How to run a lightweight, no-outreach assessment across a portfolio of vendors, read the score it produces, and decide which vendors are worth a full review.
Zero Touch Assessments are an optional module. If you don’t see Zero Touch Assessment in the left navigation, let your Coverbase representative know you’d like it turned on.
A Zero Touch Assessment answers one question cheaply: is anything obviously wrong with this vendor?It is an ordinary assessment on the ordinary pipeline, with the same controls, issues and evidence. Three differences make it a triage tool rather than a review:
Nobody is contacted
No document request, no questionnaire, no waiting on a vendor to reply. A run completes against public research and whatever evidence is already on file.
It runs without you
Launch it across a batch and walk away. Nothing is assigned to a reviewer and nothing waits on a reply, so covering a long tail of vendors takes no ongoing effort.
It produces one number
A single Zero Touch Score, so a batch of vendors can be ranked rather than read one by one.
Zero Touch is a filter, not a replacement for a full assessment. It is the right tool when:
A new vendor arrives and you need to know whether to spend a real review on it.
You have inherited a portfolio and have no idea which vendors are risky.
A renewal is coming up and you want a cheap re-check since the last review.
Someone asks “are we exposed to this vendor?” and you need an answer today.
It is the wrong tool when you need assurance you can show an auditor. A run has never spoken to the vendor, so it cannot confirm a control is operating. It can only tell you whether public evidence supports it.
1 Pick one vendor or many. 2 Search and filter the vendor list. 3 Selected vendors carry to the next step.
1
Pick your vendors
From Zero Touch Assessment → Launch, choose one vendor or many. You can also start from a vendor’s own page, or select rows in the vendors table and launch the whole selection at once.
2
Choose the question set
Pick the template the run evaluates. Zero Touch Comprehensive is the default and covers everything public evidence can settle; the lighter and industry-specific templates are there when that is more than you need.
Choosing a template changes what every future run evaluates, not just this one. It is an organization-level setting that happens to be reachable from the wizard. Your earlier runs keep the scope they were launched with, and each run records which template it used.
3
Confirm
The last step has no inputs. What feeds the score and where the score goes are configured once for your organization, so every run stays comparable with every other run on the same template.
4
Come back to the runs table
Runs complete on their own. The module page sorts by score by default, which is the order to work them in.
The confirm step. Nothing to configure, because scope and scoring are set once for the organization.
1 Search, saved views and filters. 2 Composite score and band. 3 Per-component scores. 4 Row selection for bulk actions.
This is the same table as the vendors and assessments lists, so everything you already know about those works here. Sort by any column, filter on any field, choose which columns to show and in what order, and save the whole arrangement as a view you can come back to or share with your team. Sorting by score is only the default; sort by when a run happened to watch a batch finish.Two details specific to scoring:
Score columns read down, not across. Every score sits in the same place in every row, so you can scan a column rather than read each row.
A dash is not a zero. It means the component did not resolve for that vendor, and it was left out of the composite rather than counted against them.
Select rows with the checkboxes, then act on the whole selection at once. Click a checkbox to toggle that row. Hold Shift and click another to take everything in between.
1 Click a checkbox to toggle a row, Shift-click another to take the range. 2 The footer counts your selection against every run, not just this page. 3 Approve, escalate or archive the whole selection at once.
1
Approve
Records your approval against every selected run. Each one gets its own entry in its own audit trail, exactly as if you had opened it and approved it there.
2
Escalate
Flags the selection for a full assessment. Escalating does not start one, because a full assessment commits your team and your vendor to real work. Starting it stays a deliberate act.
3
Archive
Removes the selected runs from the module. This one asks for confirmation, because it is the only action here you cannot undo from this page.
If a run in your selection has been archived by someone else since the page loaded, it is reported as skipped and the rest still go through.
Open any run to get a single-page fact sheet. It opens with every section
collapsed, so the first thing you see is the composite, the band, and the shape
of what the run covered. Click a section to read it, or use the rail on the left
to jump straight to one.
A finished run as it opens: the composite and band in the review banner, the rail on the left, and each section collapsed to its one-line summary.
A dash instead of a tick means the section produced nothing. That is not a
failing grade; it means nothing public settled it, and its share of the score
moved to the sections that did report.
The same run with its sections open, and the Actions menu drawn down over the banner.
Read it in this order:
1
Who the vendor is
The page opens with the company itself: what it sells, the industry it operates in, what an organization would typically use it for, its services and where it is headquartered. This is for the common case where you know a vendor is in use but not what it does.Everything here is researched from public sources, never asked of the vendor. Two separate confidence markers sit beside it, and they mean different things:
Identity confidence: how sure the run is that it profiled the right company. Low when the name is generic or several companies share it.
