> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coverbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How to run an assessment

> A step-by-step walkthrough of the full assessment lifecycle, from getting the vendor into Coverbase to exporting the final report.

<Info>
  This guide is part of the [User Guides](/user-guides/overview) collection. It follows one vendor through the whole assessment lifecycle, screen by screen. For the shorter version, see the [Assessment quick reference](/user-guides/assessment-quick-reference). For the wider analyst workflow (Radar, contracts, obligations), see the [Analyst and reviewer guide](/user-guides/analyst-reviewer).
</Info>

## What's in this guide

Each part stands on its own, so you can jump to the stage you need.

<CardGroup cols={2}>
  <Card title="Part 1: Get the vendor into Coverbase" icon="building" href="#part-1-get-the-vendor-into-coverbase">
    Intake, or the manual New Vendor wizard.
  </Card>

  <Card title="Part 2: Create the assessment" icon="plus" href="#part-2-create-the-assessment">
    One dialog: vendors, plan, name.
  </Card>

  <Card title="Part 3: Collect the evidence" icon="folder-open" href="#part-3-collect-the-evidence">
    Five routes into the document set.
  </Card>

  <Card title="Part 4: Find your way around" icon="compass" href="#part-4-find-your-way-around-the-assessment">
    The panel, the tabs, the Summary.
  </Card>

  <Card title="Part 5: Work the issues" icon="triangle-exclamation" href="#part-5-work-the-issues">
    Bulk actions and individual results.
  </Card>

  <Card title="Part 6: Run follow-up cycles" icon="rotate" href="#part-6-run-follow-up-cycles">
    Draft, send, reanalyze.
  </Card>

  <Card title="Part 7: Reviews and quality control" icon="user-check" href="#part-7-reviews-and-quality-control">
    Per-domain reviewers and gating.
  </Card>

  <Card title="Part 8: Complete and export" icon="file-export" href="#part-8-complete-and-export">
    Outcome, status, reassessment date, report.
  </Card>
</CardGroup>

## Before you start

You will move faster with these to hand:

* The vendor name, website, and a security contact email address.
* Any evidence you already hold: SOC 2 report, policies, pen test results, certificates of insurance.
* The vendor's Trust Center URL if they publish one. Adding it to the vendor record lets Coverbase pull documents straight from the trust center later, saving a round trip.
* An Assessment Plan that matches the depth of review you need. Plans bundle the control sets, questionnaires, and collection method, so choosing the right one is most of the setup.
* Permission to create vendors and assessments. If a button described here is missing, check your role with an administrator.

## Two terms worth pinning down

<AccordionGroup>
  <Accordion title="Inherent risk vs residual risk" icon="scale-balanced" defaultOpen>
    **Inherent risk** is the risk a vendor introduces based on what they do: the data they touch, the systems they connect to, the scope of the engagement. It is established before any evidence is reviewed.

    **Residual risk** is what remains once their controls, certifications, and documentation have been evaluated. The assessment is what moves you from one to the other.
  </Accordion>

  <Accordion title="Assessment Plan" icon="clipboard-list">
    An **Assessment Plan** is a reusable template defining what an assessment evaluates. Plans are managed centrally, so most users pick one rather than building an assessment up field by field.
  </Accordion>
</AccordionGroup>

***

## Part 1: Get the vendor into Coverbase

An assessment attaches to a vendor record, so the vendor has to exist first. There are two ways to get one in, and the difference between them matters more than it first appears.

* **The Intake module**: the standard path. A requester submits the vendor through a portal, answers a short set of questions, and Coverbase produces an inherent risk score as a by-product. You end up with a vendor record and a risk profile in one pass.
* **Manual creation**: the New Vendor wizard in the dashboard. Faster if you only need the record, but it does not establish inherent risk on its own.

<Note>
  **If the vendor is already in Coverbase.** Check whether it already carries an inherent risk score. If it does, you need neither path. Skip straight to [Part 2](#part-2-create-the-assessment) and create the assessment. Re-running intake on a vendor that already has a current risk profile just duplicates work.
</Note>

### Path 1 (recommended): through the Intake module

Intake determines how much risk a vendor introduces before anyone looks at their documentation. It answers two questions: what is the use case, and what is the scope?

