Skip to main content

Vendor Security Review

Conduct AI-powered vendor security assessments by uploading vendor documentation and evaluating it against your configured security requirements.

Overview

The Vendor Security Review feature allows your organization to:

  • Upload SOC 2 reports, penetration test results, and other vendor security documents
  • Evaluate uploaded documentation against your configured vendor security requirements
  • Receive an AI-generated overall summary, per-requirement findings, and a recommendation
  • Send follow-up questions to vendors and re-analyze based on their responses
  • Track vendor approval status through a full lifecycle

Vendor Lifecycle Statuses

StatusDescription
Pending AnalysisDocuments uploaded; AI analysis in progress
PendingAnalysis complete; questions may be outstanding
Pending ResponseQuestions sent; awaiting vendor answers
ApprovedVendor meets your security requirements
DeniedVendor does not meet requirements
Conditionally ApprovedVendor meets requirements with conditions
No Longer in UseVendor relationship ended

Starting a Vendor Review

  1. Navigate to Vendors in the main menu
  2. Click Add Vendor and enter the vendor name and details
  3. Open the vendor and click Start New Review
  4. Set the data sensitivity level for this engagement
  5. Upload one or more vendor security documents (PDF, DOCX, TXT, etc.)
  6. Click Start Analysis — the AI begins evaluating the documents against your requirements

Analysis typically takes 1–3 minutes depending on document size.


Reading Review Results

After analysis completes, the review page shows:

Recommendation Banner

The top of the page displays the overall AI recommendation:

  • Approve — All deal-breaker requirements are met
  • Conditionally Approve — Most requirements met with minor gaps
  • Pending Further Information — More documentation or vendor answers needed
  • Deny — Critical requirements are not met

The banner also shows the AI's rationale, formatted with Markdown for clarity.

Findings

Each configured vendor security requirement is assessed individually with a status:

  • Meets — Requirement is satisfied by the uploaded documents
  • Does Not Meet — Requirement is not satisfied
  • Partially Meets — Evidence is incomplete or conditional
  • Pending Vendor Response — Needs a direct answer from the vendor
  • Fails Requirement - Risk Accepted — Requirement is not met, but the risk has been formally accepted (human-only; the AI never sets this status)

Each finding links to the source document citation that supports the conclusion.

Editing Finding Status

Any authenticated org member can manually override the status of any finding directly in the UI:

  1. Open the vendor review page and scroll to the Findings card
  2. Click the status dropdown in the Status column for any finding
  3. Select the desired status — the change saves automatically
  4. A brief "Saved" indicator confirms the update

The "Fails Requirement - Risk Accepted" option is available to all members and is never set by the AI. Use it when your organization decides to proceed despite a known gap.

AI Summary

A markdown-formatted overall summary of the vendor's security posture based on all uploaded documents.


Document Downloads

All documents uploaded for a review are listed in the Documents card. Click Download next to any document to open a time-limited secure link to the file.

Cited document names in the Findings section are also clickable. Supported PDF, DOCX, and TXT citations open as PDF in the inline viewer, which searches for the cited excerpt. Use Download original in the viewer if you need the source file outside the browser.


Deleted Source Documents

If your organization enabled Delete source documents after initial analysis before this review was created, the files remain available until the initial results and questions have been saved. The Documents card then reports the source lifecycle truthfully as Deletion pending, Deletion retry pending, or Deleted after analysis. Deleted or pending documents cannot be downloaded, and their citations remain visible as evidence metadata without a source-file link.

Deletion retries are bounded. If the storage provider still cannot confirm deletion after 12 attempts, the document changes to Unavailable and automatic retries stop. Contact your RepoRisk administrator so the bucket permissions, Object Lock retention, or MFA Delete configuration can be checked; Unavailable does not claim that every stored version was deleted.

warning

Source deletion is permanent. Follow-up processing uses the saved findings, questions, responses, organization context, and summary without re-reading the original documents, so follow-up question and response-analysis quality may be degraded.

See Vendor Review Document Retention for administrator setup and prospective-scope details.


Follow-Up Questions

If the AI determines that additional information is needed, it generates follow-up questions for the vendor.

Copying and Sending Questions

In the Questions card:

  1. Click Copy All Questions to copy the full list to your clipboard, formatted as a numbered list ready to paste into an email
  2. After sending, click Mark All as Sent to update the question status

Recording Vendor Responses

Each question row has a two-column layout:

  • Left column: The question text
  • Right column: A text area to record the vendor's response

Each response field auto-saves as you type. Changes are saved automatically after a short pause; a brief "Saved" indicator confirms the update. No manual Save button click is required, though a Save button is still available if you prefer.

Submitting for Re-Analysis

Once responses are recorded:

  1. Click Submit All Responses in the questions card
  2. The AI re-evaluates the relevant requirements based on the recorded answers
  3. A new review round is created with updated findings

For reviews whose source documents were deleted after initial analysis, re-analysis is based only on retained review context and the recorded vendor responses. The review page displays a warning when this applies.

warning

If any response failed to save (shown in red), submission is blocked until those fields are successfully saved. Retry by clicking the Save button on the failed field again.


Audit Log

Every change to a vendor review — including finding status updates, question text edits, and vendor response edits — is captured in the Audit Log displayed at the bottom of the review page.

What the Audit Log Shows

ColumnDescription
TimestampWhen the change was made
ActorWho or what made the change: a specific user name, or "AI" for AI-generated changes
FieldWhich field was changed (status, question_text, or vendor_response)
Old ValueThe value before the change
New ValueThe value after the change

Who Can See the Audit Log

All authenticated members of your organization can view the audit log. Admin access is not required to read it.


Vendor AI Instructions

You can provide organization-specific context to guide AI analysis for all vendor reviews. This is configured in SettingsVendor AI Instructions.

Examples of useful context:

  • Your organization's risk tolerance or compliance framework (SOC 2, ISO 27001, HIPAA)
  • Vendor categories that require stricter scrutiny
  • Specific clauses or certifications your procurement policy requires

See Organization Settings for configuration steps.


Vendor Security Requirements

The AI evaluates documents against requirements you configure in SettingsVendor Security Requirements. Each requirement has a severity level:

  • Deal Breaker — Must be met for approval
  • Highly Desired — Important but not blocking
  • Preferred — Nice to have
  • Optional — Informational only

See Organization Settings for how to add, edit, and import requirements.


Troubleshooting

Analysis Stuck at "Analysis in Progress"

If the review stays at "Analysis in progress" for more than 5 minutes:

  1. Check that your Anthropic API key is configured in Settings (BYOK or platform key)
  2. Contact Support if the issue persists

All Documents Failed Extraction

If you see "All documents failed text extraction":

  1. Ensure documents are not encrypted or password-protected
  2. Try re-uploading the document in a different format (e.g., PDF → DOCX)
  3. Check that the document contains selectable text (not a scanned image without OCR)

Auto-Save Failed

If a "Save failed" indicator appears on a response field or status dropdown:

  1. Check your network connection
  2. Make another edit to the field to trigger a retry, or click the Save button if visible
  3. The indicator will clear once the save succeeds

Inline PDF Viewer Failed

If a cited document cannot be displayed inline, click Download original in the viewer. Confirm that the downloaded source file opens normally, then contact Support if inline viewing continues to fail.