Skip to main content
This guide is part of the User Guides collection. For what the capability is and where it stops, see Zero Touch Assessments. For the sub-scores it folds in, see Financial Health Score, Security Intelligence, Corporate Registrations and People Intelligence.
Zero Touch Assessments are an optional module. If you don’t see Zero Touch Assessment in the left navigation, let your Coverbase representative know you’d like it turned on.
A Zero Touch Assessment answers one question cheaply: is anything obviously wrong with this vendor? It is an ordinary assessment on the ordinary pipeline, with the same controls, issues and evidence. Three differences make it a triage tool rather than a review:

Nobody is contacted

No document request, no questionnaire, no waiting on a vendor to reply. A run completes against public research and whatever evidence is already on file.

It runs without you

Launch it across a batch and walk away. Nothing is assigned to a reviewer and nothing waits on a reply, so covering a long tail of vendors takes no ongoing effort.

It produces one number

A single Zero Touch Score, so a batch of vendors can be ranked rather than read one by one.

When to reach for one

Zero Touch is a filter, not a replacement for a full assessment. It is the right tool when:
  • A new vendor arrives and you need to know whether to spend a real review on it.
  • You have inherited a portfolio and have no idea which vendors are risky.
  • A renewal is coming up and you want a cheap re-check since the last review.
  • Someone asks “are we exposed to this vendor?” and you need an answer today.
It is the wrong tool when you need assurance you can show an auditor. A run has never spoken to the vendor, so it cannot confirm a control is operating. It can only tell you whether public evidence supports it.

Running one

The Zero Touch launch wizard, showing vendor selection with a search box and a running count of selected vendors.

1 Pick one vendor or many. 2 Search and filter the vendor list. 3 Selected vendors carry to the next step.

1

Pick your vendors

From Zero Touch Assessment → Launch, choose one vendor or many. You can also start from a vendor’s own page, or select rows in the vendors table and launch the whole selection at once.
2

Choose the question set

Pick the template the run evaluates. Zero Touch Comprehensive is the default and covers everything public evidence can settle; the lighter and industry-specific templates are there when that is more than you need.
Choosing a template changes what every future run evaluates, not just this one. It is an organization-level setting that happens to be reachable from the wizard. Your earlier runs keep the scope they were launched with, and each run records which template it used.
3

Confirm

The last step has no inputs. What feeds the score and where the score goes are configured once for your organization, so every run stays comparable with every other run on the same template.
4

Come back to the runs table

Runs complete on their own. The module page sorts by score by default, which is the order to work them in.
The confirm step of the Zero Touch launch wizard, listing the vendors about to be assessed and the control sets in scope.

The confirm step. Nothing to configure, because scope and scoring are set once for the organization.

The Zero Touch runs table, listing vendors by composite score with per-component columns for controls, financial health, security, registration and people.

1 Search, saved views and filters. 2 Composite score and band. 3 Per-component scores. 4 Row selection for bulk actions.

This is the same table as the vendors and assessments lists, so everything you already know about those works here. Sort by any column, filter on any field, choose which columns to show and in what order, and save the whole arrangement as a view you can come back to or share with your team. Sorting by score is only the default; sort by when a run happened to watch a batch finish. Two details specific to scoring:
  • Score columns read down, not across. Every score sits in the same place in every row, so you can scan a column rather than read each row.
  • A dash is not a zero. It means the component did not resolve for that vendor, and it was left out of the composite rather than counted against them.

Working a batch

Select rows with the checkboxes, then act on the whole selection at once. Click a checkbox to toggle that row. Hold Shift and click another to take everything in between.
The Zero Touch runs table with three rows selected, and a floating bar reading 3 assessments selected with Approve, Escalate and Archive buttons.

1 Click a checkbox to toggle a row, Shift-click another to take the range. 2 The footer counts your selection against every run, not just this page. 3 Approve, escalate or archive the whole selection at once.

1

Approve

Records your approval against every selected run. Each one gets its own entry in its own audit trail, exactly as if you had opened it and approved it there.
2

Escalate

Flags the selection for a full assessment. Escalating does not start one, because a full assessment commits your team and your vendor to real work. Starting it stays a deliberate act.
3

Archive

Removes the selected runs from the module. This one asks for confirmation, because it is the only action here you cannot undo from this page.
If a run in your selection has been archived by someone else since the page loaded, it is reported as skipped and the rest still go through.

Reading a result

Open any run to get a single-page fact sheet. It opens with every section collapsed, so the first thing you see is the composite, the band, and the shape of what the run covered. Click a section to read it, or use the rail on the left to jump straight to one.
A Zero Touch result page as it first opens, showing a composite score of 85 marked Low risk, a Review score composition link, a left-hand rail listing every section, and eleven collapsed sections from Vendor profile through Notes.

A finished run as it opens: the composite and band in the review banner, the rail on the left, and each section collapsed to its one-line summary.

A dash instead of a tick means the section produced nothing. That is not a failing grade; it means nothing public settled it, and its share of the score moved to the sections that did report.
A Zero Touch result page with every section expanded: the vendor profile and inherent-risk reasoning, two control sets scored 92 and 78, five score-composition cards, two open issues with evidence links, the sources grouped by kind, and the Activity and Notes sections, with the Actions menu open over the review banner.

The same run with its sections open, and the Actions menu drawn down over the banner.

Read it in this order:
1

Who the vendor is

The page opens with the company itself: what it sells, the industry it operates in, what an organization would typically use it for, its services and where it is headquartered. This is for the common case where you know a vendor is in use but not what it does.Everything here is researched from public sources, never asked of the vendor. Two separate confidence markers sit beside it, and they mean different things:
  • Identity confidence: how sure the run is that it profiled the right company. Low when the name is generic or several companies share it.
  • Risk tier confidence: how sure it is about the exposure. A run can be certain which company this is and still be unsure how much risk it represents.
2

The risk tier

A triage read of how much exposure the vendor typically creates (critical, high, moderate, low or minimal) with a one-line reason and the full argument underneath.
This is its own scale, deliberately not your organization’s risk levels. Those are calibrated against a completed questionnaire; this is judged from the outside. It does not touch a vendor’s inherent risk unless your organization turns that on, and even then it stands down if the composite score is already being written there.
3

The composite, then what it's made of

The headline number combines up to five independently-sourced components: the control evaluation, the vendor’s Financial Health Score, its outside-in security rating, its corporate registration standing, and its leadership dossier. Each is scored 0–100 on its own before anything is combined.
4

Check which components actually resolved

A component with no data is left out, never counted as zero. A vendor with no filed financials has not failed the financial component. It has no financial component, and the remaining weights are redistributed across what did resolve. The card tells you both the weight it was configured with and the share it actually carried.
This is the most common misreading. A vendor scoring 78 on one component is not comparable to a vendor scoring 78 on three. Check the composition before ranking two vendors against each other.
5

Work the controls

Controls sits directly under the vendor profile, ahead of Security posture, Corporate registration, Financial health and People, because the control evaluation is one of the things the composite is made of rather than a footnote to it. See Working the controls below.
6

Work the issues

Each open issue carries the evidence behind it and the control set that raised it. This is the part that tells you what is wrong, as opposed to how much.
7

Check the sources

Every place the run drew evidence from is listed, grouped by kind: web research, registries and filings, vendor infrastructure, and documents already on file. If a conclusion looks wrong, this is where you check its provenance.

Working the controls

Every control the run evaluated is listed under Controls, grouped into sections (Security, Privacy, Company and identity, and so on) with its identifier, the question that was put to the research, the answer, and the evidence behind it.

The four outcomes

A Zero Touch run reads public evidence and nothing else, so pass/fail is the wrong shape for what it can honestly say. Each control lands in one of four states:
Not enough information is not a finding against the vendor. It says the question cannot be answered from outside, which is what a full assessment is for. Treating it as a failure is the most common way to misread one of these runs, which is why it has its own view rather than being folded in with what was found.

Four views over the same list

  • What we found: the not-validated controls. Start here.
  • What we validated: validated and partially validated together, so you can see what the vendor demonstrably does publish.
  • Not settled: the controls nothing public answered.
  • All controls: everything, in section order.

Recording your verdict

Each control takes a decision, on its own or several at once:
1

Confirm

You agree with what the run concluded. The control stays as it is.
2

Dismiss

You disagree, or the issue does not apply to how you use this vendor. The control is marked resolved and drops out of the open issues.
3

Note

Leave context for whoever reads the run next: why you accepted a thin answer, or what you checked separately.
4

Create findings

Select one or more controls and raise findings from them. This is the same finding creation the assessment page uses, so the result is an ordinary finding that behaves like any other.
Verdicts are recorded on the control itself, not in a Zero Touch-only place, so the assessment page and the Excel export show the same thing you decided here.

What is in a template

Every template card carries a What’s in it? link listing all of its controls by section: the identifier, the question, and what the run treats as a pass. Worth reading before you commit a portfolio to a template.

Deciding what happens next

A result page is a decision point, and there are three reasonable exits:

Accept it

The vendor is low-risk enough that a full review isn’t warranted right now. The score can be written onto the vendor’s risk score automatically. See below.

Escalate

Create full assessment carries the vendor straight into a normal assessment, with the triage findings already on the record.