Risk tier confidence: how sure it is about the exposure. A run can be certain which company this is and still be unsure how much risk it represents.
2
The risk tier
A triage read of how much exposure the vendor typically creates (critical, high, moderate, low or minimal) with a one-line reason and the full argument underneath.
This is its own scale, deliberately not your organization’s risk levels. Those are calibrated against a completed questionnaire; this is judged from the outside. It does not touch a vendor’s inherent risk unless your organization turns that on, and even then it stands down if the composite score is already being written there.
3
The composite, then what it's made of
The headline number combines up to five independently-sourced components: the control evaluation, the vendor’s Financial Health Score, its outside-in security rating, its corporate registration standing, and its leadership dossier. Each is scored 0–100 on its own before anything is combined.
4
Check which components actually resolved
A component with no data is left out, never counted as zero. A vendor with no filed financials has not failed the financial component. It has no financial component, and the remaining weights are redistributed across what did resolve. The card tells you both the weight it was configured with and the share it actually carried.
This is the most common misreading. A vendor scoring 78 on one component is not comparable to a vendor scoring 78 on three. Check the composition before ranking two vendors against each other.
5
Work the controls
Controls sits directly under the vendor profile, ahead of Security posture, Corporate registration, Financial health and People, because the control evaluation is one of the things the composite is made of rather than a footnote to it. See Working the controls below.
6
Work the issues
Each open issue carries the evidence behind it and the control set that raised it. This is the part that tells you what is wrong, as opposed to how much.
7
Check the sources
Every place the run drew evidence from is listed, grouped by kind: web research, registries and filings, vendor infrastructure, and documents already on file. If a conclusion looks wrong, this is where you check its provenance.
Every control the run evaluated is listed under Controls, grouped into sections (Security, Privacy, Company and identity, and so on) with its identifier, the question that was put to the research, the answer, and the evidence behind it.
A Zero Touch run reads public evidence and nothing else, so pass/fail is the wrong shape for what it can honestly say. Each control lands in one of four states:
Outcome
What it means
Validated
Public evidence was found, and it meets the expectation.
Partially validated
Evidence was found, but it is thin or indirect enough that the run is not certain.
Not validated
Evidence was found, and it does not meet the expectation. This is the issue case.
Not enough information
Nothing public settles it.
Not enough information is not a finding against the vendor. It says the question cannot be answered from outside, which is what a full assessment is for. Treating it as a failure is the most common way to misread one of these runs, which is why it has its own view rather than being folded in with what was found.
Each control takes a decision, on its own or several at once:
1
Confirm
You agree with what the run concluded. The control stays as it is.
2
Dismiss
You disagree, or the issue does not apply to how you use this vendor. The control is marked resolved and drops out of the open issues.
3
Note
Leave context for whoever reads the run next: why you accepted a thin answer, or what you checked separately.
4
Create findings
Select one or more controls and raise findings from them. This is the same finding creation the assessment page uses, so the result is an ordinary finding that behaves like any other.
Verdicts are recorded on the control itself, not in a Zero Touch-only place, so the assessment page and the Excel export show the same thing you decided here.
Every template card carries a What’s in it? link listing all of its controls by section: the identifier, the question, and what the run treats as a pass. Worth reading before you commit a portfolio to a template.
A result page is a decision point, and there are three reasonable exits:
Accept it
The vendor is low-risk enough that a full review isn’t warranted right now. The score can be written onto the vendor’s risk score automatically. See below.
Escalate
Create full assessment carries the vendor straight into a normal assessment, with the triage findings already on the record.
Reassess
Financial and security inputs refresh on their own schedule. Reassess recomputes the composite against today’s data without re-running the controls, and takes a correction first if you give one.
A fourth exit, Archive, takes a run out of the working set without deleting it, for a duplicate or a vendor you no longer use. It is confirmed before it applies, because it is the one action here you cannot undo from the page.
Everything you can do to a run sits behind Actions, at the top right of the result page. You can approve the run, create a full assessment from it, reassess it, open the full record, export it, or archive it.
Approve closes the run. Create full assessment carries it onward. Reassess re-runs it, taking your correction first if you give one.
Reassess opens a box for a correction before it re-runs. Leave it empty and the run is simply re-scored against refreshed sources.The correction box takes plain language, not a form:
This is the wrong company. The vendor we mean is at northwind.example
Zero Touch researches a vendor from public sources with nobody to ask, so it sometimes binds the wrong website, or a different company with a similar name. Describing that in a sentence is faster than hunting for the field it maps to, and it is what a reviewer knows first.What happens when you submit: the correction is read into a short, fixed set of fields, the website and the company name and nothing else. Those are applied to the vendor record, and the run is re-scored against them. Your exact words, the fields that changed, and the score before and after are all written to the audit trail below.
