Supplier Assessments
Supplier Assessments let you send a structured security & privacy questionnaire to a supplier, collect their answers through a public link, and turn those answers into a risk read you can act on. You send the questionnaire; the supplier fills it in; you review the result.
Open Suppliers, choose a supplier, and use the Assessments section to get started.
Pick the right questionnaire up front
When you start an assessment you now choose a Template type. There are two fixed questionnaires, and the one you pick decides which questions the supplier sees:
| Template | For | Roughly |
|---|---|---|
| Technological supplier | Software, development, IT, managed services | ~49 questions |
| Non-technological supplier | Consulting, DPO, professional services | ~34 questions |
The two options appear as cards in the Start supplier assessment dialog, each with a short description and an approximate question count. autociso pre-selects the one it recommends for that supplier and shows a line such as “Recommended for this supplier: Technological”, but you can switch freely before you create the assessment.
This choice replaces the old Short / Full mode toggle, and the old automatic “what kind of vendor are you?” question inside the questionnaire is gone — you decide the template up front instead of asking the supplier.
Note: The template is frozen when the assessment is created. As the dialog states: “This choice sets the whole questionnaire and can’t be changed after the assessment is created.” If you picked the wrong one, start a new assessment.
Why two templates
A consultant, DPO, or other non-technical vendor should never be asked about penetration testing, SBOMs, backup regimes, or hardware tamper-proofing — controls that only make sense for a product or IT vendor. The Non-technological supplier template simply leaves those questions out, so a small non-tech supplier is scored only on what actually applies to them.
”Not applicable to our operating model”
On the Technological supplier template, some questions target controls that a large product vendor should have but a solo developer or micro-vendor genuinely cannot operate — for example independent penetration testing, a formal supply-chain program, or hardware tamper prevention.
On those eligible questions the supplier can pick Not applicable to our operating model instead of a normal answer. When they do, a required field appears — Why is this not applicable? — and they cannot submit until they write a short justification.
What this means for you as the reviewer:
- A justified N/A answer does not count against the score — it is excluded, not marked as a failure.
- Every N/A answer carries the supplier’s written reason, which you see when you review the assessment.
- Baseline controls that apply to everyone — multi-factor authentication, passwords, breach notification, privacy handling — are never eligible for N/A.
This keeps the score fair for small suppliers while keeping their opt-outs visible and auditable, so nobody can quietly mark everything “not applicable” to inflate their result.
Two results, never mixed up
When an assessment is scored you see two separate numbers, each with its own label and meaning. This is deliberate — they answer different questions.
Security & privacy score
Control maturity from the supplier’s answers. A 0–100 number derived purely from the questionnaire. It measures how mature the supplier’s security and privacy controls are, and nothing else. Justified N/A answers are excluded from it.
If every scored question was marked not applicable, there is no meaningful score and the card shows Not scored instead of a number.
Overall risk rating
Inherent risk × control gap. A single verdict — Low, Medium, High, or Critical — that combines the questionnaire result with the supplier’s business context: how critical they are to you, what data they can touch, their level of access, and the frameworks in scope for them.
The key insight this surfaces: a supplier can score well on the questionnaire yet still be High or Critical overall if they are business-critical or hold sensitive data. A mid questionnaire score for a supplier with deep access is not the same risk as the same score for a low-exposure vendor.
To see how a rating was reached, expand Why {rating}? on the score card. It shows the Inherent risk tier, the Control gap tier, and the resulting Overall risk — so the reasoning is transparent, not a black box.
Note: If a supplier’s risk profile is incomplete, the Overall risk rating is still calculated but the card notes it is based on incomplete data. Filling in the supplier’s risk profile gives a sharper rating.
The two results also appear as separate Score and Overall risk columns in the assessments list, so the distinction carries through everywhere.
Frameworks in scope
The score card lists the Frameworks in scope for the supplier (for example ISO 27001, SOC 2, HIPAA). These reflect the compliance frameworks that apply to the supplier and inform the Overall risk rating. If no frameworks are set, the row is hidden.
Roles and permissions
| Action | Member | Manager | Owner |
|---|---|---|---|
| View assessments and results | yes | yes | yes |
| Start an assessment / send a link | — | yes | yes |
| Review and record a decision | — | yes | yes |
The supplier who fills in the questionnaire does so through a public link and needs no autociso account.
Related pages
- Personal Data Dictionary — link the data types a supplier processes to the rest of your privacy records.
Was this page helpful?