Workflow Template
Supplier Risk Assessment Workflow
Captures a supplier risk assessment request, triages inherent risk with AI, runs due diligence, adds a security/privacy review when sensitive data or critical systems are accessed, has a reviewer record the risk treatment plan, gates residual risk acceptance through formal approval, sets a reassessment date, and notifies the requester of the outcome.
Every new supplier or software vendor request seems to trigger the same scramble — someone chases down risk questions, security has to weigh in on data access, and approval sits in someone's inbox for weeks. This workflow captures the request, uses AI to triage inherent risk, runs due diligence, automatically pulls in a security/privacy review when sensitive data or critical systems are involved, and routes the treatment plan through formal approval before setting a reassessment date. Your team gets a consistent, auditable process instead of a patchwork of emails and spreadsheets — and the requester is notified automatically once a decision is made.
Business Outcomes
- Cut supplier risk assessment turnaround from weeks to days
- 100% of high-risk suppliers routed through security/privacy review automatically
- Full audit trail of risk tier, due diligence, and approval decisions
- Zero missed reassessment dates with automatic scheduling by risk tier
- Fewer back-and-forth emails chasing approvals or missing information
Workflow Steps
Steps
- 1Create Supplier Assessment Recordcreate record
Registers the assessment request as a record.
- 2Set Status to Submittedupdate record
Marks the assessment as submitted.
- 3AI Inherent Risk Triageai prioritisation
AI assesses inherent risk based on criticality, data/system access, and locations.
- 4Route on AI Triage Confidence
Sends low-confidence triage to human review, otherwise persists the AI-derived risk tier.
_ai_priority_ai_inherent_risk_triage_needs_human_review: "true"→Manual Inherent Risk ReviewDefault→Persist AI-Derived Risk Tier - 5Manual Inherent Risk Reviewcreate task
Risk analyst manually determines the inherent risk tier when AI confidence is low.
- 6Persist Manually Set Risk Tierupdate record
Writes the analyst's manually chosen risk tier to the record.
- 7Persist AI-Derived Risk Tierupdate record
Writes the AI-derived inherent risk tier to the record.
- 8Conduct Due Diligencecreate task
Risk analyst performs due diligence on the supplier and records findings.
- 9Persist Due Diligence Resultsupdate record
Saves due diligence findings and outcome to the record.
- 10Check if Security/Privacy Review Needed
Routes to a security/privacy review when the AI classifies the supplier's data/systems access as sensitive; low-confidence results go to manual review.
_ai_clf_ai_sensitive_data_classification_needs_human_review: "true"→Manual Sensitive Access Reviewsensitive_access_flag: "Sensitive"→Security/Privacy ReviewDefault→Set Status to Treatment Planning - 11Security/Privacy Reviewcreate task
Security/privacy specialist reviews controls given the supplier's sensitive data or system access.
- 12Persist Security/Privacy Review Resultsupdate record
Saves security/privacy review findings and result to the record, and marks status.
- 13Determine Risk Treatment Plancreate task
Reviewer records the risk treatment plan and residual risk rating based on all findings.
- 14Persist Treatment Planupdate record
Saves the risk treatment plan and residual risk rating, and updates status.
- 15Request Residual Risk Acceptancerequest approval
Risk manager reviews the treatment plan and approves or rejects acceptance of the residual risk.
- 16Route on Residual Risk Acceptance Outcome
Routes based on whether the risk manager approved or rejected the residual risk acceptance.
approval_status: "approved"→Set Status to Acceptedapproval_status: "rejected"→Set Status to RejectedDefault→Set Status to Rejected - 17Loop Back for Treatment Revisionrestart from step
Rejected acceptance sends the assessment back for the reviewer to revise the treatment plan.
- 18Set Status to Acceptedupdate record
Marks the residual risk as accepted.
- 19Route Reassessment Interval by Risk Tier
Sets a different reassessment interval based on the final residual risk rating.
residual_risk_rating: "High"→Set Reassessment Date (High Risk - 180 Days)residual_risk_rating: "Medium"→Set Reassessment Date (Medium Risk - 365 Days)residual_risk_rating: "Low"→Set Reassessment Date (Low Risk - 730 Days)Default→Set Reassessment Date (Medium Risk - 365 Days) - 20Set Reassessment Date (High Risk - 180 Days)set due date
High residual risk suppliers are reassessed every 180 days.
