assess.one – AI-powered business operations platform

Workflow Template

Third-Party Security Assessment Workflow

Manages third-party vendor security assessments end-to-end: intake of vendor/service/data-access details, sends a security questionnaire to the vendor for completion, internal review of evidence with risk findings and remediation notes, approval routing on residual risk, and either recording final approval with a reassessment date or returning the assessment to the vendor for remediation and re-review.

Security teams tracking vendor assessments across email threads and spreadsheets lose weeks chasing questionnaire responses, misplace risk findings, and forget reassessment dates until an audit exposes the gap. The Third-Party Security Assessment Workflow captures vendor and data-access details up front, automates questionnaire delivery, routes risk findings for approval, and schedules reassessment automatically. Teams cut vendor onboarding time and eliminate missed reassessment deadlines without building anything custom.

Business Outcomes

  • Reduces vendor security review cycle time by eliminating manual email chasing
  • Ensures 100% of high-risk vendors get reassessment dates automatically scheduled
  • Cuts risk-approval bottlenecks with structured routing on residual risk
  • Provides a full audit trail of questionnaire responses and review findings per vendor
  • Shortens remediation loops by returning failed assessments directly to vendors for re-review

Workflow Steps

Steps

  1. 1
    Create vendor assessment recordcreate record

    Registers the vendor security assessment record from the owner's intake submission.

  2. 2
    Set status to Openupdate record

    Marks the newly created assessment as Open.

  3. 3
    Send security questionnaire to vendorrequest external input

    Sends the vendor a link to complete the security questionnaire covering data handling, access control, incidents, and certifications.

  4. 4
    Persist questionnaire responsesupdate record

    Saves the vendor's questionnaire responses to the record and updates status.

  5. 5
    Review evidence and record risk findingscreate task

    Reviewer examines the questionnaire responses and any supporting evidence, then records risk findings, remediation needs, and residual risk level.

  6. 6
    Persist review findings to recordupdate record

    Writes the reviewer's risk findings, remediation notes, and residual risk level to the assessment record.

  7. 7
    Request approval on residual riskrequest approval

    Routes the residual risk finding to an approver to accept or reject the assessment outcome.

  8. 8
    Route on residual risk approval outcome

    Branches based on whether the residual risk is approved or deemed unacceptable.

    approval_status: "approved"Record approval and set reassessment date
    approval_status: "rejected"Update status and notify vendor of remediation
    DefaultEnd
  9. 9
    Record approval and set reassessment dateupdate record

    Marks the assessment as approved and sets the reassessment due date 12 months out.

  10. 10
    Set reassessment due dateset due date

    Applies a 12-month reassessment target to the record for SLA tracking and persists the reassessment date field.

  11. 11
    Persist reassessment date to recordupdate record

    Writes the resolved reassessment due date to the record so it is visible in reports and table views.

  12. 12
    Notify owner of approvalsend email

    Informs the assessment owner that the vendor's residual risk was approved.

  13. 13
    Update status and notify vendor of remediationupdate record

    Marks the assessment as requiring remediation and sends the vendor the required remediation details.

  14. 14
    Send remediation request to vendorsend email

    Notifies the vendor that residual risk was unacceptable and specifies the remediation required before re-review.

  15. 15
    Restart review after remediationrestart from step

    Restarts the workflow from the evidence review step so the reviewer can re-assess after the vendor remediates.

  16. 16
    Set status to Questionnaire Sentupdate record

    Marks the assessment as Questionnaire Sent before dispatching the vendor questionnaire.

Fields

  • Assessment Owner Name*
  • Assessment Owner Email*
  • Third Party / Vendor Name*
  • Vendor Contact Email*
  • Service Provided by Vendor*
  • Data or Systems the Vendor Accesses*
  • +10 more fields

Forms

Third-Party Security Assessment Intake

6 fields

Data Views

Vendor Security Assessments

vendor_name, assessment_status, residual_risk_level, reassessment_date

Dashboard Widgets

Assessments by StatusAssessment PipelineResidual Risk Level Breakdown

Recommended integrations

Setup the following integrations to extend workflow capability.

  • Send email in the workflow

    AWS SES logoAWS SES
third party security assessmentvendor security reviewsecurity questionnairesupplier cyber riskthird party risk

Similar Workflows

Similar Categories

FAQs

What happens if a vendor doesn't respond to the security questionnaire?

The assessment record stays in Open status until questionnaire responses are persisted, so nothing silently disappears. You can configure reminder notifications inside assess.one to nudge vendors automatically, and reviewers can see at a glance which vendors are outstanding. The workflow doesn't force a deadline by default, but you can add a due date and escalation step directly in the template editor.

Can this handle a vendor that fails the risk review multiple times?

Yes. The workflow explicitly supports looping — if residual risk approval is rejected, the record updates status, notifies the vendor of required remediation, and restarts the review after remediation is submitted. This cycle can repeat as many times as needed until the risk is resolved or the assessment is formally closed out.

What if we need different approval logic for high-risk vendors versus low-risk ones?

You can customise the approval routing step directly in assess.one to branch based on risk score, vendor tier, or data-access level. This lets you require multiple approvers for high-risk vendors while keeping low-risk approvals single-step, all without any code changes.

Who needs access to this workflow?

Typically vendor owners or procurement staff create the assessment record, security reviewers evaluate evidence and log findings, and a designated approver signs off on residual risk. Vendors themselves only need access to the questionnaire link — they don't need a full platform account. Access and permissions for each step are configured inside assess.one's role settings.

How does the reassessment date get set, and can we change the interval?

Once an assessment is approved, the workflow automatically sets a reassessment due date and persists it to the vendor record. The default interval is configurable — you can set it to 6 months, 12 months, or any cadence your compliance policy requires, directly in the workflow settings.

What if we have vendors with multiple services or data-access levels to assess separately?

Each vendor assessment is created as its own record during intake, so you can run separate assessments per service or data-access scope for the same vendor. This keeps risk findings and approval history distinct per engagement rather than lumped into one blanket vendor rating.

How long does it take to get this workflow live?

Publishing the template takes minutes — there's no implementation project or software installation required. Once published, your team can immediately start creating vendor assessment records and sending questionnaires in the same session.

Can we customise the security questionnaire itself?

Yes. The questionnaire content, fields, and scoring logic can be edited directly within assess.one before it's sent to vendors. You can tailor questions to your specific compliance framework, such as SOC 2, ISO 27001, or internal risk criteria.

What happens at the residual risk approval decision point?

After internal review, the workflow routes the record to a designated approver who evaluates the documented risk findings and remediation notes. If approved, the system records the decision and sets a reassessment date; if rejected, it flags the vendor for remediation and loops the assessment back for re-review.

Does this workflow support compliance audit requirements?

Every step — questionnaire responses, review findings, approval decisions, and reassessment dates — is persisted to the vendor record, creating a complete audit trail. This makes it straightforward to demonstrate to auditors when and how each vendor's risk was assessed and approved.

Ready to use this workflow?

Create a free account and customise this workflow for your business.

Third-Party Security Assessment Workflow | assess.one