**Why this is the better path.** The inherent risk result drives which control sets apply and how deep the assessment goes. A consulting vendor with no system access should not be assessed like a core processor, and intake is what tells Coverbase the difference.

Intake is completed by the requester (the business owner asking for the vendor) through a portal separate from the main dashboard. It runs in three steps: **Select Vendor**, **Additional Information**, **Review Questionnaires**.

<Warning>
  You need your organization's intake link. Opening the intake path without it returns "Unable to identify intake portal. Please use the link provided by your organization." Find the link under **Intake → Request new vendor**.
</Warning>

<Steps>
  <Step title="Name the vendor and describe the use case">
    Enter the vendor name, or use **Help Me Choose** if you are still comparing options, then pick the use cases that apply. Coverbase generates these suggestions for the specific vendor, and you can add your own in the custom answer field.

    Below, **Pre-Qualification** runs a quick analysis and, importantly, checks whether you are about to duplicate a vendor you already have. If it finds a match it says so plainly and offers **Not my vendor** if it has guessed wrong. It also surfaces existing vendors in good standing that might already cover the use case, along with their current use cases, services, and tags.

    <Frame caption="1 Use cases tailor the questions that follow. 2 Pre-Qualification catches duplicates before you onboard.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-intake-use-cases.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=b9303b0115a1148941cdd308e10f4f93" alt="Intake step 1 with use case selection and pre-qualification results" width="1650" height="1378" data-path="images/user-guides/assessment-intake-use-cases.png" />
    </Frame>

    <Tip>
      **Worth pausing here.** The duplicate check is the cheapest risk reduction in the whole process. If Coverbase says the vendor is already onboarded, or that an approved vendor already covers the need, that is usually the end of the request. It is also the same check that tells you whether you can skip intake entirely.
    </Tip>
  </Step>

  <Step title="Scope it to services, if relevant">
    **Select Services or Product Lines** is optional. Choose the specific services you will be evaluating, or add one with **+ New Service**. Scoping here keeps the assessment focused on what you are actually buying.

    The **Confirm** section follows, where you can check the details Coverbase gathered and attach any supporting documents you already hold: email threads, proposals, SOWs.

    <Frame caption="Optional scoping, with the Confirm section beneath it.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-intake-services.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=f91514b8f87020ab88f0440c5c44b3d0" alt="Optional service scoping and the confirm section in intake" width="1630" height="392" data-path="images/user-guides/assessment-intake-services.png" />
    </Frame>
  </Step>

  <Step title="Answer the clarification questions">
    Step 2 is headed **Additional Information**. Coverbase asks roughly four questions, generated for this vendor and deliberately narrow. They cover only what cannot be determined from public sources. In practice they establish whether personal data is involved, the size of the spend, whether you are in a regulated industry, and how deeply the vendor will integrate.

    Each has a few preset answers plus a free-text option if none fits.

    <Frame caption="Clarification questions, generated for this vendor and limited to what public sources can't answer.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-intake-questions.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=0d315fc59949463aa2491164a239ea4d" alt="Additional information step with generated clarification questions" width="1630" height="1198" data-path="images/user-guides/assessment-intake-questions.png" />
    </Frame>
  </Step>

  <Step title="Review the autofilled questionnaire">
    Step 3 is headed **Review Questionnaires**. Rather than making the requester complete a long inherent risk questionnaire, Coverbase fills it in, often twenty or more responses, and tells you which ones need a human.

    Three tabs across the top split the work: all responses, the ones still needing an answer, and the ones flagged for review. Work the flagged ones first.

    Every response carries:

    * **A confidence badge**: green *High confidence* where the evidence was clear, amber *Review this response* where it was not.
    * **Reasoning**: why Coverbase chose that answer, with links to the sources it used. Expand it with **Read more**.
    * **Answered / Reviewed checkboxes**: track your way through the list.
    * **Select supporting documents**: optionally attach evidence to a response.