- 21Set Reassessment Date (Medium Risk - 365 Days)set due date
Medium residual risk suppliers are reassessed annually.
- 22Set Reassessment Date (Low Risk - 730 Days)set due date
Low residual risk suppliers are reassessed every 2 years.
- 23Notify Requester of Outcomesend email
Emails the requester confirming the assessment is complete and residual risk accepted.
- 24AI Classify Sensitive Data/Systems Accessai classification
Classifies whether the supplier's selected data/systems access includes any sensitive category, since data_systems_access is multi-select and cannot be matched with exact equality.
- 25Persist Sensitive Access Flagupdate record
Writes the AI-derived sensitive access classification to the record.
- 26Manual Sensitive Access Reviewcreate task
Risk analyst manually confirms whether the supplier's access is sensitive when AI confidence is low.
- 27Persist Manually Confirmed Sensitive Flagupdate record
Writes the analyst's manually confirmed sensitive access flag to the record.
- 28Route on Manually Confirmed Sensitive Flag
Routes to security/privacy review or straight to treatment based on the analyst's manual confirmation.
sensitive_access_flag: "Sensitive"→Security/Privacy ReviewDefault→Set Status to Treatment Planning - 29Set Status to Treatment Planningupdate record
Marks the assessment as entering the treatment planning stage.
- 30Set Status to Rejectedupdate record
Marks the residual risk acceptance as rejected before looping back for treatment revision.
Fields
- Requester Name*
- Requester Email*
- Supplier Name*
- Services Provided by Supplier*
- Business Criticality*
- Data or Systems Accessed*
- +11 more fields
Forms
Supplier Risk Assessment Request
8 fields
Data Views
Supplier Risk Assessments
supplier_name, criticality, inherent_risk_tier, due_diligence_outcome +3 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Categories
FAQs
Do I need technical skills to set this workflow up?
No. This is a ready-to-use template inside assess.one — you publish it and it's live in seconds, no coding or IT project required. You can adjust steps, approval logic, and notifications directly in the platform's interface.
Can my team customise the risk tiers or approval thresholds?
Yes. The AI inherent risk triage, manual review overrides, and residual risk acceptance gate can all be edited to match your organisation's risk appetite and thresholds. You can also change who reviews or approves at each stage without any developer involvement.
Is this suitable for small procurement teams without a dedicated risk function?
Yes, it works well for lean teams. The AI triage step handles initial risk sorting automatically, so a small team only needs to step in for manual review, due diligence, and approval decisions rather than building the process from scratch.
How long does it take to get this workflow running?
Minutes. Once you publish the template it's live immediately, and your team can start submitting supplier assessment requests right away — there's no implementation project or waiting period.
Who needs access to this workflow?
Typically the requester (whoever wants to onboard a supplier), a risk or procurement reviewer, a security/privacy reviewer for sensitive cases, and an approver for residual risk acceptance. Access and permissions for each role are set directly within assess.one.
What happens if the AI triage confidence is low?
The workflow routes low-confidence AI triage results to a manual inherent risk review step, so a person sets the risk tier instead of relying solely on the AI output. Both the manually set and AI-derived tiers are recorded for audit purposes.
When does the security/privacy review get triggered?
The workflow checks automatically whether the supplier will access sensitive data or critical systems. If yes, it routes the request into a dedicated security/privacy review step before the risk treatment plan is determined.
What if residual risk isn't accepted?
The workflow loops back for treatment plan revision if residual risk acceptance is declined, so the reviewer can strengthen mitigations and resubmit. It only moves to 'Accepted' status once a formal approver signs off.
How does reassessment scheduling work?
Once a supplier is accepted, the workflow routes the reassessment interval based on the assigned risk tier — for example, high-risk suppliers are automatically scheduled for reassessment in 180 days. This removes the need to manually track review dates in a spreadsheet.
Does the requester get notified of the outcome?
Yes, the requester receives a notification once the risk assessment reaches a decision, whether that's acceptance, further review, or rejection. Notification channels like email or Slack are configured directly inside assess.one.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
