Review vendor assurance packs by security, privacy and resilience
For: Third-party risk manager onboarding or re-assessing critical vendors
The pain today
Each vendor sends an assurance report, a questionnaire, policies and a penetration test summary. Reviewers confirm the documents exist, not whether the report's exceptions and carve-outs contradict the questionnaire answers.
The ask
“I attached the assurance packs from our critical vendors and our own requirements for security, data protection, business continuity and subcontracting. For each vendor, tell me which requirements the evidence supports, where the vendor's answers conflict with its own reports, and what is missing.”
Plain words, as you would say it to a colleague. Edit it to fit your case before you send it.
What you attach or connect
- Independent assurance reports with exceptions and scope
- Completed vendor questionnaires
- Vendor policies and continuity test results
- Penetration test summaries
- Our vendor requirements per risk domain
The unit of work
One worker task per one vendor pack section under one reviewer brief.
Why a swarm fits
Vendors are independent and each pack is read against separate domain checklists. The telling finding is often a conflict between two documents in the same pack, which a scoped reader per domain brings out.
Not for
Low-risk vendors cleared by a short questionnaire: a checklist review is proportionate and cheaper.
The decision tree
5 typed decisions, each with an action for every answer
At fixed moments in a run, the engine puts one narrow question to a decision model. The decision model never writes text: it answers yes or no with a probability, picks from listed options, or gives a score, about a small slice of the material. The engine then does exactly what this tree says, which is what makes the run auditable. The thresholds are the template's design values, not measured results.
Planner, while planning
Scope checkYes or no, with a probability
Before work starts on a unit
Does the assurance report's scope cover the service we buy and a period overlapping our contract term?
Sees only: The report's scope section and our service description
Why: A report on another service line is no evidence at all.
- Yes: 0.70 or higherthenAccept
- Unsure: 0.40 up to 0.70thenMark unresolved
- No: below 0.40thenMark unresolved
Before workers, before a task runs
Small worker or strong modelYes or no, with a probability
Before a task runs
Does this section contain auditor exceptions, a qualified opinion or carved-out subservice providers?
Sees only: One report section
Why: Clean sections stay with small workers; exceptions get careful reading.
- Yes: 0.50 or higherthenEscalate to a strong model
- Unsure: 0.30 up to 0.50thenEscalate to a strong model
- No: below 0.30thenAccept
After workers, the judge checks
Evidence checkYes or no, with a probability
After a worker answers
Does the cited report section show the control was tested and operated, as opposed to a policy stating that it should?
Sees only: The requirement and the quoted report or policy passage
Why: A policy document alone is not evidence that a control works.
- Yes: 0.85 or higherthenAccept
- Unsure: 0.50 up to 0.85thenEscalate to a strong model
- No: below 0.50thenReject and retry
Reconciler, while merging
Conflict checkA choice among options
While reconciling
How does the vendor's questionnaire answer compare with its own report on the same topic?
Sees only: One questionnaire answer and the report passage on that topic
Why: The telling finding is a vendor contradicting its own auditor.
- Answer and report agreethenAccept
- Answer says yes, report records an exceptionthenMark unresolved
- Report is silent on the topicthenMark unresolved
Accountable person, before anything is settled
Person decidesYes or no, with a probability
Before anything is reported as settled
Would this finding leave a requirement for a critical vendor unmet at onboarding or renewal?
Sees only: The finding, the requirement and the vendor's criticality
Why: The risk manager and business owner accept or refuse residual risk.
Accountable: The risk manager and business owner decide whether to onboard, require remediation or accept the residual risk.
- Yes: 0.40 or higherthenAsk a person
- Unsure: 0.15 up to 0.40thenAsk a person
- No: below 0.15thenAccept
The fleet: who does what
Model tiers by role, not brands: you choose the models. Strong reasoning models plan and reconcile, small fast models do the wide work, and the judge is a decision model from a different family, so it does not share the workers' blind spots.
Planner
A strong reasoning model maps each requirement to the pack documents that could evidence it and to the owning brief.
Decisions here:1. Scope check
Workers
Small fast workers, each with one brief (security, privacy, resilience, subcontracting), test one pack section.
Designed for 8 to 300 agents, one worker task per one vendor pack section under one reviewer brief. Each worker receives only its own unit.
Decisions here:2. Small worker or strong model
Judge, from a different model family
A decision model from a different family checks that cited evidence covers the service we buy and the period in question.
Decisions here:3. Evidence check
Reconciler
A strong reasoning model joins the briefs per vendor and lists conflicts between questionnaire answers and report findings.
Decisions here:4. Conflict check
Accountable person
The risk manager and business owner decide whether to onboard, require remediation or accept the residual risk.
Decisions here:5. Person decides
Checked before anything is accepted
- Report scope, period and carved-out subservice providers are checked against the service in use
- Each questionnaire answer is compared with report exceptions on the same topic
- A policy document alone is not accepted as evidence that a control operates
- Requirements with no evidence are listed as open, not as met
What comes back
- Requirement coverage per vendor and risk domain, with evidence
- Conflicts between a vendor's answers and its own reports
- Report exceptions and scope gaps relevant to our service
- Follow-up questions per vendor
What to measure
- Findings a risk analyst confirms
- Conflicts found that the manual review had missed
- Analyst hours per vendor assessment
Names of measures only. No result is claimed for this template.
Templates open in the workspace chat with the ask filled in. Nothing runs until you send it.
Get early accessSign in to useMore in Compliance and risk
Re-screen counterparties when sanctions lists or ownership change
For: Sanctions or financial crime compliance officer at a trading, shipping or manufacturing group
Screening happens at onboarding and then goes stale.
Map a new regulation to policies and controls, rule by rule
For: Head of compliance or regulatory change manager implementing a new rule
A new regulation arrives with obligations buried in articles, annexes and guidance.
Test control evidence samples against the control description
For: Internal control manager or second-line tester running the annual control testing cycle
Every key control needs sampled evidence checked: was the approval there, by the right person, before the event, for the right amount.