Skip to main content

Review a Vendor's Responses

Updated over 2 weeks ago

Once your vendor has provided their answers and submitted the Security Review, you'll be able to review their responses, add feedback for the vendor, and flag responses as a potential risk for your internal team to review.

Start the review process

Select a Security Review from the Due Diligence homepage or from the vendor's page.

1. Use filters to narrow down responses

Once in the Security Review, you can use the filter on the top to narrow down responses by Status, Comments, Assignees, or Sections.

Filters.png

2. Review the vendor's submission

You'll have the following options for each question:

ReviewOptions.png
  • Approve - you/your team approve of the response and no further action/attention is needed. This will not be shared with the vendor.

  • Submit feedback - this is feedback for your vendor and could include a request for further detail or other feedback information for them. This will be shared with the vendor.

  • Flag - flag the answer internally for your team as a response that should be further reviewed or noted as potential risks. This will not be shared with the vendor.

    • Note: by clicking the three dots, you will have the options of

      • Assign - assign this specific question to a team member you want to collaborate with

      • Copy Link - will redirect the recipient to this specific question

      • View question activity - will show you a log of all actions that have been taken with this question

AdditionalOptions.png

3. Submit Feedback

Once you've finished reviewing all of the questions, select the "Submit feedback" button on the top to send your saved feedback to the vendor.

SubmitFeedback.png

This will only share responses where you added feedback and will not share approved or flagged responses. This will also update the status of the Security Review to "In Remediation."

4. Security review ready for final review

After the vendor responds to your feedback, the Security Review will be ready for your final review. Complete a review of their responses and select the "Complete security review" button on the top.

CompleteSecurityReview.png

This will prompt you to log a Decision, Residual Risk Rating (optional), and Reason for Decision (optional). This information is for internal purposes only and will be saved to the vendor's page. The vendor will only be informed that the review is complete.

It is up to you or your team to inform them of your decision.

Did this answer your question?