Hello Everyone, our team is building out our Vendor Assessment function and I wanted to hear some hands-on experience with it. We are trying to understand what the vendors will receive when we kick off an assessment and when it's ready for us to review. Thanks! (More questions may follow but starting with the overall kick off and gathering details)
Hey Andrew K., happy to share a quick overview of what I've been doing. I've stood up my VRM program by leveraging multiple systems that are all connected. My workflow leverages some automation and consists of Jira > Vanta > Claude > GDrive + Asana I built my workflow around Jira as the intake and communication mechanism that captures the request from the business. That request then pushes to Vanta as a new procurement record. I use Vanta to upload the vendors security and compliance docs. From Vanta, I send out invites to the vendor point of contact to request any additional or missing evidence to assist with our review. While I do have Vanta AI enabled, I don't rely solely on it's output and keep a human-in-the-loop approach. I still require the vendor to respond to some of our questions and review it against the source material Vanta AI has found. Once the questionnaire is complete, I download the responses to combine it with our internal documentation for how the vendor will be used internally to draft up the risk assessment. Depending on your industry, use case, program maturity, I would actually consider using Vanta's intake feature that's already baked into the tool. Unfortunately, when I started building, it didn't exist.
Thanks for that walkthrough Andy S.. Looks like we have a similar approach to intake and also use Jira tagging to pull in vendors. A few follow-ups:
When you say “upload the vendor’s security and compliance docs”, are you separately obtaining materials from the vendor trust center for outside the assessment?
How do you populate the Vendor Point of Contact? Is that a manual lift or do you have integration with a contract management repository (possibly GDrive)?
It’s interesting you download the responses from Vanta and combine with internal documentation. Are you able to provide some further insight into this part of your workflow? Why would you want to pull this data out of Vanta?
No problem, Andrew. See responses below -
When you say “upload the vendor’s security and compliance docs”, are you separately obtaining materials from the vendor trust center for outside the assessment? I do a little of both - First, I include the "evidence" I'd like to receive as part of the assessment within Vanta. A few things occur here: 1) Not all vendors have trust centers and they typically require you to request access before you can obtain them. This becomes a manual step and I obtain them directly via Trust or email 2) Not all vendors provide all of the necessary documentation we're looking to see.
For our org, since we're in a regulated industry, there's some additional due diligence that is required.
How do you populate the Vendor Point of Contact? Is that a manual lift or do you have integration with a contract management repository (possibly GDrive)? This is definitely a limitation within Vanta - but I have a series of questions that exist in my Jira intake, one that includes a POC for the vendor that's being procured. This is a requirement I put on the business to collect. For those where no contract is done, contacting support becomes the alternate route or we work with what's available and place some additional controls internally.
It’s interesting you download the responses from Vanta and combine with internal documentation. Are you able to provide some further insight into this part of your workflow? Why would you want to pull this data out of Vanta? Vanta is capturing the general vendor info, but what I want is the actual business justification or use case for how the business intends to use the service. We care about how our data will be handled and how it intends to flow across the environment. Vanta doesn't capture the responses from the business (this is feature request I've already pushed for).
In my ideal state, I'd like to map Jira responses to custom fields in Vanta and/or allow for additional internal documentation to be uploaded to Vanta for the AI agent to build a solid profile of the vendor.
Hi Andrew, I can strongly recommend having a dummy test account to make sure you are getting all the notifications (and be aware, there may be many), or assess your own company 😉 . Plus, as a newbie, I have come to adding myself to every request for evidence that goes out per e-mail. So far, I tried to keep both my internal contacts plus any supplier contact in the distro-list. I dont usually like to spread e-mails to everybody, but in this scenario it has proven to be successful. Hope this helps!