    <Frame caption="1 Tabs split answered from flagged. 2 Amber means low confidence, so read these. 3 Reasoning shows the sources behind the answer.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-intake-questionnaire.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=bd6972498b3f7b3ec466f4c39e17171b" alt="Autofilled inherent risk questionnaire with confidence badges and reasoning" width="1618" height="1452" data-path="images/user-guides/assessment-intake-questionnaire.png" />
    </Frame>

    <Note>
      **Human in the loop.** Autofilled answers are a starting point, not a verdict. Anything flagged for review is flagged because Coverbase is not confident, and the Reasoning will usually tell you exactly what was missing.
    </Note>
  </Step>

  <Step title="Submit">
    When every questionnaire reads **All done**, the panel switches to **Ready to Submit**. A summary of the vendor and any uploaded documents sits on the right so you can sanity-check before committing.

    <Frame caption="1 Submit when ready. 2 Responses cannot be edited afterwards, so review first.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-intake-submit.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=8fc4986eeff4a1eea8e85cf91dac307f" alt="Ready to submit panel with vendor summary" width="2045" height="590" data-path="images/user-guides/assessment-intake-submit.png" />
    </Frame>

    A risk analyst reviews the submission before it becomes an assessment, and can edit responses, ask the requester for clarification, or accept it and launch the assessment. At that point the vendor exists, carries an inherent risk score, and is ready for [Part 2](#part-2-create-the-assessment).
  </Step>
</Steps>

### Path 2 (alternative): creating the vendor manually

Use this when you only need the record: a vendor being logged for administrative reasons, a supplier inherited from elsewhere, or a case where you already know the risk profile and will set it yourself.

<Warning>
  **The trade-off.** Manual creation does not produce an inherent risk score. Until one is set, the assessment has nothing to calibrate its depth against, and the risk-domain view will have gaps. If you want that calibration, use Path 1 instead.
</Warning>

<Steps>
  <Step title="Open the Vendors page and click New Vendor">
    Go to **Vendors** in the left-hand navigation. The page has four tabs (Vendors, Services, Engagements, and Nth Parties), and you want the default **Vendors** tab. Click **+ New Vendor** at the top right. A three-step modal opens.

    <Frame caption="The + New Vendor button sits at the top right of the Vendors page.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-new-vendor-button.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=bad14d38de06405a794efcbec445c326" alt="Vendors page with the New Vendor button highlighted" width="1572" height="466" data-path="images/user-guides/assessment-new-vendor-button.png" />
    </Frame>
  </Step>

  <Step title="Search for the vendor (step 1 of 3)">
    The search field reads *Select from existing vendors or create new…*. Start typing and Coverbase Entity Intelligence matches against its own database, labelling each result as a **Vendor** or a **Product**. Selecting a match pre-fills the details.

    If there is no match, choose `Create vendor from scratch: "{your vendor}"`. Click it or press <kbd>Enter</kbd>.

    <Frame caption="Selecting a match pre-fills the vendor. The arrow marks the create-from-scratch option, used when nothing matches.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-vendor-search.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=01bc53b819e22e14423f29248bf7433b" alt="Vendor search with Entity Intelligence matches" width="2046" height="631" data-path="images/user-guides/assessment-vendor-search.png" />
    </Frame>
  </Step>

  <Step title="Fill in the details (step 2 of 3)">
    This step is headed **Modify Vendor Details**. If Entity Intelligence had data, most fields are already populated. Otherwise click **AI Autofill** to have Coverbase search the web, then correct anything it got wrong.

    <Frame caption="1 AI Autofill populates the record from public sources. Only Vendor Name is required.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-vendor-details.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=9ac8391effdbafa988561390896b8a2a" alt="Modify vendor details step with AI autofill" width="1512" height="660" data-path="images/user-guides/assessment-vendor-details.png" />
    </Frame>

    Only **Vendor Name** is required, but the rest save work later:

    * **Website, Description, HQ Location, Use Cases**: context the AI draws on during assessment.
    * **Security Contact Email**: used when Coverbase contacts the vendor.
    * **Trust Center URL**: enables **Retrieve from Trust Center** in [Part 3](#part-3-collect-the-evidence).
    * **Services**: you can then assess a single service rather than the whole vendor, which keeps scope tight.
    * **Vendor Contacts**: these pre-fill every document request and follow-up you send.
    * **Tags**: tags can drive which control sets apply, so if you tag by tier, do it now.
    * **Risk Analysts, Relationship Owners, Watchers**: ownership and notification.

