Scenario: onboarding and assessing a new vendor

Follow one person, end to end, as she adds a new cloud provider to the register, sends it a security questionnaire, runs an AI investigation, turns a finding into a tracked risk, and links the proof an auditor will ask for.

Third-party risk — the chance that a supplier's weakness becomes yours — is a named requirement in ISO 27001 (an information-security standard), NIS2 (a European cybersecurity law) and DORA (a European financial-sector resilience law). This chapter is one journey across four modules: Vendors, Questionnaires, Risks and Evidence. It follows Aisha, a Contributor, as she onboards a provider called "DataNest" — from a blank row to a finding she can defend in an audit. Each module's own chapter carries the full detail; this one shows the order the work happens in.

Who can do this

The whole journey is within reach of a Contributor: adding vendors, sending questionnaires, running the AI investigation, raising risks and linking evidence. A Viewer can read the register and open a vendor's detail page, but the Add Vendor button is not rendered for them, and the three row action icons are replaced by a single view-details icon. Deleting a vendor — including the bulk Delete — is reserved for a Manager or Admin, and so is unlinking evidence from a vendor. Changing status in bulk needs update rights, which a Contributor has. The full matrix is in What each role can do.

What's on this screen

The journey starts at /vendors, reached from the RISKS group in the left sidebar. Two buttons sit above the page title on the right: Import and the blue Smart Triage (AI). Below them the heading reads Vendor Management with the subtitle "Track and assess third-party vendors.", and the dark Add Vendor button sits on the right, level with that heading. Next comes the filter bar — a Search vendors… box with its own Search button, then two dropdowns, All Statuses and All Criticalities.

The table beneath has a select checkbox on every row, then the columns Name, Criticality, Data Classification, Rating, Last Assessment, Next Review, Status, Owner and Actions. The suppliers in the capture are real names, several of them with regional variants — 15Five and 15Five (APAC), Accenture and Accenture (EMEA), Adobe Sign and Adobe Sign (Americas), ADP — at Low, Medium and High criticality. Ratings run from a green 92/100 down to red single-figure scores, and a supplier nobody has assessed shows a dash under both Rating and Last Assessment, with Not scheduled in grey italics under Next Review. Status is a badge — green Active or grey Inactive in this capture — and Owner names the person who holds the relationship. Each row ends with three icons under Actions: a lightbulb (AI investigation), a document (send questionnaire) and a box (archive).

Ticking row checkboxes reveals a bulk bar, and what it offers depends on your rights: each action is hidden from anyone without the matching permission. A Contributor such as Aisha sees only Change Status; Delete and Export need delete and export rights respectively and do not appear for her at all. Below the part the screenshot shows, the page continues with a portfolio report card, a concentration-risk map, and panels for saved AI briefings and action items.

Stage 1 — Get your bearings on the register

Before adding anything, Aisha takes stock of what is already there. These six controls are the ones she returns to throughout the journey.

  1. Bring in an existing list with Import. The Import vendors dialog opens: download the template, fill it in, upload it, and select Validate before committing. A summary reports how many rows are valid and how many carry errors; only clean rows are created.
  2. Ask for a ranked starting point with Smart Triage (AI). The Vendor Portfolio Smart Triage panel opens; selecting Run Smart Triage streams a briefing on the active vendors most in need of reassessment. Aegis computes the order — criticality, overdue review, never assessed, then rating — and the AI narrates it rather than inventing one. It reads your active vendors only and changes nothing.
  3. Start the new record with Add Vendor. The Add New Vendor dialog opens over the table. This is where Stage 2 begins.
  4. Find a row with the search box. Type part of a name into Search vendors… and select Search; the table reloads filtered to matching names. The two dropdowns beside it narrow the list by status and by criticality.
  5. Open a supplier by selecting its name. The name is a link to that vendor's detail page, which holds the rating panel, the assessment history, linked risks and linked evidence.
  6. Use the row action icons for assessment work. The lightbulb starts an AI investigation of that supplier, the document icon opens the questionnaire dialog, and the box archives the vendor after a confirmation. All three appear for a Contributor and above.
The vendor register: Import and Smart Triage (AI) above the title, Add Vendor on the header line, the search and filter bar, and one row per supplier ending in three action icons — /vendors.
The vendor register: Import and Smart Triage (AI) above the title, Add Vendor on the header line, the search and filter bar, and one row per supplier ending in three action icons — /vendors.

