flagged. 2 Amber means low confidence, so read these. 3 Reasoning shows the sources behind the answer.

Human in the loop. Autofilled answers are a starting point, not a verdict. Anything flagged for review is flagged because Coverbase is not confident, and the Reasoning will usually tell you exactly what was missing.
5

Submit

When every questionnaire reads All done, the panel switches to Ready to Submit. A summary of the vendor and any uploaded documents sits on the right so you can sanity-check before committing.
Ready to submit panel with vendor summary

1 Submit when ready. 2 Responses cannot be edited afterwards, so review first.

A risk analyst reviews the submission before it becomes an assessment, and can edit responses, ask the requester for clarification, or accept it and launch the assessment. At that point the vendor exists, carries an inherent risk score, and is ready for Part 2.

Path 2 (alternative): creating the vendor manually

Use this when you only need the record: a vendor being logged for administrative reasons, a supplier inherited from elsewhere, or a case where you already know the risk profile and will set it yourself.
The trade-off. Manual creation does not produce an inherent risk score. Until one is set, the assessment has nothing to calibrate its depth against, and the risk-domain view will have gaps. If you want that calibration, use Path 1 instead.
1

Open the Vendors page and click New Vendor

Go to Vendors in the left-hand navigation. The page has four tabs (Vendors, Services, Engagements, and Nth Parties), and you want the default Vendors tab. Click + New Vendor at the top right. A three-step modal opens.
Vendors page with the New Vendor button highlighted

The + New Vendor button sits at the top right of the Vendors page.

2

Search for the vendor (step 1 of 3)

The search field reads Select from existing vendors or create new…. Start typing and Coverbase Entity Intelligence matches against its own database, labelling each result as a Vendor or a Product. Selecting a match pre-fills the details.If there is no match, choose Create vendor from scratch: "{your vendor}". Click it or press Enter.
Vendor search with Entity Intelligence matches

Selecting a match pre-fills the vendor. The arrow marks the create-from-scratch option, used when nothing matches.

3

Fill in the details (step 2 of 3)

This step is headed Modify Vendor Details. If Entity Intelligence had data, most fields are already populated. Otherwise click AI Autofill to have Coverbase search the web, then correct anything it got wrong.
Modify vendor details step with AI autofill

1 AI Autofill populates the record from public sources. Only Vendor Name is required.

Only Vendor Name is required, but the rest save work later:
  • Website, Description, HQ Location, Use Cases: context the AI draws on during assessment.
  • Security Contact Email: used when Coverbase contacts the vendor.
  • Trust Center URL: enables Retrieve from Trust Center in Part 3.
  • Services: you can then assess a single service rather than the whole vendor, which keeps scope tight.
  • Vendor Contacts: these pre-fill every document request and follow-up you send.
  • Tags: tags can drive which control sets apply, so if you tag by tier, do it now.
  • Risk Analysts, Relationship Owners, Watchers: ownership and notification.
Adding services, contacts, and tags to the vendor record

2 Add Service. 3 Add Contact. 4 Add Tags. Then Next, bottom right.

4

Custom fields and create (step 3 of 3)

Step 3 is headed Fill in additional fields and shows whatever custom fields your organization has defined: contract amounts, audit dates, department, SLA, and so on. None are mandatory. Click Create Vendor and you land on the Vendor Overview page.
Custom fields step of the new vendor wizard

Custom fields vary by organization. Create Vendor finishes the wizard.

Abandoning the wizard. Closing part-way through prompts “Discard changes?” with Keep editing and Close and discard. Discarding leaves no partial vendor behind.

Part 2: Create the assessment

Simpler than it looks. Assessment setup is a single dialog. Control sets and questionnaires are not chosen assessment by assessment. They come from the Assessment Plan you select.
1

Open the Assessments page and click New Assessment

Go to Assessments and click + New Assessment at the top right. The list shows each assessment’s outcome, score, status, auto-review progress, and both risk figures.
Assessments list with outcome, score, status, and risk columns

If the list looks empty, clear the filters. An Assignee filter persists between visits.