    <Frame caption="2 Add Service. 3 Add Contact. 4 Add Tags. Then Next, bottom right.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-vendor-services-contacts-tags.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=564aa284a329bbe84fc41844f3d221e6" alt="Adding services, contacts, and tags to the vendor record" width="1510" height="928" data-path="images/user-guides/assessment-vendor-services-contacts-tags.png" />
    </Frame>
  </Step>

  <Step title="Custom fields and create (step 3 of 3)">
    Step 3 is headed **Fill in additional fields** and shows whatever custom fields your organization has defined: contract amounts, audit dates, department, SLA, and so on. None are mandatory. Click **Create Vendor** and you land on the Vendor Overview page.

    <Frame caption="Custom fields vary by organization. Create Vendor finishes the wizard.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-vendor-custom-fields.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=3730940898f5685d87803bb8d0b1afc1" alt="Custom fields step of the new vendor wizard" width="1526" height="1356" data-path="images/user-guides/assessment-vendor-custom-fields.png" />
    </Frame>

    <Note>
      **Abandoning the wizard.** Closing part-way through prompts "Discard changes?" with **Keep editing** and **Close and discard**. Discarding leaves no partial vendor behind.
    </Note>
  </Step>
</Steps>

***

## Part 2: Create the assessment

<Tip>
  **Simpler than it looks.** Assessment setup is a single dialog. Control sets and questionnaires are not chosen assessment by assessment. They come from the Assessment Plan you select.
</Tip>

<Steps>
  <Step title="Open the Assessments page and click New Assessment">
    Go to **Assessments** and click **+ New Assessment** at the top right. The list shows each assessment's outcome, score, status, auto-review progress, and both risk figures.

    <Frame caption="If the list looks empty, clear the filters. An Assignee filter persists between visits.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-list.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=8024b19a29d9ca66b384be69eac34d22" alt="Assessments list with outcome, score, status, and risk columns" width="2045" height="338" data-path="images/user-guides/assessment-list.png" />
    </Frame>
  </Step>

  <Step title="Add the vendors and any services">
    Click **+ Add vendor…** and pick the vendor, then optionally narrow to specific services. You can add more than one vendor, and each gets its own assessment from the same plan, which is the efficient way to start a batch of annual reviews. The button reads **Create Assessments** for that reason.

    <Frame caption="1 Add as many vendors as you need. 2 The plan summary tells you what you are about to run.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-add-vendors.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=6d868156bc3850bd0a4d42d59d2dcc32" alt="New assessment dialog with vendors added" width="1030" height="814" data-path="images/user-guides/assessment-add-vendors.png" />
    </Frame>
  </Step>

  <Step title="Choose the Assessment Plan">
    This single choice determines what the assessment evaluates. The dropdown defaults to **None** and lists your saved plans. Selecting one shows a summary beneath it: how many control sets and questionnaires it carries, whether documents are collected manually or automatically, whether it targets residual risk, and who reviews it.

    Read that summary before you continue; it is the fastest way to catch a plan that is heavier or lighter than the vendor warrants. **Configure** opens the plan itself if you need to inspect or change it.

    <Warning>
      Leaving the plan on **None** creates an assessment with no control sets attached, which is rarely what you want.
    </Warning>

    <Frame caption="1 Configure inspects a plan. 2 Plans are built and named by your team.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-choose-plan.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=e551e351f7970793b8e798f0d5b5e8ed" alt="Assessment plan dropdown with plan summary" width="1040" height="1188" data-path="images/user-guides/assessment-choose-plan.png" />
    </Frame>

    <Note>
      **Choosing a plan.** Plans built on your own control sets usually produce fewer and more relevant issues than a broad third-party questionnaire, which can run to several hundred expectations. Start with your own and add breadth only where you need it.
    </Note>
  </Step>

  <Step title="Check the name, then create">
    Expand **Customize assessment name**. Names are generated from a template rather than typed by hand (the default produces something like "2026 HubSpot initial"), and a live example shows the result as you edit. Leave it alone unless you have a reason to change it; consistent names are what make three hundred assessments searchable a year from now.

    Click **Create Assessments**.

    <Frame caption="1 Expand to see the template. 2 Live example. 3 The template itself.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-name-template.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=0257fdf96dc3a1dec1c029458d89984b" alt="Customize assessment name with template and live example" width="1036" height="938" data-path="images/user-guides/assessment-name-template.png" />
    </Frame>
  </Step>
</Steps>

***

## Part 3: Collect the evidence

An assessment is only as good as its evidence. Open the **Documents** tab. A **Collection Mode** badge shows whether this assessment is collecting manually or automatically, and five routes are offered. They combine freely, and each card tells you how much is available before you click.

<Frame caption="1 Existing vendor docs. 2 Request from vendor. 3 Switch to automatic. 4 Coverbase Library. 5 Trust Center. The badge shows the current collection mode.">
  <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-documents-collection.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=c313b15d91395eaf4fef699e9958761b" alt="Documents tab with the five evidence collection routes" width="1848" height="940" data-path="images/user-guides/assessment-documents-collection.png" />
</Frame>

* **Import from existing vendor docs**: anything already on the vendor profile. Fastest route for a reassessment.
* **Request from vendor**: manages the assessment portal, and shows the portal's current status so you can see where the vendor has got to.
* **Request automatic collection**: switches this assessment to automatic collection.
* **Import from Coverbase Library**: curated documents Coverbase already holds for this vendor. Check the count; for well-known vendors it is often substantial.
* **Retrieve from Trust Center**: pulls from the vendor's public trust center. Only available with a Trust Center URL on the vendor record.

Below the cards, **Upload vendor documents** takes files you hold yourself.

A sixth route needs no collection at all: where a control set allows it, the AI researches the public web while evaluating a control. That evidence is filtered on publisher accountability before it can be cited, and every accepted page carries its grade and its age. See [Evidence quality and source credibility](/user-guides/evidence-quality).

<Steps>
  <Step title="If you are using the portal, send the request">
    The vendor gets a branded portal with a due date, your message, and a checklist of what you need: questionnaires and document requests, with required items marked. They cannot submit until the required parts are done, and progress is visible to both sides.

    When they upload, analysis of the affected controls starts automatically. No handoff needed.

    <Frame caption="1 Upload area. 2 Each section the vendor must complete; Submit stays disabled until required items are done.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-vendor-portal.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=de78ced9f0a2df5ca8a1f9fbeeb962fb" alt="Vendor-facing assessment portal with upload area and required sections" width="2046" height="635" data-path="images/user-guides/assessment-vendor-portal.png" />
    </Frame>
  </Step>

  <Step title="Wait for analysis">
    Analysis typically takes 20 to 30 minutes depending on document volume. A long SOC 2 report takes longer than a certificate of insurance. You do not need to keep the tab open.

    The left panel tracks four stages: **Collecting Documents**, **Analyzing Controls**, **Review Results**, **Quality Control**. It also tells you what it is waiting for, which at the start is at least one document.

    <Frame caption="1 The four-stage tracker. 2 A shortcut to whatever the assessment needs next.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-stage-tracker.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=9307512808abb374db58ccf702cce8f9" alt="Assessment stage tracker showing the four lifecycle stages" width="636" height="674" data-path="images/user-guides/assessment-stage-tracker.png" />
    </Frame>
  </Step>
</Steps>

***

## Part 4: Find your way around the assessment

There is a lot on this page. Three areas matter.

### The left panel

Current stage, what it is waiting for, a shortcut into the work, and an **Export** menu. Below that, **Details**: assignee, inherent risk, risk target, services, and the plan the assessment came from.

### The tabs

Eleven tabs run across the top. Most of the time you need the first two, **Summary** and **Issues**. The rest carry supporting detail and the audit trail: Controls, Findings, Emails, Work Queue, Documents, Activity, Notes, Properties, and SLAs.

### The Summary tab

At the top is **Recommendation**, the human conclusion. It appears in exports, so write it properly rather than leaving it thin.

Then a band showing the **Score** as a percentage with a compliance band, how many domain reviews are complete, and **Complete Assessment**.

