Assessing vendors

Add new vendors to your inventory, run vendor risk and security assessments, and record approval decisions, from first request to ongoing review.

Every vendor you bring on can introduce privacy, security and AI risk. MineOS gives you one place to onboard vendors, assess them, record your decision and keep reviewing them over time. Because vendors live in your inventory, each assessment and risk stays connected to the systems, data and processing activities the vendor touches.

The vendor onboarding lifecycle

Each vendor's status shows where it is in the process:

StatusWhat it means
DraftThe vendor has been added, but the review hasn't started
In evaluationAssessments are in progress
ApprovedThe vendor passed review and can be used
RejectedThe vendor didn't pass review

You can change a vendor's status at any time from the Details tab on its page.

Third-party risk requirements appear in frameworks worldwide, such as ISO 27001, SOC 2, DORA and NIS2, as well as privacy laws that require due diligence and contracts with service providers. A consistent onboarding process helps you meet them across regions.

Onboard a vendor

1. Add the vendor to your inventory

Go to Data mapping › Inventory and click Add data source. Search the catalog for the vendor and add it. If the vendor isn't in the catalog, create a custom source. See Navigate Your Inventory.

Vendors can also be added automatically from your procurement, ticketing or intake tools. See Automate privacy by design with workflows.

2. Enrich the vendor's details

Click Vendor scout at the top of the vendor's page to research the vendor and fill in details such as data types, hosting locations, certifications and AI use. See Research Vendors with Mira AI (Vendor Scout).

3. Set ownership and business impact

On the Details tab:

  1. Assign a business owner, the person accountable for the vendor.
  2. Set the vendor's business impact, which describes how critical the vendor is to your business. Business impact is also needed to calculate the vendor's risk rating.

4. Run the right assessments

Open the assessments the vendor needs, such as a privacy assessment for vendors that process personal data, a security assessment for critical vendors, or an AI assessment for vendors that use AI. MineOS includes ready-made vendor templates in its template catalog. See Creating Assessments.

To complete assessments faster:

Change the vendor's status to In evaluation while assessments are in progress.

5. Flag and review risks

Flag the risks your assessments identify, and record any mitigations, such as contractual safeguards or security controls. The vendor's risks appear on its Risks tab and in your risk registry. See Flagging risks in assessments.

Review the vendor's cyber posture rating as part of your decision. See Cyber posture rating.

6. Record your decision

When the assessments are completed, set the vendor's status to Approved or Rejected.

7. Schedule ongoing review

Vendors change over time. Set a review date on the vendor's assessments, so they're reassessed on a regular cadence, for example annually for critical vendors.

Track your vendors

In your inventory, filter by the Vendor risk use case to see only vendors, and by status to focus on vendors that are in evaluation or due for a decision.

Automate vendor onboarding

Once your process is working, you can automate it end to end: adding vendors from procurement or intake requests, running Vendor scout, opening the right assessments, assigning owners and collaborators, and updating the vendor's status when assessments are completed. See Automate privacy by design with workflows.

Related articles


Did this page help you?