Scrutineer.ai

Scrutineer · Vendor risk

Vendor risk management that scores every vendor on evidence

Vendor risk management breaks down when it is a once-a-year questionnaire that nobody reads and a spreadsheet that goes stale the day after onboarding. The risk a vendor carries changes constantly, and your view of it should too. Scrutineer assesses each vendor, produces a clear risk score, and then keeps watching.

For every vendor you get a risk score backed by evidence: their security posture, the data they touch, their certifications and any monitoring signals that change over time. New vendors are onboarded with a structured assessment instead of a gut feel, and existing vendors are continuously monitored so a downgrade reaches you before an incident does. You decide who to onboard; Scrutineer makes sure the decision is informed.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with vendor risk

Almost nothing that changes a vendor's risk happens on your review date

The annual reassessment is the backbone of most vendor risk programs and it is calibrated to the wrong clock. Acquisitions, new subcontractors, breaches, expired certificates, a security leader leaving, a service quietly moving to a new region: all of it lands on an arbitrary Tuesday. A calendar-driven program discovers those changes an average of six months late and, in the worst case, twelve. The fix is not a shorter cycle, which just multiplies the busywork. It is a small set of event triggers that pull a vendor back into review the moment something material moves, with the annual pass reduced to what genuinely needs a periodic look.

The gap between two SOC 2 reports is the blind spot nobody budgets for

A SOC 2 Type II opinion covers a defined period that has already ended by the time you read the report. When the next period starts is up to the vendor, and consecutive reports frequently leave weeks or months uncovered. The industry patch is a bridge letter, in which the vendor asserts that nothing material changed since the report period closed. A bridge letter is management representation, not audit work: no auditor tested anything in that window. Treat it as what it is. Record the report period, record the gap, and decide deliberately whether the vendor's tier justifies asking for more than an assertion.

A risk score is a summary, not evidence

A single number is useful for triage and useless in an audit. When a regulator or a customer asks why a vendor was approved, the answer has to be the reasoning underneath: what data the vendor reaches, which controls were tested and by whom, what the report period covered, what exceptions were raised and what compensating controls you accepted. Scrutineer keeps the score visible for prioritization and the evidence trail underneath it intact, so the two audiences that ask about a vendor, your own team triaging work and an examiner testing your judgement, both get an answer in the form they need.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Assesses each vendor on security posture, the data it reaches and the systems it can touch, on one consistent standard
  • Produces a risk score for triage with the full evidence trail preserved underneath it, so the score never has to stand alone in an audit
  • Pulls vendors back into review on event triggers, not only on the anniversary of onboarding
  • Records the exact period each SOC 2 Type II covers, and flags the uncovered gap before the next report arrives
  • Tracks certification expiry across ISO 27001 surveillance cycles, SOC 2 periods and any framework the vendor claims
  • Keeps subcontractor disclosures attached to the vendor record, so a new one added mid-term is visible rather than buried
  • Prioritizes remediation by the exposure a vendor actually carries instead of by contract value
  • Keeps a defensible, dated record of every assessment, exception and accepted risk, in the form an examiner asks for
Vendor risk readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Reassessment trigger reference

What changes a vendor's risk, and whether an annual review would ever catch it

Vendor risk comparisons are usually built around features. This one is built around the thing that actually decides whether a program works: what happens at a vendor between your reviews. Every row is a real change that alters exposure, matched against whether a calendar-driven reassessment would find it and what evidence records it.