2

Add the vendors and any services

Click + Add vendor… and pick the vendor, then optionally narrow to specific services. You can add more than one vendor, and each gets its own assessment from the same plan, which is the efficient way to start a batch of annual reviews. The button reads Create Assessments for that reason.
New assessment dialog with vendors added

1 Add as many vendors as you need. 2 The plan summary tells you what you are about to run.

3

Choose the Assessment Plan

This single choice determines what the assessment evaluates. The dropdown defaults to None and lists your saved plans. Selecting one shows a summary beneath it: how many control sets and questionnaires it carries, whether documents are collected manually or automatically, whether it targets residual risk, and who reviews it.Read that summary before you continue; it is the fastest way to catch a plan that is heavier or lighter than the vendor warrants. Configure opens the plan itself if you need to inspect or change it.
Leaving the plan on None creates an assessment with no control sets attached, which is rarely what you want.
Assessment plan dropdown with plan summary

1 Configure inspects a plan. 2 Plans are built and named by your team.

Choosing a plan. Plans built on your own control sets usually produce fewer and more relevant issues than a broad third-party questionnaire, which can run to several hundred expectations. Start with your own and add breadth only where you need it.
4

Check the name, then create

Expand Customize assessment name. Names are generated from a template rather than typed by hand (the default produces something like “2026 HubSpot initial”), and a live example shows the result as you edit. Leave it alone unless you have a reason to change it; consistent names are what make three hundred assessments searchable a year from now.Click Create Assessments.
Customize assessment name with template and live example

1 Expand to see the template. 2 Live example. 3 The template itself.


Part 3: Collect the evidence

An assessment is only as good as its evidence. Open the Documents tab. A Collection Mode badge shows whether this assessment is collecting manually or automatically, and five routes are offered. They combine freely, and each card tells you how much is available before you click.
Documents tab with the five evidence collection routes

1 Existing vendor docs. 2 Request from vendor. 3 Switch to automatic. 4 Coverbase Library. 5 Trust Center. The badge shows the current collection mode.

  • Import from existing vendor docs: anything already on the vendor profile. Fastest route for a reassessment.
  • Request from vendor: manages the assessment portal, and shows the portal’s current status so you can see where the vendor has got to.
  • Request automatic collection: switches this assessment to automatic collection.
  • Import from Coverbase Library: curated documents Coverbase already holds for this vendor. Check the count; for well-known vendors it is often substantial.
  • Retrieve from Trust Center: pulls from the vendor’s public trust center. Only available with a Trust Center URL on the vendor record.
Below the cards, Upload vendor documents takes files you hold yourself. A sixth route needs no collection at all: where a control set allows it, the AI researches the public web while evaluating a control. That evidence is filtered on publisher accountability before it can be cited, and every accepted page carries its grade and its age. See Evidence quality and source credibility.
1

If you are using the portal, send the request

The vendor gets a branded portal with a due date, your message, and a checklist of what you need: questionnaires and document requests, with required items marked. They cannot submit until the required parts are done, and progress is visible to both sides.When they upload, analysis of the affected controls starts automatically. No handoff needed.
Vendor-facing assessment portal with upload area and required sections

1 Upload area. 2 Each section the vendor must complete; Submit stays disabled until required items are done.

2

Wait for analysis

Analysis typically takes 20 to 30 minutes depending on document volume. A long SOC 2 report takes longer than a certificate of insurance. You do not need to keep the tab open.The left panel tracks four stages: Collecting Documents, Analyzing Controls, Review Results, Quality Control. It also tells you what it is waiting for, which at the start is at least one document.
Assessment stage tracker showing the four lifecycle stages

1 The four-stage tracker. 2 A shortcut to whatever the assessment needs next.


Part 4: Find your way around the assessment

There is a lot on this page. Three areas matter.

The left panel

Current stage, what it is waiting for, a shortcut into the work, and an Export menu. Below that, Details: assignee, inherent risk, risk target, services, and the plan the assessment came from.

The tabs

Eleven tabs run across the top. Most of the time you need the first two, Summary and Issues. The rest carry supporting detail and the audit trail: Controls, Findings, Emails, Work Queue, Documents, Activity, Notes, Properties, and SLAs.

The Summary tab

At the top is Recommendation, the human conclusion. It appears in exports, so write it properly rather than leaving it thin. Then a band showing the Score as a percentage with a compliance band, how many domain reviews are complete, and Complete Assessment. Then the risk domain table: Overall Vendor Risk plus a row per domain, each with inherent risk, residual risk, and the assigned reviewer. Domains vary by plan; a broad plan can produce nine or more, covering things like AI & Emerging Technology, Operational Resilience, Concentration & Fourth-Party Risk, and Reputational & ESG alongside the familiar Data Security and Privacy. Rows reading “Not set” against residual risk have not been reviewed yet. Those are your gaps.
Assessment summary tab with recommendation, score band, and risk domain table

1 Recommendation. 2 Score, review progress, and completion. 3 Risk by domain. 'Not set' means not yet reviewed.


Part 5: Work the issues

The Issues tab holds one result for every control in the assessment. It opens filtered to the results raised as issues.

Reading the top of the page

  • Risk domain selector: narrow to a single domain.
  • Control Score: the score out of 100%.
  • Open Issues: open count against the total.
  • Vendor Score: inherent and residual risk for the vendor.
If any follow-ups exist, a bar summarizes them (how many await a response, how many are still drafts) alongside Configure portal, Download workbook, Import responses, and Manage sent follow-ups. The workbook and import options are there for vendors who would rather work in a spreadsheet than the portal.
1

Orient yourself in the list

Three toggles switch the view (all results, issues only, and open follow-ups), each with a count. Group by defaults to Control Section, so results arrive clustered by control set and section, with the reviewers for that section shown on the group header.Each row shows the control reference, the expectation in short form, status chips such as Missing document or Awaiting, any linked findings, the weight, and the result.
Issues tab with view toggles, grouping, and result rows

1 Switch between all results and issues. 2 Grouping. 3 Status chips, weight, and result on every row.

2

Handle the straightforward ones in bulk

Select rows, or Select all, and an action bar appears with everything you can do at once: Accept risk, Add Finding, Create follow-ups (the count comes along, so you can draft dozens in one sweep), Delete follow-ups, Lock, and Draft new email.On a large assessment this is the single biggest time-saver. Bulk-drafting follow-ups for every missing-document issue takes one action rather than a hundred.
Bulk action bar on the issues list

1 The bulk action bar appears once anything is selected. The arrow marks the row checkboxes.

3

Open an individual result

Click a row to open it. A status banner sits at the top with the actions available for that state. An open issue offers Not an issue and an Action menu; a result that has come back from the vendor reads Response received and offers Mark as issue instead.The left column shows the control: the Expectation (what must be true), the Question as it is put to the vendor, the Guidance for judging evidence, which Control Set it came from, and its Weight.Beneath it, Evaluation gives the score and compliance band, and a bulleted analysis explaining the verdict. Each claim carries an Evidence reference you can click through to. Three controls sit above it: Correct the AI to override the result, Preserve to pin a result so later runs do not overwrite it, and Edit.
Individual control result with expectation, guidance, and cited evaluation

1 Correct the AI, Preserve, Edit. 2 Actions available for this state. 3 Analysis cites its evidence inline.

4

Follow the citation to the source

The right column holds Evidence, Follow-up, Findings, Emails, and Activity, with prev/next controls so you can work straight through the list. Each piece of evidence names its source document and page, quotes the passage, and shows a preview of the page with the passage highlighted.
Evidence panel with the cited passage highlighted in the source document

1 The cited passage, highlighted in the source document. 2 Step through results without returning to the list.

Why the citation matters. The highlighted source is what makes a result defensible. When an examiner asks why a control passed, the answer is a quoted passage from a named document on a specific page.

Part 6: Run follow-up cycles

Follow-ups are drafted individually and sent together, so the vendor gets one consolidated request rather than a trickle of emails.
1

Draft the follow-up

From a result, draft a follow-up question. AI Autofill writes a first pass that references what the evidence already showed and asks only for the gap, which is usually better than starting from scratch. Use control question and response reuses the original control wording instead.Under Required document types you can name what the vendor should attach, so the request is specific rather than “please send evidence”.Saving creates a draft. Nothing reaches the vendor until the drafts are included in a follow-up questionnaire sent through the portal.
Draft follow-up dialog with AI autofill and required document types

1 AI Autofill drafts the question. 2 Name the documents you need. 3 Save creates a draft, it does not send.

2

Send them

Back on the Issues tab, the bar shows how many drafts are waiting. Sending opens the assessment portal with a questionnaire built from your questions and notifies the vendor. Configure portal controls what the vendor sees; Manage sent follow-ups tracks what is already out.
Follow-up bar showing drafts waiting to send

1 Manage what has been sent. 2 The draft count. Here a bulk action has queued a large batch.

3

Let the reanalysis run

When the vendor submits, only the controls selected for follow-up are analyzed again against the new evidence. Everything else is left alone.A result that has come back reads Response received, and the analysis is rewritten to account for what the vendor said, often moving from Not Compliant to Fully Compliant where the gap was documentation rather than practice.
Result showing response received and the rewritten analysis

1 Response received. 2 The score after reanalysis. 3 Preserved pins this result against future runs.

Follow-up versus rerun. A follow-up reanalyzes only the affected controls. If you have changed the plan or control sets, or want everything re-evaluated from scratch, use the rerun option from the assessment Actions menu instead.

Part 7: Reviews and quality control

Each risk domain can carry its own reviewer, which is what lets several teams work one assessment: InfoSec on the security domains, Legal on the contractual ones, Compliance on regulatory. The Summary tab reports progress as a count of completed reviews. A reviewer opens their domain with Start review. Domains show Not started until someone does, and their residual risk stays “Not set”.
Risk domain rows with reviewers and Start review actions

1 Start review. 2 'Not set' until reviewed. 3 Reviewer per domain. 4 Complete Assessment can stay disabled until reviews are in.

Completion can be gated. Depending on configuration, Complete Assessment stays disabled until the domain reviews are finished. If the button is greyed out, look at the review column rather than the score.
  • Reviewers are set per domain or control set and can be changed at any time.
  • Reviewers are notified when results are ready for them.
  • Risk analysts and administrators can resend reminders.
  • You can optionally prevent anyone who is not a risk analyst or administrator from completing assessments.
Once reviews are in, the assessment moves to Quality Control, the last stage on the tracker, for a final pass.

Part 8: Complete and export

1

Complete the assessment

When the issues have been worked and the reviews returned, click Complete Assessment on the Summary tab.
Complete Assessment button next to the score and review progress

Completion sits alongside the score and review progress.

The dialog asks for four things:
  • Action: approve, reject, or whichever outcomes your organization uses.
  • Vendor Status: where this leaves the vendor in its lifecycle, for example Active.
  • Next Vendor Reassessment Date: set for you based on risk tier and the date you completed, typically a year out. Change it if this vendor needs watching sooner.
  • Recommendation: the written conclusion that appears in exports.
Risk Scoring Changes expands to show how this assessment moved the vendor’s scores, which is worth a look before you confirm.
Complete assessment dialog with action, vendor status, reassessment date, and recommendation

1 The next reassessment date is set automatically. 2 Outcome and vendor status. 3 The recommendation carried into exports.

2

Export the results

Once complete, the panel reads Complete and offers Export Report in four formats: PDF, Excel, CSV, and Word.Match the format to the audience. PDF for anything leaving the company. Excel or CSV when someone wants to sort and filter the results themselves. Word when the output needs to drop into an existing house template. The Word export is driven by your organization’s branded template, and Custom Word report templates covers changing what it pulls in.
Export report menu with PDF, Excel, CSV, and Word formats

1 Export Report. 2 Four formats, chosen by audience.

A word on report length. The fullest export includes every result, all document evidence, the activity log, follow-ups, and notes, and can run to hundreds of pages. Reach for it when someone has asked for the complete file. For examiners and executives, the summary-level report usually lands better.

Assessment quick reference

The one-page version: steps, tips, common scenarios, and a troubleshooting table.

Analyst and reviewer guide

The wider daily loop, including Radar alerts, contracts, and obligations.

Admin and setup guide

How assessment plans, control sets, scales, and reviewers are configured.

Evidence quality and source credibility

How web evidence is graded and filtered before it can be cited, and where you set the bar.

Control Set library

What ships in the box, and how control sets differ from questionnaires.

Need help?

Email support@coverbase.ai, or ask your Coverbase contact to run a live working session with your team.