Assessing vendors
Add new vendors to your inventory, run vendor risk and security assessments, and record approval decisions, from first request to ongoing review.
Every vendor you bring on can introduce privacy, security and AI risk. MineOS gives you one place to onboard vendors, assess them, record your decision and keep reviewing them over time. Because vendors live in your inventory, each assessment and risk stays connected to the systems, data and processing activities the vendor touches.
The vendor onboarding lifecycle
Each vendor's status shows where it is in the process:
| Status | What it means |
|---|---|
| Draft | The vendor has been added, but the review hasn't started |
| In evaluation | Assessments are in progress |
| Approved | The vendor passed review and can be used |
| Rejected | The vendor didn't pass review |
You can change a vendor's status at any time from the Details tab on its page.
Third-party risk requirements appear in frameworks worldwide, such as ISO 27001, SOC 2, DORA and NIS2, as well as privacy laws that require due diligence and contracts with service providers. A consistent onboarding process helps you meet them across regions.
Onboard a vendor
1. Add the vendor to your inventory
Go to Data mapping › Inventory and click Add data source. Search the catalog for the vendor and add it. If the vendor isn't in the catalog, create a custom source. See Navigate Your Inventory.
Vendors can also be added automatically from your procurement, ticketing or intake tools. See Automate privacy by design with workflows.
2. Enrich the vendor's details
Click Vendor scout at the top of the vendor's page to research the vendor and fill in details such as data types, hosting locations, certifications and AI use. See Research Vendors with Mira AI (Vendor Scout).
3. Set ownership and business impact
On the Details tab:
- Assign a business owner, the person accountable for the vendor.
- Set the vendor's business impact, which describes how critical the vendor is to your business. Business impact is also needed to calculate the vendor's risk rating.
4. Run the right assessments
Open the assessments the vendor needs, such as a privacy assessment for vendors that process personal data, a security assessment for critical vendors, or an AI assessment for vendors that use AI. MineOS includes ready-made vendor templates in its template catalog. See Creating Assessments.
To complete assessments faster:
- Upload the vendor's documents, such as a DPA, SOC 2 report or security questionnaire, and let Mira AI draft answers from them. See Draft Assessments with Mira AI.
- Invite the vendor or the requester as collaborators to answer the questions only they can. See Collaborating on Assessments.
Change the vendor's status to In evaluation while assessments are in progress.
5. Flag and review risks
Flag the risks your assessments identify, and record any mitigations, such as contractual safeguards or security controls. The vendor's risks appear on its Risks tab and in your risk registry. See Flagging risks in assessments.
Review the vendor's cyber posture rating as part of your decision. See Cyber posture rating.
6. Record your decision
When the assessments are completed, set the vendor's status to Approved or Rejected.
7. Schedule ongoing review
Vendors change over time. Set a review date on the vendor's assessments, so they're reassessed on a regular cadence, for example annually for critical vendors.
Track your vendors
In your inventory, filter by the Vendor risk use case to see only vendors, and by status to focus on vendors that are in evaluation or due for a decision.
Automate vendor onboarding
Once your process is working, you can automate it end to end: adding vendors from procurement or intake requests, running Vendor scout, opening the right assessments, assigning owners and collaborators, and updating the vendor's status when assessments are completed. See Automate privacy by design with workflows.
Related articles
- Cyber posture rating: understand and use a vendor's security score
- Analyze business impact across your data sources: compare vendors by usage, access, data sensitivity and cyber posture
Updated about 1 hour ago
