The Vendor Directory provides a centralized place to store and manage the vendors your organization works with. It serves as the system of record for your third-party ecosystem, allowing Vendor Risk Managers to maintain an accurate vendor inventory and monitor their risk posture from a single location.
Each vendor record represents an organization your company works with. Vendor records are connected to SecurityScorecard's repository of legal entities, allowing the platform to surface the scorecards and risk intelligence associated with that organization.
Using the Vendor Directory helps teams:
Maintain a centralized inventory of vendors.
Monitor security intelligence associated with vendor organizations.
Track vendor onboarding and offboarding status.
Access vendor profiles and related monitoring data.
Vendor contact data
Vendor records may include contact information associated with the organization. Contact data can originate from:
Contacts maintained by your organization
Contact information maintained by SecurityScorecard
Depending on the source, some contact fields may be editable while others are managed automatically.
Understand the vendor directory table
The Vendor Directory displays vendors in a table that summarizes key information about each organization.
Each row represents a vendor and includes information to help you identify vendors that require attention, such as those with outstanding observations or those still undergoing onboarding.
The table includes the following columns by default:
Vendor: Vendor's company name, logo, and domain.
Risk: A shape icon indicating the vendor's assigned risk level (e.g. Low, Medium, High).
Monitored: Yes/No indicator of whether the vendor is actively monitored.
Data types shared: Badge tags showing the categories of data shared with this vendor (e.g. PII, PHI).
Status: The vendor's relationship status in your program (New, Initial assessment, Onboarded, or Off-boarded).
Business impact: A shape icon indicating the vendor's assessed business impact level.
Access type: Comma-separated list of the vendor's access methods (e.g. System application access, Network level access).
Groups: Badges showing which vendor groups this vendor belongs to (up to 2 visible, then a +N overflow badge).
- Portfolio: The portfolio(s) the vendor is associated with.
- Vendor ID: The unique identifier for the vendor record.
- Contract value: The value of your organization's contract with the vendor.
- Contract end date: The date the vendor contract ends.
- Coworker contact: The internal teammate assigned as the point of contact for this vendor.
- External vendor contact: The point of contact at the vendor organization.
Updated: Date the vendor record was last modified.
Date added: The date the vendor was added to the directory.
Some accounts may also see additional columns, such as Score and Tags, depending on enabled features. You can customize which columns are visible from the table's column settings.
Vendor relationship status
Each vendor in the directory has a status that indicates the current state of your organization's relationship with that vendor.
New: The vendor has just been added to the directory and has not yet started onboarding.
- Initial assessment: The vendor has been added and is undergoing onboarding or assessment activities, but has not yet completed them.
Onboarded: The vendor has completed onboarding and is actively monitored.
Off-boarded: The vendor relationship has ended, and the vendor is no longer actively monitored.
Manage vendors in the directory
Keeping the Vendor Directory up to date ensures that monitoring, assessments, and vendor communications remain tied to the correct organizations.. You can perform several actions directly from the Vendor Directory.
Select the Row actions (...) icon for a vendor to:
View full profile: Open the vendor's detailed profile to review risk information and monitoring data.
- View Scorecard: Open the vendor's scorecard.
- Set tags: Assign or update tags on the vendor. This option is available if your organization has tag management enabled.
Delete: Remove the vendor from the directory.
To act on multiple vendors at once, select their checkboxes. A toolbar appears at the bottom of the table with Offboard vendor and delete options, plus a … menu with Set tags and Start monitoring.