Scrutineer.ai

Scrutineer · Vendor risk

Vendor risk management software for your whole portfolio

Once you pass a few dozen vendors, managing risk in spreadsheets stops working: assessments are inconsistent, no one knows which vendors touch sensitive data, and renewals lapse silently. Vendor risk management software should give you one operating picture of the whole portfolio. Scrutineer centralizes onboarding, assessment, scoring and monitoring for every vendor in one place.

Each vendor carries a current risk score, the data it accesses, its certifications and an owner, and the platform keeps that picture live. You can see your riskiest vendors at a glance, route assessments and renewals automatically, and prove to leadership and auditors that third-party risk is under control. You set the policy and make the calls; Scrutineer runs the program underneath.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with VRM software

One portfolio view

Every vendor, its risk score, data access, certifications and owner lives in one platform, so you manage third-party risk as a program, not a pile of spreadsheets.

Consistent assessments

Onboarding and reassessment follow the same structured process for every vendor, so your scores are comparable and your decisions defensible.

Always current

Continuous monitoring and automated renewals keep the portfolio picture live, so nothing lapses silently and risk never quietly drifts.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Centralizes the entire vendor portfolio
  • Standardizes onboarding and reassessment
  • Maintains a current risk score per vendor
  • Routes assessments and renewals to owners
  • Surfaces the riskiest vendors at a glance
  • Reports third-party risk to leadership and auditors
VRM software readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Vendor evidence reference

What each vendor risk signal actually proves, and what it cannot see

Vendor risk tooling is normally compared on which artifacts it can collect. The more useful question is what each artifact is worth once you have it. Every signal below has a blind spot that is structural rather than accidental, and knowing which blind spot you are accepting is the whole job. A completed questionnaire is not assurance; it is a claim you have not tested yet.

The signal What it actually proves What it structurally cannot see How stale it is the day it reaches you
A completed security questionnaire, SIG, CAIQ, HECVAT or your own That someone at the vendor is willing to assert a set of answers, and which topics they claim coverage on Whether any single answer is true. Nothing in a questionnaire becomes evidence until you ask for the artifact sitting behind an answer As stale as the day it was filled in, which is frequently a copy of last year's file with the date changed
A SOC 2 Type II report That an independent CPA firm tested a defined set of controls across a defined period, and exactly which exceptions it found Everything outside the scope section, which is where most surprises live. The complementary user entity controls list what the auditor assumed you would do yourself Covers a window that closed before the report was issued, so it is commonly three to twelve months old on arrival
An ISO/IEC 27001 certificate That an accredited certification body found a working information security management system covering a declared scope What was in that scope. The Statement of Applicability decides it and the certificate does not show it. A certificate is an outcome, not a test result you can read Valid up to three years, and the surveillance audits in between are lighter than the initial certification
A security rating or score Externally observable hygiene: exposed services, certificate handling, patch cadence, leaked credentials appearing in public data Anything behind the perimeter. Access reviews, change management, subprocessor governance and whether an employee can export your data are all invisible to it Close to current, which is its real advantage over everything else here. A good score on Tuesday still does not prevent a breach on Wednesday
A penetration test report That a tester looked for specific classes of weakness in a specific scope at a specific time, and what they found Whether the scope included the system you actually buy. A one page summary letter with no scope section is close to worthless as vendor evidence A point in time, aging from the day the testing ended rather than the day the report was written
A right-to-audit clause in the contract That you are permitted to ask. It is leverage, and leverage is genuinely worth having Nothing at all, until you exercise it. Most organizations never do, which is why the clause tends to be negotiated hard and used never Not applicable, and that is exactly the problem with counting it as assurance
Live evidence pulled from the vendor's own systems The current state of one specific control, with the underlying artifact attached to it Only what you asked for and were granted access to. Coverage is narrow by construction, so it complements the documents rather than replacing them Current, which makes it the only signal here that answers the question you are actually asking: is this true today

None of these signals is redundant and none is sufficient alone. A workable program pairs a scoped document review with a continuous external signal and targeted live evidence on the controls that matter for the data a vendor actually touches. Scrutineer holds and organizes this evidence; it does not audit your vendors and does not certify anyone.

Good questions

Questions about VRM software

Vendor risk management software gives you one current picture of every supplier: what data each one touches, how critical it is, what evidence you hold about its security, when that evidence expires and who owns the relationship. It replaces the spreadsheet and shared mailbox that most programs start with, and its real job is keeping the picture current after onboarding rather than producing it once.
Vendor risk management covers suppliers you pay. Third party risk management is broader and includes relationships that never produce an invoice: resellers, agents, affiliates, joint ventures and cloud services someone expensed on a card. Most teams use the two terms interchangeably and it rarely matters, until an examiner asks whether your inventory covers the relationships procurement never saw.
What data the vendor touches and where it is processed, its authentication and access controls, encryption in transit and at rest, logging and monitoring, change management, incident response and notification commitments, business continuity, subprocessor disclosure, and the evidence behind each claim. Start from the data rather than from a template: a vendor with no access to customer data does not earn the same depth as one holding it.
Only within its scope. A SOC 2 Type II report is strong evidence about the systems and trust services criteria named in its scope section, and silent about everything else. Read the scope, the exception list and the complementary user entity controls before treating it as an approval, because the complementary controls are obligations the auditor assumed you would meet on your side.
Tie the cadence to tier rather than to the calendar. Critical vendors holding regulated or customer data typically warrant an annual full reassessment plus continuous external monitoring; moderate vendors an annual light review; low-risk vendors a review at renewal. Add an event trigger on top: a breach, an acquisition, a change of subprocessor or a material change in the service should pull a reassessment forward regardless of the schedule.
A composite number summarizing how much risk a vendor represents, usually blending the sensitivity of the data it touches, its criticality to your operations, the quality of the evidence you hold and any external security signal. Scores are useful for triage and prioritization and poor as a decision by themselves, because two vendors can reach the same number for entirely different reasons. Always read what drove the score before acting on it.
Fifty is roughly where spreadsheets start failing, though the count matters less than the shape of the portfolio. If most of those vendors are low risk and only a handful touch customer data, a disciplined spreadsheet can hold. The signals that you have outgrown it are lapsed reassessments nobody noticed, no single answer to which vendors touch a given data type, and evidence living in personal mailboxes.
Most platforms in this category quote on request rather than publishing tiers. The drivers are the number of vendors under management, how many require deep assessment rather than a light review, the number of internal users and approval paths, and whether continuous monitoring is bundled or charged per vendor. Scope a quote against your actual tier distribution, because pricing on total vendor count usually overstates what you need.
No. Scrutineer is software rather than an assessment firm or an auditor. It holds the vendor inventory, applies your tiering rules, collects and stores evidence against each control, tracks scores, renewals and expiring documents, and produces the trail leadership and examiners ask for. Every risk decision and every approval stays with your team.
Scrutineer is built for enterprise portfolios, from dozens to thousands of vendors. Because assessments are structured and scoring is automated, the program scales without your team re-reading every questionnaire by hand.
Yes. You can tier vendors by the data they access and their importance to the business, and apply deeper assessment and more frequent monitoring to the critical ones, so effort goes where the risk actually is.

Keep reading

Guides that go deeper on vendor risk

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification