Workflow Template
Third-Party Security Assessment Workflow
Manages third-party vendor security assessments end-to-end: intake of vendor/service/data-access details, sends a security questionnaire to the vendor for completion, internal review of evidence with risk findings and remediation notes, approval routing on residual risk, and either recording final approval with a reassessment date or returning the assessment to the vendor for remediation and re-review.
Security teams tracking vendor assessments across email threads and spreadsheets lose weeks chasing questionnaire responses, misplace risk findings, and forget reassessment dates until an audit exposes the gap. The Third-Party Security Assessment Workflow captures vendor and data-access details up front, automates questionnaire delivery, routes risk findings for approval, and schedules reassessment automatically. Teams cut vendor onboarding time and eliminate missed reassessment deadlines without building anything custom.
Business Outcomes
- Reduces vendor security review cycle time by eliminating manual email chasing
- Ensures 100% of high-risk vendors get reassessment dates automatically scheduled
- Cuts risk-approval bottlenecks with structured routing on residual risk
- Provides a full audit trail of questionnaire responses and review findings per vendor
- Shortens remediation loops by returning failed assessments directly to vendors for re-review
Workflow Steps
Steps
- 1Create vendor assessment recordcreate record
Registers the vendor security assessment record from the owner's intake submission.
- 2Set status to Openupdate record
Marks the newly created assessment as Open.
- 3Send security questionnaire to vendorrequest external input
Sends the vendor a link to complete the security questionnaire covering data handling, access control, incidents, and certifications.
- 4Persist questionnaire responsesupdate record
Saves the vendor's questionnaire responses to the record and updates status.
- 5Review evidence and record risk findingscreate task
Reviewer examines the questionnaire responses and any supporting evidence, then records risk findings, remediation needs, and residual risk level.
- 6Persist review findings to recordupdate record
Writes the reviewer's risk findings, remediation notes, and residual risk level to the assessment record.
- 7Request approval on residual riskrequest approval
Routes the residual risk finding to an approver to accept or reject the assessment outcome.
- 8Route on residual risk approval outcome
Branches based on whether the residual risk is approved or deemed unacceptable.
approval_status: "approved"→Record approval and set reassessment dateapproval_status: "rejected"→Update status and notify vendor of remediationDefault→End - 9Record approval and set reassessment dateupdate record
Marks the assessment as approved and sets the reassessment due date 12 months out.
- 10Set reassessment due dateset due date
Applies a 12-month reassessment target to the record for SLA tracking and persists the reassessment date field.
- 11Persist reassessment date to recordupdate record
Writes the resolved reassessment due date to the record so it is visible in reports and table views.
- 12Notify owner of approvalsend email
Informs the assessment owner that the vendor's residual risk was approved.
- 13Update status and notify vendor of remediationupdate record
Marks the assessment as requiring remediation and sends the vendor the required remediation details.
- 14Send remediation request to vendorsend email
Notifies the vendor that residual risk was unacceptable and specifies the remediation required before re-review.
- 15Restart review after remediationrestart from step
Restarts the workflow from the evidence review step so the reviewer can re-assess after the vendor remediates.
- 16Set status to Questionnaire Sentupdate record
Marks the assessment as Questionnaire Sent before dispatching the vendor questionnaire.
Fields
- Assessment Owner Name*
- Assessment Owner Email*
- Third Party / Vendor Name*
- Vendor Contact Email*
- Service Provided by Vendor*
- Data or Systems the Vendor Accesses*
- +10 more fields
Forms
Third-Party Security Assessment Intake
6 fields
Data Views
Vendor Security Assessments
vendor_name, assessment_status, residual_risk_level, reassessment_date
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Workflows
Similar Categories
FAQs
What happens if a vendor doesn't respond to the security questionnaire?
The assessment record stays in Open status until questionnaire responses are persisted, so nothing silently disappears. You can configure reminder notifications inside assess.one to nudge vendors automatically, and reviewers can see at a glance which vendors are outstanding. The workflow doesn't force a deadline by default, but you can add a due date and escalation step directly in the template editor.
Can this handle a vendor that fails the risk review multiple times?
Yes. The workflow explicitly supports looping — if residual risk approval is rejected, the record updates status, notifies the vendor of required remediation, and restarts the review after remediation is submitted. This cycle can repeat as many times as needed until the risk is resolved or the assessment is formally closed out.
What if we need different approval logic for high-risk vendors versus low-risk ones?
You can customise the approval routing step directly in assess.one to branch based on risk score, vendor tier, or data-access level. This lets you require multiple approvers for high-risk vendors while keeping low-risk approvals single-step, all without any code changes.
Who needs access to this workflow?
Typically vendor owners or procurement staff create the assessment record, security reviewers evaluate evidence and log findings, and a designated approver signs off on residual risk. Vendors themselves only need access to the questionnaire link — they don't need a full platform account. Access and permissions for each step are configured inside assess.one's role settings.
How does the reassessment date get set, and can we change the interval?
Once an assessment is approved, the workflow automatically sets a reassessment due date and persists it to the vendor record. The default interval is configurable — you can set it to 6 months, 12 months, or any cadence your compliance policy requires, directly in the workflow settings.
What if we have vendors with multiple services or data-access levels to assess separately?
Each vendor assessment is created as its own record during intake, so you can run separate assessments per service or data-access scope for the same vendor. This keeps risk findings and approval history distinct per engagement rather than lumped into one blanket vendor rating.
How long does it take to get this workflow live?
Publishing the template takes minutes — there's no implementation project or software installation required. Once published, your team can immediately start creating vendor assessment records and sending questionnaires in the same session.
Can we customise the security questionnaire itself?
Yes. The questionnaire content, fields, and scoring logic can be edited directly within assess.one before it's sent to vendors. You can tailor questions to your specific compliance framework, such as SOC 2, ISO 27001, or internal risk criteria.
What happens at the residual risk approval decision point?
After internal review, the workflow routes the record to a designated approver who evaluates the documented risk findings and remediation notes. If approved, the system records the decision and sets a reassessment date; if rejected, it flags the vendor for remediation and loops the assessment back for re-review.
Does this workflow support compliance audit requirements?
Every step — questionnaire responses, review findings, approval decisions, and reassessment dates — is persisted to the vendor record, creating a complete audit trail. This makes it straightforward to demonstrate to auditors when and how each vendor's risk was assessed and approved.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