Then the risk domain table: **Overall Vendor Risk** plus a row per domain, each with inherent risk, residual risk, and the assigned reviewer. Domains vary by plan; a broad plan can produce nine or more, covering things like AI & Emerging Technology, Operational Resilience, Concentration & Fourth-Party Risk, and Reputational & ESG alongside the familiar Data Security and Privacy.

Rows reading "Not set" against residual risk have not been reviewed yet. Those are your gaps.

<Frame caption="1 Recommendation. 2 Score, review progress, and completion. 3 Risk by domain. 'Not set' means not yet reviewed.">
  <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-summary-domains.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=59c5e454cf6c1e1debd28d7af967954f" alt="Assessment summary tab with recommendation, score band, and risk domain table" width="1886" height="1316" data-path="images/user-guides/assessment-summary-domains.png" />
</Frame>

***

## Part 5: Work the issues

The **Issues** tab holds one result for every control in the assessment. It opens filtered to the results raised as issues.

### Reading the top of the page

* **Risk domain selector**: narrow to a single domain.
* **Control Score**: the score out of 100%.
* **Open Issues**: open count against the total.
* **Vendor Score**: inherent and residual risk for the vendor.

If any follow-ups exist, a bar summarizes them (how many await a response, how many are still drafts) alongside **Configure portal**, **Download workbook**, **Import responses**, and **Manage sent follow-ups**. The workbook and import options are there for vendors who would rather work in a spreadsheet than the portal.

<Steps>
  <Step title="Orient yourself in the list">
    Three toggles switch the view (all results, issues only, and open follow-ups), each with a count. **Group by** defaults to **Control Section**, so results arrive clustered by control set and section, with the reviewers for that section shown on the group header.

    Each row shows the control reference, the expectation in short form, status chips such as *Missing document* or *Awaiting*, any linked findings, the weight, and the result.

    <Frame caption="1 Switch between all results and issues. 2 Grouping. 3 Status chips, weight, and result on every row.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-issues-list.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=d7df6269d03cb4cff3d712b0f8d7027b" alt="Issues tab with view toggles, grouping, and result rows" width="1896" height="1100" data-path="images/user-guides/assessment-issues-list.png" />
    </Frame>
  </Step>

  <Step title="Handle the straightforward ones in bulk">
    Select rows, or **Select all**, and an action bar appears with everything you can do at once: **Accept risk**, **Add Finding**, **Create follow-ups** (the count comes along, so you can draft dozens in one sweep), **Delete follow-ups**, **Lock**, and **Draft new email**.

    On a large assessment this is the single biggest time-saver. Bulk-drafting follow-ups for every missing-document issue takes one action rather than a hundred.

    <Frame caption="1 The bulk action bar appears once anything is selected. The arrow marks the row checkboxes.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-bulk-actions.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=d45148a21ca7ca726762684b4f65a468" alt="Bulk action bar on the issues list" width="2046" height="1289" data-path="images/user-guides/assessment-bulk-actions.png" />
    </Frame>
  </Step>

  <Step title="Open an individual result">
    Click a row to open it. A status banner sits at the top with the actions available for that state. An open issue offers **Not an issue** and an **Action** menu; a result that has come back from the vendor reads **Response received** and offers **Mark as issue** instead.

    The left column shows the control: the **Expectation** (what must be true), the **Question** as it is put to the vendor, the **Guidance** for judging evidence, which **Control Set** it came from, and its **Weight**.

    Beneath it, **Evaluation** gives the score and compliance band, and a bulleted analysis explaining the verdict. Each claim carries an **Evidence** reference you can click through to. Three controls sit above it: **Correct the AI** to override the result, **Preserve** to pin a result so later runs do not overwrite it, and **Edit**.

    <Frame caption="1 Correct the AI, Preserve, Edit. 2 Actions available for this state. 3 Analysis cites its evidence inline.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-result-detail.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=f3a4fb0f16940727c13ca5968724ef93" alt="Individual control result with expectation, guidance, and cited evaluation" width="1352" height="1246" data-path="images/user-guides/assessment-result-detail.png" />
    </Frame>
  </Step>

  <Step title="Follow the citation to the source">
    The right column holds **Evidence**, **Follow-up**, **Findings**, **Emails**, and **Activity**, with prev/next controls so you can work straight through the list. Each piece of evidence names its source document and page, quotes the passage, and shows a preview of the page with the passage highlighted.