What changed at the vendor What it should change in your risk view Would an annual reassessment catch it What records it
Acquired, merged or taken private New ownership, possible new data locations, possible consolidation onto the acquirer's infrastructure. The entity you assessed no longer exists in the same form Only at the next review, and only if somebody notices the name changed Contract assignment notices, the vendor's own announcement, and any change of control clause you negotiated
Adds a subcontractor mid-term A new fourth party reaches your data with no assessment behind it No. Nothing in an annual questionnaire surfaces a change made in month three unless you ask again The notice clause in your contract, if you have one. Without that clause there is no record at all
Discloses a security incident Immediate reassessment of the controls involved, plus the question of what data of yours was in scope No. Incident notification is a contract obligation and a monitoring signal, not a review outcome The incident notice itself, your own logs, and the remediation evidence the vendor provides afterward
SOC 2 Type II period ends and the next report is months away A defined window with no audit coverage. Any assurance in that window is management assertion only No. Most reviews record that a report exists, not what period it covered or what came after The report period dates, plus any bridge letter, which is a vendor representation rather than tested work
ISO 27001 certificate approaches expiry or fails a surveillance audit A claimed certification may no longer be live. The three-year cycle with annual surveillance means lapses are common and quiet Sometimes, if the review happens to fall after the expiry date The certificate itself with its validity dates, and the certification body register
Starts handling a new data type or a new system Scope has grown. The tier you assigned at onboarding was set against a smaller footprint Rarely. Scope creep usually arrives through a new use case that never reaches the vendor risk team Change requests, new integrations and access grants, which is why access review data belongs in the same record
Loses its security leader or the team behind your account A capability question rather than a control question, and one the guidance names explicitly as a monitoring signal No, unless the departure is public Relationship notes, escalation history, and how long incident responses take compared with before

Monitoring expectations reflect the Interagency Guidance on Third-Party Relationships issued June 6, 2023, which lists changes in key personnel, reliance on subcontractors and audit results among the things to monitor throughout a relationship. SOC 2 reporting treatment follows the AICPA attestation standards. Your own contract determines which of these changes you will actually be told about. Scrutineer organizes readiness evidence and does not issue attestations.

Good questions

Questions about vendor risk

Vendor risk management is the practice of assessing, tiering, monitoring and exiting the suppliers your organization depends on, so that the risk each one carries is known before it becomes an incident. It covers security posture, the data and systems the vendor reaches, the certifications behind its claims, and the contract terms that give you rights when something goes wrong.
Five steps in order: inventory every vendor and what it touches, tier them by the exposure a failure would create, run diligence proportionate to the tier, contract for the rights you will need including notice and audit access, then monitor continuously with event triggers rather than only on an annual calendar. Offboarding closes the loop with data return or destruction evidence.
Tier the interval, then add triggers. Critical vendors handling regulated data warrant at least an annual pass; low-tier vendors with no data access rarely justify one. What matters more is the trigger list: an acquisition, a new subcontractor, an incident, an expired certification, a SOC 2 period gap, or a change in the data the vendor handles should each pull the vendor back into review immediately.
A bridge letter, sometimes called a gap letter, is a written statement from a vendor that nothing material changed between the end of its SOC 2 report period and today. It is management representation, not audit work, and no independent party tested the window it covers. Accept it for lower-tier vendors, and for critical ones record the gap explicitly and decide whether the tier justifies asking for more.
A security rating is produced by an outside firm from internet-facing signals: exposed services, certificates, patch cadence, leaked credentials. A vendor risk score is your own composite judgement, which should include the rating if you buy one, but also the data the vendor reaches, its audited controls, its certifications and its contract terms. A rating is an input. A score is a decision.
The data and systems the vendor can reach, the controls it operates and who tested them, the audit reports and certifications behind its claims with their validity periods, its use of subcontractors and where they are located, its incident history and notification commitments, and the contract rights you hold. Depth should scale with tier rather than being identical for every supplier.
By what a failure would cost, not by what the contract costs. A small analytics tool with production database access outranks a large facilities contract with no data access. Rank by the sensitivity of data reached, whether the vendor supports an activity you consider critical, and how hard the vendor would be to replace at short notice.
No, and be wary of any tool that says it does. Software removes the collection and chasing: gathering reports, tracking expiry dates, watching for changes and assembling the evidence trail. The judgement calls, which vendors are critical, which exceptions are acceptable, which risks get accepted and by whom, stay with your team, and the record of who decided what is the part an examiner will actually test.
Scrutineer combines the vendor assessment, their security posture, the sensitivity of data they access, their certifications and ongoing monitoring signals into a single score, with the evidence behind each factor visible so you can see exactly why a vendor scored where it did.
Yes. That is the point. Scrutineer continuously watches each vendor for posture changes, lapsed certifications and new signals, and re-scores them, so a vendor that degrades after onboarding triggers an alert rather than going unnoticed.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification