Review vendor assurance packs by security, privacy and resilience

For: Third-party risk manager onboarding or re-assessing critical vendors

Pattern: Specialist panelNeeds live modelsDesigned for 8 to 300 agents

The pain today

Each vendor sends an assurance report, a questionnaire, policies and a penetration test summary. Reviewers confirm the documents exist, not whether the report's exceptions and carve-outs contradict the questionnaire answers.

The ask

I attached the assurance packs from our critical vendors and our own requirements for security, data protection, business continuity and subcontracting. For each vendor, tell me which requirements the evidence supports, where the vendor's answers conflict with its own reports, and what is missing.

Plain words, as you would say it to a colleague. Edit it to fit your case before you send it.

What you attach or connect

  • Independent assurance reports with exceptions and scope
  • Completed vendor questionnaires
  • Vendor policies and continuity test results
  • Penetration test summaries
  • Our vendor requirements per risk domain

The unit of work

One worker task per one vendor pack section under one reviewer brief.

Why a swarm fits

Vendors are independent and each pack is read against separate domain checklists. The telling finding is often a conflict between two documents in the same pack, which a scoped reader per domain brings out.

Not for

Low-risk vendors cleared by a short questionnaire: a checklist review is proportionate and cheaper.

The decision tree

5 typed decisions, each with an action for every answer

At fixed moments in a run, the engine puts one narrow question to a decision model. The decision model never writes text: it answers yes or no with a probability, picks from listed options, or gives a score, about a small slice of the material. The engine then does exactly what this tree says, which is what makes the run auditable. The thresholds are the template's design values, not measured results.

  1. Planner, while planning

    Scope checkYes or no, with a probability

    Before work starts on a unit

    Does the assurance report's scope cover the service we buy and a period overlapping our contract term?

    Sees only: The report's scope section and our service description

    Why: A report on another service line is no evidence at all.

    • Yes: 0.70 or higherthenAccept
    • Unsure: 0.40 up to 0.70thenMark unresolved
    • No: below 0.40thenMark unresolved
  2. Before workers, before a task runs

    Small worker or strong modelYes or no, with a probability

    Before a task runs

    Does this section contain auditor exceptions, a qualified opinion or carved-out subservice providers?

    Sees only: One report section

    Why: Clean sections stay with small workers; exceptions get careful reading.

    • Yes: 0.50 or higherthenEscalate to a strong model
    • Unsure: 0.30 up to 0.50thenEscalate to a strong model
    • No: below 0.30thenAccept
  3. After workers, the judge checks

    Evidence checkYes or no, with a probability

    After a worker answers

    Does the cited report section show the control was tested and operated, as opposed to a policy stating that it should?

    Sees only: The requirement and the quoted report or policy passage

    Why: A policy document alone is not evidence that a control works.

    • Yes: 0.85 or higherthenAccept
    • Unsure: 0.50 up to 0.85thenEscalate to a strong model
    • No: below 0.50thenReject and retry
  4. Reconciler, while merging

    Conflict checkA choice among options

    While reconciling

    How does the vendor's questionnaire answer compare with its own report on the same topic?

    Sees only: One questionnaire answer and the report passage on that topic

    Why: The telling finding is a vendor contradicting its own auditor.

    • Answer and report agreethenAccept
    • Answer says yes, report records an exceptionthenMark unresolved
    • Report is silent on the topicthenMark unresolved
  5. Accountable person, before anything is settled

    Person decidesYes or no, with a probability

    Before anything is reported as settled

    Would this finding leave a requirement for a critical vendor unmet at onboarding or renewal?

    Sees only: The finding, the requirement and the vendor's criticality

    Why: The risk manager and business owner accept or refuse residual risk.

    Accountable: The risk manager and business owner decide whether to onboard, require remediation or accept the residual risk.

    • Yes: 0.40 or higherthenAsk a person
    • Unsure: 0.15 up to 0.40thenAsk a person
    • No: below 0.15thenAccept

The fleet: who does what

Model tiers by role, not brands: you choose the models. Strong reasoning models plan and reconcile, small fast models do the wide work, and the judge is a decision model from a different family, so it does not share the workers' blind spots.

  1. Planner

    A strong reasoning model maps each requirement to the pack documents that could evidence it and to the owning brief.

    Decisions here:1. Scope check

  2. Workers

    Small fast workers, each with one brief (security, privacy, resilience, subcontracting), test one pack section.

    Designed for 8 to 300 agents, one worker task per one vendor pack section under one reviewer brief. Each worker receives only its own unit.

    Decisions here:2. Small worker or strong model

  3. Judge, from a different model family

    A decision model from a different family checks that cited evidence covers the service we buy and the period in question.

    Decisions here:3. Evidence check

  4. Reconciler

    A strong reasoning model joins the briefs per vendor and lists conflicts between questionnaire answers and report findings.

    Decisions here:4. Conflict check

  5. Accountable person

    The risk manager and business owner decide whether to onboard, require remediation or accept the residual risk.

    Decisions here:5. Person decides

Checked before anything is accepted

  • Report scope, period and carved-out subservice providers are checked against the service in use
  • Each questionnaire answer is compared with report exceptions on the same topic
  • A policy document alone is not accepted as evidence that a control operates
  • Requirements with no evidence are listed as open, not as met

What comes back

  • Requirement coverage per vendor and risk domain, with evidence
  • Conflicts between a vendor's answers and its own reports
  • Report exceptions and scope gaps relevant to our service
  • Follow-up questions per vendor

What to measure

  • Findings a risk analyst confirms
  • Conflicts found that the manual review had missed
  • Analyst hours per vendor assessment

Names of measures only. No result is claimed for this template.

Templates open in the workspace chat with the ask filled in. Nothing runs until you send it.

Get early accessSign in to use

Map a new regulation to policies and controls, rule by rule

For: Head of compliance or regulatory change manager implementing a new rule

A new regulation arrives with obligations buried in articles, annexes and guidance.

Pattern: Hierarchical decompositionNeeds live models6 decisionsDesigned for 8 to 400 agents

Test control evidence samples against the control description

For: Internal control manager or second-line tester running the annual control testing cycle

Every key control needs sampled evidence checked: was the approval there, by the right person, before the event, for the right amount.

Pattern: Map, verify, reduceNeeds scale6 decisionsDesigned for 20 to 800 agents