Reassess

Financial and security inputs refresh on their own schedule. Reassess recomputes the composite against today’s data without re-running the controls, and takes a correction first if you give one.
A fourth exit, Archive, takes a run out of the working set without deleting it, for a duplicate or a vendor you no longer use. It is confirmed before it applies, because it is the one action here you cannot undo from the page.

Reviewing a run

Everything you can do to a run sits behind Actions, at the top right of the result page. You can approve the run, create a full assessment from it, reassess it, open the full record, export it, or archive it.
The Zero Touch Actions menu on a finished run: view full record, approve, create full assessment, reassess, export PDF, export spreadsheet, and archive.

Approve closes the run. Create full assessment carries it onward. Reassess re-runs it, taking your correction first if you give one.

Reassess opens a box for a correction before it re-runs. Leave it empty and the run is simply re-scored against refreshed sources. The correction box takes plain language, not a form:
This is the wrong company. The vendor we mean is at northwind.example
Zero Touch researches a vendor from public sources with nobody to ask, so it sometimes binds the wrong website, or a different company with a similar name. Describing that in a sentence is faster than hunting for the field it maps to, and it is what a reviewer knows first. What happens when you submit: the correction is read into a short, fixed set of fields, the website and the company name and nothing else. Those are applied to the vendor record, and the run is re-scored against them. Your exact words, the fields that changed, and the score before and after are all written to the audit trail below.
A correction that our reading could not turn into a concrete change is still recorded, and says so. Silence would be indistinguishable from never having asked.

While a run is working

Results fill in as they land, so a run is readable long before it finishes. Each stage carries its own state, and the banner at the top is the only place a run can be stopped.
A Zero Touch result page for a run still working: a Running banner with a progress bar and a Cancel menu, and stage cards below showing which have finished, which are working and which are still waiting.

Stages fill in as they land. Cancel stops the run; start over relaunches it, optionally with a correction.

The Actions menu keeps its shape while the run works and greys out what cannot work yet — there is nothing to export, no score to reassess and nothing settled to approve.
The Zero Touch Actions menu on a run in flight, with approve, create full assessment, reassess and the exports greyed out, and view full record still available.

The same menu on a run in flight. What is greyed out is what the run has not produced yet.

Where a run stands

Every run carries a review status, shown on the result page and as a column in the runs table: A run is scored as soon as the engine finishes, before anyone approves it. Approval is a judgement about the result, not what produces it.
Archiving does not overwrite an approval. The status answers “was this result accepted?”; archiving answers “is this still in my working set”. They are different questions, and the trail records both.

The audit trail and notes

Below the result, the Activity section is the same activity log that vendors and assessments use, and it lists every action on the run with who took it, what it changed and what the score did: approvals, escalations, archives, corrections, re-scores and control verdicts alike. Notes sits underneath it for context that is not an action.
The Zero Touch review trail is append-only. Nothing on it can be edited or removed, including by us. A correction that later turns out to be wrong is fixed by making another correction, which appears as a new entry.
This matters because a Zero Touch Score can be written onto a vendor’s real risk score. If a number moved, the trail is what tells you whether the machine found something or a person corrected it. Escalating does not itself launch a full assessment. It records the judgement; starting the assessment stays a deliberate act, because a full assessment puts work in front of your team and your vendor.

Where the score goes

By default the Zero Touch Score stays on the run. Your administrator can point it at a risk score instead, from Scoring on the module page: Only the axis you choose is written, so a Zero Touch run can never overwrite an inherent score your team set deliberately from an intake questionnaire.
A vendor-scoped run configured to write a service score writes nothing, and says so on the result. Guessing which service was meant would move the wrong number.

Tuning what feeds the score

Also under Scoring: which signals count, and how heavily.
  • Toggle the financial health, security, corporate registration and people components on or off for your organization.
  • Set relative weights. They are not percentages. They are renormalised over whichever components resolve for a given vendor, which is why a vendor missing one component still scores out of a full 100.
Two of the components are derived rather than read from an existing score, and behave in ways worth knowing:
Scores the registry standing of an identity that was actually matched to this vendor. A vendor no register matched is unavailable, not zero. Plenty of legitimate private companies appear in none of the free registers. A plausible but unconfirmed match is capped well below a confirmed one. A dissolved company scores above an unfound one, because being on record and wound up is better evidenced than never being found.
Starts from how much of the leadership is on record and deducts for adverse-media findings, capped so a long tail cannot dominate a triage number. Informational items such as a departure or a disputed report are shown, and carry no weight.If adverse-media screening never ran, nothing is deducted at all. A screening that did not happen cannot establish the clean record a zero deduction would imply, so the component scores leadership visibility alone and labels itself Adverse media not screened.

