Scrutineer · Vendor risk
Vendor risk management that scores every vendor on evidence
Vendor risk management breaks down when it is a once-a-year questionnaire that nobody reads and a spreadsheet that goes stale the day after onboarding. The risk a vendor carries changes constantly, and your view of it should too. Scrutineer assesses each vendor, produces a clear risk score, and then keeps watching.
For every vendor you get a risk score backed by evidence: their security posture, the data they touch, their certifications and any monitoring signals that change over time. New vendors are onboarded with a structured assessment instead of a gut feel, and existing vendors are continuously monitored so a downgrade reaches you before an incident does. You decide who to onboard; Scrutineer makes sure the decision is informed.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with vendor risk
Almost nothing that changes a vendor's risk happens on your review date
The annual reassessment is the backbone of most vendor risk programs and it is calibrated to the wrong clock. Acquisitions, new subcontractors, breaches, expired certificates, a security leader leaving, a service quietly moving to a new region: all of it lands on an arbitrary Tuesday. A calendar-driven program discovers those changes an average of six months late and, in the worst case, twelve. The fix is not a shorter cycle, which just multiplies the busywork. It is a small set of event triggers that pull a vendor back into review the moment something material moves, with the annual pass reduced to what genuinely needs a periodic look.
The gap between two SOC 2 reports is the blind spot nobody budgets for
A SOC 2 Type II opinion covers a defined period that has already ended by the time you read the report. When the next period starts is up to the vendor, and consecutive reports frequently leave weeks or months uncovered. The industry patch is a bridge letter, in which the vendor asserts that nothing material changed since the report period closed. A bridge letter is management representation, not audit work: no auditor tested anything in that window. Treat it as what it is. Record the report period, record the gap, and decide deliberately whether the vendor's tier justifies asking for more than an assertion.
A risk score is a summary, not evidence
A single number is useful for triage and useless in an audit. When a regulator or a customer asks why a vendor was approved, the answer has to be the reasoning underneath: what data the vendor reaches, which controls were tested and by whom, what the report period covered, what exceptions were raised and what compensating controls you accepted. Scrutineer keeps the score visible for prioritization and the evidence trail underneath it intact, so the two audiences that ask about a vendor, your own team triaging work and an examiner testing your judgement, both get an answer in the form they need.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Assesses each vendor on security posture, the data it reaches and the systems it can touch, on one consistent standard
- Produces a risk score for triage with the full evidence trail preserved underneath it, so the score never has to stand alone in an audit
- Pulls vendors back into review on event triggers, not only on the anniversary of onboarding
- Records the exact period each SOC 2 Type II covers, and flags the uncovered gap before the next report arrives
- Tracks certification expiry across ISO 27001 surveillance cycles, SOC 2 periods and any framework the vendor claims
- Keeps subcontractor disclosures attached to the vendor record, so a new one added mid-term is visible rather than buried
- Prioritizes remediation by the exposure a vendor actually carries instead of by contract value
- Keeps a defensible, dated record of every assessment, exception and accepted risk, in the form an examiner asks for
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Reassessment trigger reference
What changes a vendor's risk, and whether an annual review would ever catch it
Vendor risk comparisons are usually built around features. This one is built around the thing that actually decides whether a program works: what happens at a vendor between your reviews. Every row is a real change that alters exposure, matched against whether a calendar-driven reassessment would find it and what evidence records it.
| What changed at the vendor | What it should change in your risk view | Would an annual reassessment catch it | What records it |
|---|---|---|---|
| Acquired, merged or taken private | New ownership, possible new data locations, possible consolidation onto the acquirer's infrastructure. The entity you assessed no longer exists in the same form | Only at the next review, and only if somebody notices the name changed | Contract assignment notices, the vendor's own announcement, and any change of control clause you negotiated |
| Adds a subcontractor mid-term | A new fourth party reaches your data with no assessment behind it | No. Nothing in an annual questionnaire surfaces a change made in month three unless you ask again | The notice clause in your contract, if you have one. Without that clause there is no record at all |
| Discloses a security incident | Immediate reassessment of the controls involved, plus the question of what data of yours was in scope | No. Incident notification is a contract obligation and a monitoring signal, not a review outcome | The incident notice itself, your own logs, and the remediation evidence the vendor provides afterward |
| SOC 2 Type II period ends and the next report is months away | A defined window with no audit coverage. Any assurance in that window is management assertion only | No. Most reviews record that a report exists, not what period it covered or what came after | The report period dates, plus any bridge letter, which is a vendor representation rather than tested work |
| ISO 27001 certificate approaches expiry or fails a surveillance audit | A claimed certification may no longer be live. The three-year cycle with annual surveillance means lapses are common and quiet | Sometimes, if the review happens to fall after the expiry date | The certificate itself with its validity dates, and the certification body register |
| Starts handling a new data type or a new system | Scope has grown. The tier you assigned at onboarding was set against a smaller footprint | Rarely. Scope creep usually arrives through a new use case that never reaches the vendor risk team | Change requests, new integrations and access grants, which is why access review data belongs in the same record |
| Loses its security leader or the team behind your account | A capability question rather than a control question, and one the guidance names explicitly as a monitoring signal | No, unless the departure is public | Relationship notes, escalation history, and how long incident responses take compared with before |
Monitoring expectations reflect the Interagency Guidance on Third-Party Relationships issued June 6, 2023, which lists changes in key personnel, reliance on subcontractors and audit results among the things to monitor throughout a relationship. SOC 2 reporting treatment follows the AICPA attestation standards. Your own contract determines which of these changes you will actually be told about. Scrutineer organizes readiness evidence and does not issue attestations.
Good questions
Questions about vendor risk
Keep reading
Guides that go deeper on this framework
The vendor risk management process, step by step
Inventory, tiering, diligence, contracting and monitoring, with the artifact each step has to leave behind.
Read the guideVendor tiering that holds up in an audit
How to set a criticality rule you can defend, so diligence depth matches exposure instead of contract value.
Read the guideBest third-party risk management software
The categories of tooling compared on what each actually produces, and the question that decides which one you need.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification