Vendor security posture watch between assessments
For: Third-party risk analyst or security lead responsible for supplier assurance
The pain today
Vendors are assessed once a year from a questionnaire. In between, their subprocessor lists, security pages and breach notices change, and nobody rereads them.
The ask
“Watch the public security, trust, status and subprocessor pages of the vendors on my attached list, and compare them with what the vendors told us in the attached questionnaires. Tell me when a change contradicts an answer or our requirements, with both passages quoted.”
Plain words, as you would say it to a colleague. Edit it to fit your case before you send it.
What you attach or connect
- Vendor list with criticality
- Completed security questionnaires and contract security clauses
- Public trust, status and subprocessor pages
- Our vendor security requirements
The unit of work
One worker task per one vendor page against that vendor's answers.
Why a swarm fits
Vendors are independent, and so are their pages. When one page changes, only the answers that depended on it need re-reading.
Not for
A deep assessment of one critical vendor: that needs their audit reports and a conversation.
The decision tree
5 typed decisions, each with an action for every answer
At fixed moments in a run, the engine puts one narrow question to a decision model. The decision model never writes text: it answers yes or no with a probability, picks from listed options, or gives a score, about a small slice of the material. The engine then does exactly what this tree says, which is what makes the run auditable. The thresholds are the template's design values, not measured results.
Run control, between rounds
Another round?A choice among options
Between rounds
Compared with the last capture, is this vendor page unchanged, changed, or unavailable?
Sees only: The previous and current capture of one vendor page
Why: Unchanged pages cost nothing further, and a failed fetch is never read as no change.
- Fetched and unchangedthenStop
- Fetched and changedthenContinue
- Could not be fetchedthenMark unresolved
Planner, while planning
Scope checkYes or no, with a probability
Before work starts on a unit
Is the difference between the two captures a change of substance, such as a new subprocessor, a removed certification or new incident text, rather than layout or wording polish?
Sees only: The changed passages from the two captures
Why: Cosmetic edits are logged and dropped before any answer is re-read.
- Yes: 0.55 or higherthenAccept
- Unsure: 0.25 up to 0.55thenAccept
- No: below 0.25thenSkip this unit
Scope checkYes or no, with a probability
Before work starts on a unit
Does this questionnaire answer depend on what the changed passage states?
Sees only: One questionnaire answer and the changed passage
Why: Only the answers that depended on the page are redone.
- Yes: 0.60 or higherthenAccept
- Unsure: 0.25 up to 0.60thenAccept
- No: below 0.25thenSkip this unit
After workers, the judge checks
Evidence checkA choice among options
After a worker answers
Does the new page text contradict the vendor's quoted questionnaire answer or contract clause?
Sees only: The old text, the new text and the quoted answer or clause
Why: An alert a risk analyst cannot verify in one glance will be ignored next time.
- Contradicts itthenAccept
- Consistent with itthenSkip this unit
- Wording is ambiguousthenMark unresolved
- Page no longer addresses the topicthenMark unresolved
Accountable person, before anything is settled
Person decidesYes or no, with a probability
Before anything is reported as settled
Does this change concern a vendor marked critical, or the location, subprocessors or breach status of data we send them?
Sees only: One verified change and the vendor's criticality row
Why: Whether to reassess, invoke the contract or do nothing is the risk owner's decision.
Accountable: The risk owner decides whether a change triggers a reassessment, a contract step or nothing.
- Yes: 0.35 or higherthenAsk a person
- Unsure: 0.10 up to 0.35thenAsk a person
- No: below 0.10thenAccept
The fleet: who does what
Model tiers by role, not brands: you choose the models. Strong reasoning models plan and reconcile, small fast models do the wide work, and the judge is a decision model from a different family, so it does not share the workers' blind spots.
Planner
A strong reasoning model links each questionnaire answer to the public pages that could confirm or contradict it.
Decisions here:2. Scope check3. Scope check
Workers
Small fast workers from an open-weight family each re-read one changed page and extract what differs.
Designed for 10 to 300 agents, one worker task per one vendor page against that vendor's answers. Each worker receives only its own unit.
Judge, from a different model family
A decision model from a different family checks the change truly contradicts the quoted answer or clause.
Decisions here:4. Evidence check
Reconciler
A strong reasoning model orders changes by vendor criticality and keeps ambiguous wording as open questions.
Decisions here:1. Another round?
Accountable person
The risk owner decides whether a change triggers a reassessment, a contract step or nothing.
Decisions here:5. Person decides
Checked before anything is accepted
- Each alert quotes the old text, the new text and the affected answer
- Cosmetic page changes are logged but not alerted
- Pages that could not be fetched are reported, not assumed unchanged
What comes back
- Change alerts with before, after and the contradicted answer
- Questions to send the vendor
- Record of what was re-checked and why
- Vendors with no public evidence to watch
What to measure
- Alerts that led to a vendor question
- Material changes learned elsewhere first
- Analyst hours per vendor
- Cost per re-check
Names of measures only. No result is claimed for this template.
Templates open in the workspace chat with the ask filled in. Nothing runs until you send it.
Get early accessSign in to useMore in Security and IT operations
A night of alerts triaged into incidents with evidence
For: Security operations lead or on-call analyst starting the morning shift
Overnight the queue fills with alerts, most of them duplicates or noise.
Root-cause hypotheses tested against log windows
For: Site reliability engineer or incident commander writing the review after an outage
After an outage the first plausible story wins.
Threat model attacked before the design is built
For: Security architect or product security engineer reviewing a new system design
Threat models are written by the people who designed the system, so they list the threats the design already handles.