assess.one – AI-powered business operations platform

Workflow Template

Supplier Risk Assessment Workflow

Captures a supplier risk assessment request, triages inherent risk with AI, runs due diligence, adds a security/privacy review when sensitive data or critical systems are accessed, has a reviewer record the risk treatment plan, gates residual risk acceptance through formal approval, sets a reassessment date, and notifies the requester of the outcome.

Every new supplier or software vendor request seems to trigger the same scramble — someone chases down risk questions, security has to weigh in on data access, and approval sits in someone's inbox for weeks. This workflow captures the request, uses AI to triage inherent risk, runs due diligence, automatically pulls in a security/privacy review when sensitive data or critical systems are involved, and routes the treatment plan through formal approval before setting a reassessment date. Your team gets a consistent, auditable process instead of a patchwork of emails and spreadsheets — and the requester is notified automatically once a decision is made.

Business Outcomes

  • Cut supplier risk assessment turnaround from weeks to days
  • 100% of high-risk suppliers routed through security/privacy review automatically
  • Full audit trail of risk tier, due diligence, and approval decisions
  • Zero missed reassessment dates with automatic scheduling by risk tier
  • Fewer back-and-forth emails chasing approvals or missing information

Workflow Steps

Steps

  1. 1
    Create Supplier Assessment Recordcreate record

    Registers the assessment request as a record.

  2. 2
    Set Status to Submittedupdate record

    Marks the assessment as submitted.

  3. 3
    AI Inherent Risk Triageai prioritisation

    AI assesses inherent risk based on criticality, data/system access, and locations.

  4. 4
    Route on AI Triage Confidence

    Sends low-confidence triage to human review, otherwise persists the AI-derived risk tier.

    _ai_priority_ai_inherent_risk_triage_needs_human_review: "true"Manual Inherent Risk Review
    DefaultPersist AI-Derived Risk Tier
  5. 5
    Manual Inherent Risk Reviewcreate task

    Risk analyst manually determines the inherent risk tier when AI confidence is low.

  6. 6
    Persist Manually Set Risk Tierupdate record

    Writes the analyst's manually chosen risk tier to the record.

  7. 7
    Persist AI-Derived Risk Tierupdate record

    Writes the AI-derived inherent risk tier to the record.

  8. 8
    Conduct Due Diligencecreate task

    Risk analyst performs due diligence on the supplier and records findings.

  9. 9
    Persist Due Diligence Resultsupdate record

    Saves due diligence findings and outcome to the record.

  10. 10
    Check if Security/Privacy Review Needed

    Routes to a security/privacy review when the AI classifies the supplier's data/systems access as sensitive; low-confidence results go to manual review.

    _ai_clf_ai_sensitive_data_classification_needs_human_review: "true"Manual Sensitive Access Review
    sensitive_access_flag: "Sensitive"Security/Privacy Review
    DefaultSet Status to Treatment Planning
  11. 11
    Security/Privacy Reviewcreate task

    Security/privacy specialist reviews controls given the supplier's sensitive data or system access.

  12. 12
    Persist Security/Privacy Review Resultsupdate record

    Saves security/privacy review findings and result to the record, and marks status.

  13. 13
    Determine Risk Treatment Plancreate task

    Reviewer records the risk treatment plan and residual risk rating based on all findings.

  14. 14
    Persist Treatment Planupdate record

    Saves the risk treatment plan and residual risk rating, and updates status.

  15. 15
    Request Residual Risk Acceptancerequest approval

    Risk manager reviews the treatment plan and approves or rejects acceptance of the residual risk.

  16. 16
    Route on Residual Risk Acceptance Outcome

    Routes based on whether the risk manager approved or rejected the residual risk acceptance.

    approval_status: "approved"Set Status to Accepted
    approval_status: "rejected"Set Status to Rejected
    DefaultSet Status to Rejected
  17. 17
    Loop Back for Treatment Revisionrestart from step

    Rejected acceptance sends the assessment back for the reviewer to revise the treatment plan.

  18. 18
    Set Status to Acceptedupdate record

    Marks the residual risk as accepted.

  19. 19
    Route Reassessment Interval by Risk Tier

    Sets a different reassessment interval based on the final residual risk rating.

    residual_risk_rating: "High"Set Reassessment Date (High Risk - 180 Days)
    residual_risk_rating: "Medium"Set Reassessment Date (Medium Risk - 365 Days)
    residual_risk_rating: "Low"Set Reassessment Date (Low Risk - 730 Days)
    DefaultSet Reassessment Date (Medium Risk - 365 Days)
  20. 20
    Set Reassessment Date (High Risk - 180 Days)set due date

    High residual risk suppliers are reassessed every 180 days.