A correction that our reading could not turn into a concrete change is still recorded, and says so. Silence would be indistinguishable from never having asked.
Results fill in as they land, so a run is readable long before it finishes. Each stage carries its own state, and the banner at the top is the only place a run can be stopped.
Stages fill in as they land. Cancel stops the run; start over relaunches it, optionally with a correction.
The Actions menu keeps its shape while the run works and greys out what cannot work yet — there is nothing to export, no score to reassess and nothing settled to approve.
The same menu on a run in flight. What is greyed out is what the run has not produced yet.
Every run carries a review status, shown on the result page and as a column in the runs table:
Status
Meaning
Running
The engine is still working. The progress bar shows how far along it is.
Review results
Finished and scored, and nobody has decided on it yet.
Approved
A reviewer accepted the result.
Escalated
A reviewer judged that triage was not enough.
Archived
Out of the working set. Still readable by URL, and its trail is kept.
A run is scored as soon as the engine finishes, before anyone approves it. Approval is a judgement about the result, not what produces it.
Archiving does not overwrite an approval. The status answers “was this result accepted?”; archiving answers “is this still in my working set”. They are different questions, and the trail records both.
Below the result, the Activity section is the same activity log that vendors and assessments use, and it lists every action on the run with who took it, what it changed and what the score did: approvals, escalations, archives, corrections, re-scores and control verdicts alike. Notes sits underneath it for context that is not an action.
The Zero Touch review trail is append-only. Nothing on it can be edited or removed, including by us. A correction that later turns out to be wrong is fixed by making another correction, which appears as a new entry.
This matters because a Zero Touch Score can be written onto a vendor’s real risk score. If a number moved, the trail is what tells you whether the machine found something or a person corrected it.Escalating does not itself launch a full assessment. It records the judgement; starting the assessment stays a deliberate act, because a full assessment puts work in front of your team and your vendor.
By default the Zero Touch Score stays on the run. Your administrator can point it at a risk score instead, from Scoring on the module page:
Setting
Effect
Don’t apply the score
The score stays on the run and changes nothing else.
Vendor inherent / residual
Written onto the vendor’s risk score when a run completes.
Service inherent / residual
Written onto each service the run covered.
Only the axis you choose is written, so a Zero Touch run can never overwrite an inherent score your team set deliberately from an intake questionnaire.
A vendor-scoped run configured to write a service score writes nothing, and says so on the result. Guessing which service was meant would move the wrong number.
Also under Scoring: which signals count, and how heavily.
Toggle the financial health, security, corporate registration and people components on or off for your organization.
Set relative weights. They are not percentages. They are renormalised over whichever components resolve for a given vendor, which is why a vendor missing one component still scores out of a full 100.
Two of the components are derived rather than read from an existing score, and behave in ways worth knowing:
Corporate registration
Scores the registry standing of an identity that was actually matched to this vendor. A vendor no register matched is unavailable, not zero. Plenty of legitimate private companies appear in none of the free registers. A plausible but unconfirmed match is capped well below a confirmed one. A dissolved company scores above an unfound one, because being on record and wound up is better evidenced than never being found.
People
Starts from how much of the leadership is on record and deducts for adverse-media findings, capped so a long tail cannot dominate a triage number. Informational items such as a departure or a disputed report are shown, and carry no weight.If adverse-media screening never ran, nothing is deducted at all. A screening that did not happen cannot establish the clean record a zero deduction would imply, so the component scores leadership visibility alone and labels itself Adverse media not screened.
Under Scoring, or as a step in the launch wizard, you can switch which set of questions Zero Touch runs evaluate. Six ship with the product:
Template
Questions
Best for
Zero Touch Comprehensive(default)
49
Everything public evidence can settle, across every domain
Zero Touch Essentials
12
Triaging a long tail fast, when you mostly need to know who to look at
Zero Touch for SaaS and Cloud
30
Vendors that host or process your data
Zero Touch for Healthcare
21
Vendors that may touch PHI
Zero Touch for Financial Services
29
Regulated financial-sector supply chains
Zero Touch for Services and Suppliers
25
Professional services, staffing and physical suppliers
All six draw on the same catalogue of 49 questions, spread across eleven domains: company and identity, security, privacy, compliance, technical operations, resilience, financial health, ethics, ESG, reputation and AI governance. A template is a selection from that catalogue, not a separate set of questions, so a control means the same thing and is scored the same way whichever template you run.A question earns its place in the catalogue only if public evidence can settle it. Anything that needs the vendor to answer would come back unevaluated on every run and make the vendor look worse than they are.
