Skip to content

Entity assessments

An entity assessment is the actual review of a third party. It pairs the commercial context — which entity, which solutions, how critical, by when — with a questionnaire the vendor fills in, and ends with a conclusion you can defend. It is the object the whole third-party section exists to produce.

Third parties → Entity assessments in the sidebar, or the Entity assessments tab on an entity’s page. The list shows Name, Entity, Perimeter, Status, Due date, Criticality, Conclusion and Domain, and filters on all of those.

  1. Click Add entity assessment and give it a Name, a Domain and optionally a Perimeter.
  2. Tick Create audit and choose the Framework that will serve as the questionnaire — a vendor questionnaire from the library, or any framework you have imported. If it defines implementation groups, pick them under Selected implementation groups.
  3. Choose the Entity under review and the Solutions in scope, so the answers describe a defined service rather than the vendor in the abstract.
  4. Set the Criticality and a Due date.
  5. Add the Representatives who will answer, and the Authors and Reviewers on your side.
  6. Save. Open the assessment and use Send questionnaire to invite the representatives by email.

Once the audit exists, the assessment’s Audit field becomes read-only with a jump link to the questionnaire — one assessment owns one audit, and it cannot be swapped afterwards.

The questionnaire is a real audit, but it does not sit in your domain. On creation it is moved into a dedicated third-party workspace — a folder of its own, named after the entity and the assessment, nested under the assessment’s domain. Its requirement assessments and answers move with it, and the representatives are granted the third-party respondent role there and nowhere else.

That containment is what makes vendor access safe: rights granted in the workspace never reach up into the parent domain, so a representative sees their questionnaire and nothing else — not your internal audits, not other vendors, not the domain the assessment lives in.

Respondents log in and answer through the auditee experience, which is a separate surface with its own dashboard rather than a restricted view of your workspace. Answers land in the database as they are typed, so progress is visible live on the third-party dashboard. See Auditee mode and portals.

If your instance cannot be exposed to the vendor, or the vendor refuses to log into a supplier’s platform, the questionnaire can be exchanged as a spreadsheet instead: export the framework to Excel, send it, and import the filled-in file back against the same assessment. Both routes end in the same state — a populated questionnaire with per-requirement answers and observations — and you can use one route for one vendor and the other route for the next.

Fields on the assessment carry the outcome:

  • Status — Planned, In progress, In review, Done or Deprecated, the same lifecycle every assessment uses.
  • ConclusionBlocker, Warning, Ok or Not applicable. This is the verdict the dashboard shows as a coloured badge, and the field a procurement decision actually hangs on.
  • Observation — the reasoning behind the conclusion, and the residual risk you are accepting.
  • Evidence and Reference link — the signed questionnaire, the report, the contract record.
  • Version and ETA — for tracking successive rounds.