Stage 2 — Add DataNest to the register

  1. Open the create dialog. Aisha selects Add Vendor. The Add New Vendor dialog opens with three required fields and an optional company details section.
  2. Fill in the three required fields. She types "DataNest" into Vendor Name, sets Criticality to High because the provider will hold sensitive data, and sets Data Classification to Restricted. Both dropdowns carry a line of help text underneath — "How critical is this vendor to your operations?" and "What level of data does this vendor have access to?" — and both default to the lowest tier until you change them.
  3. Add the company details you have. The optional Company details section takes master data — registration number, category, address, country, phone, currency, Annual spend — plus an In scope for supplier assessment checkbox. Anything left blank can be filled in later from the vendor's detail page.
  4. Save. She selects Add Vendor in the dialog footer. The dialog closes, the table refreshes, and DataNest appears with a dash under Rating and Not scheduled under Next Review.

The two tiering fields she set in step 2 are the ones the rest of the journey keys off:

Field Values What it drives
Criticality Low, Medium, High, Critical Triage order, the default review interval when you schedule one, and how heavily the risk score weights this supplier
Data Classification None, Internal, Confidential, Restricted Which questionnaire is appropriate, and whether GDPR obligations such as a data processing agreement apply
Status Active, Inactive Whether the vendor is counted in the portfolio metrics and considered by Smart Triage
A new vendor starts unassessed, and that is visible to everyone

Aegis does not invent a score for a new supplier. Until an assessment exists the register shows a dash, and Smart Triage ranks the vendor high precisely because it has never been assessed. Next Review fills in once a review is scheduled from the detail page; when that date passes, the cell turns red and gains an (Overdue) marker.

Stage 3 — Send a security questionnaire

  1. Open the questionnaire dialog. On DataNest's row, Aisha selects the document icon under Actions. Send Assessment Questionnaire opens, with "Sending to:" and the vendor's name at the top.
  2. Choose a template. Four are built in: Basic Security Assessment, Comprehensive Security Review, GDPR Data Processing and SOC 2 Readiness. Each shows a one-line description; for a High-criticality provider she picks the comprehensive review.
  3. Add the recipient and a note. She types DataNest's contact address into Recipient Email — the address is format-checked, and a malformed one is rejected — and adds a line under Custom Message (Optional) explaining the deadline.
  4. Send it. She selects Send Questionnaire. Aegis records a placeholder assessment against DataNest, queues the email to the address entered, and recalculates the vendor's risk score. "Questionnaire sent successfully!" appears and the dialog closes after a moment.
Returned answers have to be filed by hand

Sending is automated; receiving is not. When the supplier replies, nothing files itself against the vendor row — record what came back as evidence linked to the vendor (Stage 6), as a risk (Stage 5), or both. The separate Questionnaires module, where licensed and syncing from a connected source, tracks questionnaires in their own right; it is not populated by this row action.

Stage 4 — Run the AI investigation

  1. Start it from the row. Aisha selects the lightbulb icon. AI Vendor Investigation opens with the vendor's name as its subtitle and lists what it will analyse: risk factors from criticality and data classification, compliance gaps across GDPR, NIS2 and security standards, data processing agreement status, assessment history and trend, and recommendations.
  2. Select Start Investigation and wait. The panel narrates six steps while it searches external sources for breach history, certifications and security incidents, then combines those with DataNest's internal record. It usually takes 30 to 90 seconds.
  3. Read it, then decide what to keep. Nothing is written to the vendor on the AI's own authority. The finished report offers Copy, Export to DOCX or PDF, Save as record against this vendor, Create action item, and a run-again option. Aisha saves the report to DataNest and raises an action item for the one thing that needs chasing.