Zero Touch Comprehensive: 49 questions (the default)
Every question in the catalogue. This is the widest picture open-source research can produce, and the right starting point when you do not yet know what your portfolio looks like.It is also the most sensitive to a thin vendor. A small supplier with no certifications, no filings and no security page will leave a lot of questions unevaluated, and the score reflects what could be checked rather than everything asked. If most of your tail looks like that, one of the narrower templates will read better.
Zero Touch Essentials: 12 questions
The twelve questions that most often decide whether a vendor needs a full review: is this a real, standing company, is there any security posture on record, has anything gone publicly wrong, and is anyone accountable.Fastest to run and cheapest to read. Use it when the goal is to sort a long list into “look at this” and “leave it”, rather than to characterise any one vendor in depth. It is the best choice for a first pass over hundreds of vendors.
Zero Touch for SaaS and Cloud: 30 questions
Weighted towards what matters when the vendor holds your data: SOC 2 and ISO 27001, sub-processor disclosure, hosting and region, encryption and TLS, MFA and SSO, vulnerability disclosure, status and incident history, exit and portability, and whether customer data is used to train models.Drops most of the physical-supply and labour questions, which rarely apply and would otherwise sit unevaluated.
Zero Touch for Healthcare: 21 questions
For vendors that may touch PHI. Adds weight to breach history, data retention and regulatory action, because healthcare enforcement is unusually well documented in public sources. HHS breach reporting in particular means a real incident is usually findable.Narrower than the SaaS template on infrastructure detail, deeper on what happens to records and what regulators have said.
Zero Touch for Financial Services: 29 questions
For regulated financial-sector supply chains. Emphasises operational resilience, regulatory standing, sanctions exposure and corporate transparency: who ultimately owns this company, and is that ownership traceable in a register.This is the template most likely to surface a corporate-structure problem, which is often the finding that matters in a financial supply chain.
Zero Touch for Services and Suppliers: 25 questions
For professional services, staffing and physical suppliers, where the technical surface is small and the real questions are ethics, labour practices, continuity and financial standing.Use this rather than Comprehensive for vendors with little or no online product. Asking a staffing agency about sub-processors and TLS configuration produces a page of unevaluated controls and a score that says more about the questions than the vendor.
If a lot of your runs come back with many unevaluated controls, that is usually a sign the template is wrong for the kind of vendor rather than a sign the vendor is bad. Switch to a narrower template and re-run.
Switching template applies to future runs. Past runs keep the scope they were launched with, and each run records which template it used, so if you compare two runs, check they answered the same questions.
If your organization runs a control set of its own rather than one of these, no template is highlighted and the picker says so.
Select runs in the table and choose Export as Excel from the selection bar. One row per run, carrying the score, band, and the profile fields including the risk tier and its reasoning.
2
A single run
From Actions on a result page, Export as Excel gives four sheets (profile, score components, coverage and findings) and Export as PDF gives a letter-sized report laid out like the page itself.
Why is my runs table empty right after a bulk launch?
It shouldn’t be. In-flight runs appear immediately and sort below scored ones. If it is genuinely empty, no Zero Touch runs exist yet for this organization.
Do Zero Touch runs show up in my normal assessments list?
Yes. A Zero Touch run is an assessment. The vendor’s Assessments tab splits into Full and Zero Touch, and the Full list excludes triage runs so a first pass is never mistaken for a completed review.
Why did a control come back unevaluated?
Because no public evidence spoke to it. That is a real result, not a failure. It tells you the question can only be answered by asking the vendor, which is what a full assessment is for.
Does a re-run use fresh intelligence, or what was gathered last time?
Fresh. Launching a run re-gathers the vendor’s registration, security and people research before scoring, so a composite is never a mix of today’s controls and research from months ago. The controls are re-evaluated every time regardless.
Why does a control show a code like ZT-SEC-04?
That is the control’s identifier, and it is stable, so you can quote it in a ticket or match it against an export. Codes are numbered within their section, so the letters tell you the area at a glance.
Can I re-run a vendor?
Yes. Re-run a vendor whenever something changes or new evidence lands. The table always shows the most recent run per vendor, and earlier runs stay reachable from the vendor’s own page.
The profile describes the wrong company. Can I fix it?
Yes. Correct the vendor from Actions → Reassess, telling it the right name or website in your own words, then use Re-source profile on the result page. Re-scoring alone deliberately keeps the existing profile, so correcting identity is the step that refreshes it.
Does the risk tier change my vendor's risk score?
Not unless your organization turns that on, and it is off by default. Even when on, it stands down if the composite score is already configured to write to vendor inherent risk, so two things never fight over the same field.
⌘I
Assistant
Responses are generated using AI and may contain mistakes.