Choosing a template

Under Scoring, or as a step in the launch wizard, you can switch which set of questions Zero Touch runs evaluate. Six ship with the product: All six draw on the same catalogue of 49 questions, spread across eleven domains: company and identity, security, privacy, compliance, technical operations, resilience, financial health, ethics, ESG, reputation and AI governance. A template is a selection from that catalogue, not a separate set of questions, so a control means the same thing and is scored the same way whichever template you run. A question earns its place in the catalogue only if public evidence can settle it. Anything that needs the vendor to answer would come back unevaluated on every run and make the vendor look worse than they are.

What each one is for

Every question in the catalogue. This is the widest picture open-source research can produce, and the right starting point when you do not yet know what your portfolio looks like.It is also the most sensitive to a thin vendor. A small supplier with no certifications, no filings and no security page will leave a lot of questions unevaluated, and the score reflects what could be checked rather than everything asked. If most of your tail looks like that, one of the narrower templates will read better.
The twelve questions that most often decide whether a vendor needs a full review: is this a real, standing company, is there any security posture on record, has anything gone publicly wrong, and is anyone accountable.Fastest to run and cheapest to read. Use it when the goal is to sort a long list into “look at this” and “leave it”, rather than to characterise any one vendor in depth. It is the best choice for a first pass over hundreds of vendors.
Weighted towards what matters when the vendor holds your data: SOC 2 and ISO 27001, sub-processor disclosure, hosting and region, encryption and TLS, MFA and SSO, vulnerability disclosure, status and incident history, exit and portability, and whether customer data is used to train models.Drops most of the physical-supply and labour questions, which rarely apply and would otherwise sit unevaluated.
For vendors that may touch PHI. Adds weight to breach history, data retention and regulatory action, because healthcare enforcement is unusually well documented in public sources. HHS breach reporting in particular means a real incident is usually findable.Narrower than the SaaS template on infrastructure detail, deeper on what happens to records and what regulators have said.
For regulated financial-sector supply chains. Emphasises operational resilience, regulatory standing, sanctions exposure and corporate transparency: who ultimately owns this company, and is that ownership traceable in a register.This is the template most likely to surface a corporate-structure problem, which is often the finding that matters in a financial supply chain.
For professional services, staffing and physical suppliers, where the technical surface is small and the real questions are ethics, labour practices, continuity and financial standing.Use this rather than Comprehensive for vendors with little or no online product. Asking a staffing agency about sub-processors and TLS configuration produces a page of unevaluated controls and a score that says more about the questions than the vendor.
If a lot of your runs come back with many unevaluated controls, that is usually a sign the template is wrong for the kind of vendor rather than a sign the vendor is bad. Switch to a narrower template and re-run.
Switching template applies to future runs. Past runs keep the scope they were launched with, and each run records which template it used, so if you compare two runs, check they answered the same questions.
If your organization runs a control set of its own rather than one of these, no template is highlighted and the picker says so.

Getting the results out

1

A whole portfolio

Select runs in the table and choose Export as Excel from the selection bar. One row per run, carrying the score, band, and the profile fields including the risk tier and its reasoning.
2

A single run

From Actions on a result page, Export as Excel gives four sheets (profile, score components, coverage and findings) and Export as PDF gives a letter-sized report laid out like the page itself.

Things worth knowing

It shouldn’t be. In-flight runs appear immediately and sort below scored ones. If it is genuinely empty, no Zero Touch runs exist yet for this organization.
Yes. A Zero Touch run is an assessment. The vendor’s Assessments tab splits into Full and Zero Touch, and the Full list excludes triage runs so a first pass is never mistaken for a completed review.
Because no public evidence spoke to it. That is a real result, not a failure. It tells you the question can only be answered by asking the vendor, which is what a full assessment is for.
Fresh. Launching a run re-gathers the vendor’s registration, security and people research before scoring, so a composite is never a mix of today’s controls and research from months ago. The controls are re-evaluated every time regardless.
That is the control’s identifier, and it is stable, so you can quote it in a ticket or match it against an export. Codes are numbered within their section, so the letters tell you the area at a glance.
Yes. Re-run a vendor whenever something changes or new evidence lands. The table always shows the most recent run per vendor, and earlier runs stay reachable from the vendor’s own page.
Yes. Correct the vendor from Actions → Reassess, telling it the right name or website in your own words, then use Re-source profile on the result page. Re-scoring alone deliberately keeps the existing profile, so correcting identity is the step that refreshes it.
Not unless your organization turns that on, and it is off by default. Even when on, it stands down if the composite score is already configured to write to vendor inherent risk, so two things never fight over the same field.