Between the questionnaire and the investigation, a real gap surfaces: DataNest cannot show that it tests its backups. That finding is what becomes a tracked risk next.

Stage 5 — Turn the finding into a tracked risk

  1. Create the risk. Aisha opens Risks and selects New risk (guided), the wizard that walks the whole record in one pass — from a methodology template through describing, scoring and treating the risk to a final review step. (The quicker Add Risk dialog on the table records the same title, description, category, impact and likelihood, but skips the template, the appetite check and the treatment sign-off.) She describes the exposure — "DataNest cannot evidence backup testing" — and chooses a category.
  2. Score it. She picks a likelihood level, then an impact level for each dimension her methodology defines; Aegis aggregates those into one overall impact. The score step then shows the inherent score and its band, marks that cell on the methodology matrix, and says whether the risk sits within or above the appetite set for its category. How the score is derived depends on the methodology — either likelihood multiplied by impact, or a value read from the matrix.
  3. Treat it, then set the review date. The treatment step records how she plans to handle the exposure, and asks for a sign-off tick where the score band demands one. The final step takes a next-review date. There is no owner field in the wizard: the risk is owned by whoever creates it, and reassigning it happens afterwards on the risk's own page. The supplier weakness is now a managed item with an owner and a date against it.
The vendor's Linked Risks panel cannot be filled from the risk screens

A vendor's detail page has a Linked Risks panel, and it reads the vendor field on the risk record. No form in the Risks module writes that field today, so a risk you raise in the interface will not appear there — the panel keeps reading "No risks are attributed to this vendor yet." What the risk screens do offer is the governance-links panel on a risk's detail view, which can link that risk to a vendor, a control or an evidence item — a separate link, held separately, and not the one the vendor panel reads. Until the two meet, keep the connection legible in the risk's own description and in the evidence you link in Stage 6.

Stage 6 — Link the evidence for the audit trail

  1. Open the vendor's detail page. Aisha selects DataNest's name. The page opens with a breadcrumb back to the register, the vendor's name and status badge, then the current rating panel and, in the side column, details, statistics and dates. Assessments, evidence and Linked Risks follow below.
  2. Link the proof. In the evidence panel she selects + Link Evidence, searches the Evidence library for the questionnaire result and DataNest's security certificate, and attaches both. Only evidence not already tied to a vendor appears in that search. Bulk Import beside it takes several records at once. Removing a link again needs Manager rights or above, so the unlink icon is not shown to Aisha.
  3. Set the review cadence. From the header she selects Schedule review. The Schedule vendor review dialog asks for a Review interval (days); leaving it empty derives the interval from the vendor's criticality. Confirming fills Next Review on the register. Download report beside it streams a PDF due-diligence report — profile, risk, data flows, security standards, agreements and linked evidence in one document.

With that, most of the chain is on the page for an auditor to follow: the vendor, its assessments, the evidence behind the due diligence you carried out, and the audit-log entries for each step. The risk is the one hop you still have to point to by hand, for the reason given above.

The AI assist

AI appears at three points in this journey and decides nothing at any of them. Smart Triage (AI) narrates a ranking Aegis computed itself, over your active vendors only. The investigation searches public sources and reads the internal record, then hands you a report you choose to keep, export or discard. Where AI drafts questionnaire answers, it attaches a confidence score and waits for a person to accept or reject each one. Every run is metered against your tenant's AI credits.

Tips and limits

Where this connects

Each module here has its own chapter: Vendors, Questionnaires, Risks and Evidence. Action items raised from an AI report are tracked in Action items, and every create, archive and send is written to the Audit log. For who may do what, see What each role can do; for the audit that draws on the evidence linked in Stage 6, see Scenario: preparing for an external audit.