  21. 21
    Set Reassessment Date (Medium Risk - 365 Days)set due date

    Medium residual risk suppliers are reassessed annually.

  22. 22
    Set Reassessment Date (Low Risk - 730 Days)set due date

    Low residual risk suppliers are reassessed every 2 years.

  23. 23
    Notify Requester of Outcomesend email

    Emails the requester confirming the assessment is complete and residual risk accepted.

  24. 24
    AI Classify Sensitive Data/Systems Accessai classification

    Classifies whether the supplier's selected data/systems access includes any sensitive category, since data_systems_access is multi-select and cannot be matched with exact equality.

  25. 25
    Persist Sensitive Access Flagupdate record

    Writes the AI-derived sensitive access classification to the record.

  26. 26
    Manual Sensitive Access Reviewcreate task

    Risk analyst manually confirms whether the supplier's access is sensitive when AI confidence is low.

  27. 27
    Persist Manually Confirmed Sensitive Flagupdate record

    Writes the analyst's manually confirmed sensitive access flag to the record.

  28. 28
    Route on Manually Confirmed Sensitive Flag

    Routes to security/privacy review or straight to treatment based on the analyst's manual confirmation.

    sensitive_access_flag: "Sensitive"Security/Privacy Review
    DefaultSet Status to Treatment Planning
  29. 29
    Set Status to Treatment Planningupdate record

    Marks the assessment as entering the treatment planning stage.

  30. 30
    Set Status to Rejectedupdate record

    Marks the residual risk acceptance as rejected before looping back for treatment revision.

Fields

  • Requester Name*
  • Requester Email*
  • Supplier Name*
  • Services Provided by Supplier*
  • Business Criticality*
  • Data or Systems Accessed*
  • +11 more fields

Forms

Supplier Risk Assessment Request

8 fields

Data Views

Supplier Risk Assessments

supplier_name, criticality, inherent_risk_tier, due_diligence_outcome +3 more

Dashboard Widgets

Assessments by StatusAssessment PipelineAssessments by Inherent Risk Tier

Recommended integrations

Setup the following integrations to extend workflow capability.

  • Send email in the workflow

    AWS SES logoAWS SES
supplier risk assessmentvendor risk assessmentthird party risksupplier due diligencevendor management

Similar Workflows

Similar Categories

FAQs

Do I need technical skills to set this workflow up?

No. This is a ready-to-use template inside assess.one — you publish it and it's live in seconds, no coding or IT project required. You can adjust steps, approval logic, and notifications directly in the platform's interface.

Can my team customise the risk tiers or approval thresholds?

Yes. The AI inherent risk triage, manual review overrides, and residual risk acceptance gate can all be edited to match your organisation's risk appetite and thresholds. You can also change who reviews or approves at each stage without any developer involvement.

Is this suitable for small procurement teams without a dedicated risk function?

Yes, it works well for lean teams. The AI triage step handles initial risk sorting automatically, so a small team only needs to step in for manual review, due diligence, and approval decisions rather than building the process from scratch.

How long does it take to get this workflow running?

Minutes. Once you publish the template it's live immediately, and your team can start submitting supplier assessment requests right away — there's no implementation project or waiting period.

Who needs access to this workflow?

Typically the requester (whoever wants to onboard a supplier), a risk or procurement reviewer, a security/privacy reviewer for sensitive cases, and an approver for residual risk acceptance. Access and permissions for each role are set directly within assess.one.

What happens if the AI triage confidence is low?

The workflow routes low-confidence AI triage results to a manual inherent risk review step, so a person sets the risk tier instead of relying solely on the AI output. Both the manually set and AI-derived tiers are recorded for audit purposes.

When does the security/privacy review get triggered?

The workflow checks automatically whether the supplier will access sensitive data or critical systems. If yes, it routes the request into a dedicated security/privacy review step before the risk treatment plan is determined.

What if residual risk isn't accepted?

The workflow loops back for treatment plan revision if residual risk acceptance is declined, so the reviewer can strengthen mitigations and resubmit. It only moves to 'Accepted' status once a formal approver signs off.

How does reassessment scheduling work?

Once a supplier is accepted, the workflow routes the reassessment interval based on the assigned risk tier — for example, high-risk suppliers are automatically scheduled for reassessment in 180 days. This removes the need to manually track review dates in a spreadsheet.

Does the requester get notified of the outcome?

Yes, the requester receives a notification once the risk assessment reaches a decision, whether that's acceptance, further review, or rejection. Notification channels like email or Slack are configured directly inside assess.one.

Ready to use this workflow?

Create a free account and customise this workflow for your business.

Supplier Risk Assessment Workflow | assess.one