Entity assessments
An entity assessment is the actual review of a third party. It pairs the commercial context — which entity, which solutions, how critical, by when — with a questionnaire the vendor fills in, and ends with a conclusion you can defend. It is the object the whole third-party section exists to produce.
Where to find it
Section titled “Where to find it”Third parties → Entity assessments in the sidebar, or the Entity assessments tab on an entity’s page. The list shows Name, Entity, Perimeter, Status, Due date, Criticality, Conclusion and Domain, and filters on all of those.
Running a review
Section titled “Running a review”- Click Add entity assessment and give it a Name, a Domain and optionally a Perimeter.
- Tick Create audit and choose the Framework that will serve as the questionnaire — a vendor questionnaire from the library, or any framework you have imported. If it defines implementation groups, pick them under Selected implementation groups.
- Choose the Entity under review and the Solutions in scope, so the answers describe a defined service rather than the vendor in the abstract.
- Set the Criticality and a Due date.
- Add the Representatives who will answer, and the Authors and Reviewers on your side.
- Save. Open the assessment and use Send questionnaire to invite the representatives by email.
Once the audit exists, the assessment’s Audit field becomes read-only with a jump link to the questionnaire — one assessment owns one audit, and it cannot be swapped afterwards.
The third-party workspace
Section titled “The third-party workspace”The questionnaire is a real audit, but it does not sit in your domain. On creation it is moved into a dedicated third-party workspace — a folder of its own, named after the entity and the assessment, nested under the assessment’s domain. Its requirement assessments and answers move with it, and the representatives are granted the third-party respondent role there and nowhere else.
That containment is what makes vendor access safe: rights granted in the workspace never reach up into the parent domain, so a representative sees their questionnaire and nothing else — not your internal audits, not other vendors, not the domain the assessment lives in.
How the vendor answers
Section titled “How the vendor answers”Respondents log in and answer through the auditee experience, which is a separate surface with its own dashboard rather than a restricted view of your workspace. Answers land in the database as they are typed, so progress is visible live on the third-party dashboard. See Auditee mode and portals.
If your instance cannot be exposed to the vendor, or the vendor refuses to log into a supplier’s platform, the questionnaire can be exchanged as a spreadsheet instead: export the framework to Excel, send it, and import the filled-in file back against the same assessment. Both routes end in the same state — a populated questionnaire with per-requirement answers and observations — and you can use one route for one vendor and the other route for the next.
Closing the review
Section titled “Closing the review”Fields on the assessment carry the outcome:
- Status — Planned, In progress, In review, Done or Deprecated, the same lifecycle every assessment uses.
- Conclusion — Blocker, Warning, Ok or Not applicable. This is the verdict the dashboard shows as a coloured badge, and the field a procurement decision actually hangs on.
- Observation — the reasoning behind the conclusion, and the residual risk you are accepting.
- Evidence and Reference link — the signed questionnaire, the report, the contract record.
- Version and ETA — for tracking successive rounds.
Related
Section titled “Related”- Overview — the dashboard where these assessments are tracked.
- Entities and Representatives — the prerequisites.
- Audits — the questionnaire is an audit, with all the same mechanics.
- Auditee mode and portals — the respondent’s side.