    <Frame caption="1 The cited passage, highlighted in the source document. 2 Step through results without returning to the list.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-evidence-citation.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=e813fd0c190f97e0de45ed20899f2cba" alt="Evidence panel with the cited passage highlighted in the source document" width="1294" height="914" data-path="images/user-guides/assessment-evidence-citation.png" />
    </Frame>

    <Tip>
      **Why the citation matters.** The highlighted source is what makes a result defensible. When an examiner asks why a control passed, the answer is a quoted passage from a named document on a specific page.
    </Tip>
  </Step>
</Steps>

***

## Part 6: Run follow-up cycles

Follow-ups are drafted individually and sent together, so the vendor gets one consolidated request rather than a trickle of emails.

<Steps>
  <Step title="Draft the follow-up">
    From a result, draft a follow-up question. **AI Autofill** writes a first pass that references what the evidence already showed and asks only for the gap, which is usually better than starting from scratch. **Use control question and response** reuses the original control wording instead.

    Under **Required document types** you can name what the vendor should attach, so the request is specific rather than "please send evidence".

    Saving creates a draft. Nothing reaches the vendor until the drafts are included in a follow-up questionnaire sent through the portal.

    <Frame caption="1 AI Autofill drafts the question. 2 Name the documents you need. 3 Save creates a draft, it does not send.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-draft-followup.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=d0609fed99b296cd7dbfcbc665bdac63" alt="Draft follow-up dialog with AI autofill and required document types" width="1202" height="838" data-path="images/user-guides/assessment-draft-followup.png" />
    </Frame>
  </Step>

  <Step title="Send them">
    Back on the **Issues** tab, the bar shows how many drafts are waiting. Sending opens the assessment portal with a questionnaire built from your questions and notifies the vendor. **Configure portal** controls what the vendor sees; **Manage sent follow-ups** tracks what is already out.

    <Frame caption="1 Manage what has been sent. 2 The draft count. Here a bulk action has queued a large batch.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-send-followups.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=1e33dce3a5c20c51e5afa53529e52c45" alt="Follow-up bar showing drafts waiting to send" width="2043" height="487" data-path="images/user-guides/assessment-send-followups.png" />
    </Frame>
  </Step>

  <Step title="Let the reanalysis run">
    When the vendor submits, only the controls selected for follow-up are analyzed again against the new evidence. Everything else is left alone.

    A result that has come back reads **Response received**, and the analysis is rewritten to account for what the vendor said, often moving from *Not Compliant* to *Fully Compliant* where the gap was documentation rather than practice.

    <Frame caption="1 Response received. 2 The score after reanalysis. 3 Preserved pins this result against future runs.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-response-received.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=e82ceef5d97c0570b083682061d8149b" alt="Result showing response received and the rewritten analysis" width="1330" height="1112" data-path="images/user-guides/assessment-response-received.png" />
    </Frame>

    <Note>
      **Follow-up versus rerun.** A follow-up reanalyzes only the affected controls. If you have changed the plan or control sets, or want everything re-evaluated from scratch, use the rerun option from the assessment **Actions** menu instead.
    </Note>
  </Step>
</Steps>

***

## Part 7: Reviews and quality control

Each risk domain can carry its own reviewer, which is what lets several teams work one assessment: InfoSec on the security domains, Legal on the contractual ones, Compliance on regulatory. The **Summary** tab reports progress as a count of completed reviews.

A reviewer opens their domain with **Start review**. Domains show *Not started* until someone does, and their residual risk stays "Not set".

<Frame caption="1 Start review. 2 'Not set' until reviewed. 3 Reviewer per domain. 4 Complete Assessment can stay disabled until reviews are in.">
  <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-domain-reviews.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=2a34e8a635de56dd4600bfbc415e9ddb" alt="Risk domain rows with reviewers and Start review actions" width="1882" height="816" data-path="images/user-guides/assessment-domain-reviews.png" />
</Frame>

<Warning>
  **Completion can be gated.** Depending on configuration, **Complete Assessment** stays disabled until the domain reviews are finished. If the button is greyed out, look at the review column rather than the score.
</Warning>

* Reviewers are set per domain or control set and can be changed at any time.
* Reviewers are notified when results are ready for them.
* Risk analysts and administrators can resend reminders.
* You can optionally prevent anyone who is not a risk analyst or administrator from completing assessments.

Once reviews are in, the assessment moves to **Quality Control**, the last stage on the tracker, for a final pass.

***

## Part 8: Complete and export

<Steps>
  <Step title="Complete the assessment">
    When the issues have been worked and the reviews returned, click **Complete Assessment** on the **Summary** tab.

    <Frame caption="Completion sits alongside the score and review progress.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-complete-button.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=a90bf6f094e8cf783e6ac32a8bb60091" alt="Complete Assessment button next to the score and review progress" width="1890" height="264" data-path="images/user-guides/assessment-complete-button.png" />
    </Frame>

    The dialog asks for four things:

    * **Action**: approve, reject, or whichever outcomes your organization uses.
    * **Vendor Status**: where this leaves the vendor in its lifecycle, for example *Active*.
    * **Next Vendor Reassessment Date**: set for you based on risk tier and the date you completed, typically a year out. Change it if this vendor needs watching sooner.
    * **Recommendation**: the written conclusion that appears in exports.

    **Risk Scoring Changes** expands to show how this assessment moved the vendor's scores, which is worth a look before you confirm.

    <Frame caption="1 The next reassessment date is set automatically. 2 Outcome and vendor status. 3 The recommendation carried into exports.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-complete-dialog.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=3b33e4b9757bf51c0fc0958a6f4d18cc" alt="Complete assessment dialog with action, vendor status, reassessment date, and recommendation" width="1198" height="764" data-path="images/user-guides/assessment-complete-dialog.png" />
    </Frame>
  </Step>

  <Step title="Export the results">
    Once complete, the panel reads **Complete** and offers **Export Report** in four formats: PDF, Excel, CSV, and Word.

    Match the format to the audience. PDF for anything leaving the company. Excel or CSV when someone wants to sort and filter the results themselves. Word when the output needs to drop into an existing house template. The Word export is driven by your organization's branded template, and [Custom Word report templates](/reporting/assessment-report-templates) covers changing what it pulls in.

    <Frame caption="1 Export Report. 2 Four formats, chosen by audience.">
      <img src="https://mintcdn.com/coverbase/0pGJWhjmBaO1DMAN/images/user-guides/assessment-export-report.png?fit=max&auto=format&n=0pGJWhjmBaO1DMAN&q=85&s=17fd451a04185b5ae9f2dffbc86d6bf3" alt="Export report menu with PDF, Excel, CSV, and Word formats" width="612" height="476" data-path="images/user-guides/assessment-export-report.png" />
    </Frame>

    <Note>
      **A word on report length.** The fullest export includes every result, all document evidence, the activity log, follow-ups, and notes, and can run to hundreds of pages. Reach for it when someone has asked for the complete file. For examiners and executives, the summary-level report usually lands better.
    </Note>
  </Step>
</Steps>

***

## Related guides

<CardGroup cols={2}>
  <Card title="Assessment quick reference" icon="bolt" href="/user-guides/assessment-quick-reference">
    The one-page version: steps, tips, common scenarios, and a troubleshooting table.
  </Card>

  <Card title="Analyst and reviewer guide" icon="user-check" href="/user-guides/analyst-reviewer">
    The wider daily loop, including Radar alerts, contracts, and obligations.
  </Card>

  <Card title="Admin and setup guide" icon="sliders" href="/user-guides/admin-setup">
    How assessment plans, control sets, scales, and reviewers are configured.
  </Card>

  <Card title="Evidence quality and source credibility" icon="shield-check" href="/user-guides/evidence-quality">
    How web evidence is graded and filtered before it can be cited, and where you set the bar.
  </Card>

  <Card title="Control Set library" icon="shield-check" href="/control-library">
    What ships in the box, and how control sets differ from questionnaires.
  </Card>
</CardGroup>

<Card title="Need help?" icon="envelope" href="mailto:support@coverbase.ai">
  Email [support@coverbase.ai](mailto:support@coverbase.ai), or ask your Coverbase contact to run a live working session with your team.
</Card>
