This feature is currently in Early Access. Learn how to turn it on for your organization here.
The vendor intake workflow gives Vendor Risk Managers (VRMs) a consistent, self-service way to onboard new vendors. Instead of collecting details through ad hoc emails, you build a standard intake form and share it with business partners in your organization. When a partner completes the form, the vendor is added to the Intake tab for your review, and the answers populate the Vendor System of Record (VSOR) automatically. This reduces manual data entry and miscommunication, and helps you tier vendors and act faster.
Before you begin
This feature is available to organizations that have access to the All Companies page. Access to set up and manage the intake form is limited to the Customer Admin role.
If you plan to map questions to custom vendor fields, create those fields first so they appear in the mapping dropdown as you build the form. Optionally, create the questionnaire templates you want to send by risk tier — you need these only if the platform should send a questionnaire based on a vendor's tier.
Set up the vendor intake form
You can manage the intake form by going to Companies > All Companies. An intake button shows the current status of your form: a gray dot means the form is not yet set up, and a green dot means the form is active. Select the button to open the intake panel.
Create and configure questions
The form ships ready to use, with a set of default questions and default scoring already applied.
Select Add question to create a custom one, or the edit tool on any question to open the question edit modal, where you can:
- Edit the question text.
- Turn Affects inherent risk on or off, and mark whether an answer is Required.
- Map the answer to a VSOR field so responses are stored on the vendor record; a field maps to only one question.
- Under Scoring, assign points (including negative values) to each answer option to set how much it adds to the vendor's inherent risk score. The tiers it maps to are configured separately, in the Inherent risk panel.
In the questions table, you can reorder, edit, or remove any question. Most teams adapt the form to their program by adjusting the answer options and point values on the default fields, or by creating new VSOR fields and mapping questions to them. A newly created field appears in the mapping dropdown once you refresh the form.
Every form also includes a system-owned question that asks the business partner for a vendor contact email. Unlike the other questions, this one creates a contact record for the vendor instead of mapping to a VSOR field, and its mapping is locked. You cannot delete it, but you can hide it. When hidden, it does not appear on the form, and no contact is collected. This contact prepopulates the recipient when you later send a questionnaire.
Set risk tiers and questionnaire templates
In the Inherent risk panel, select Edit to define the normalized score range (0-100) for each of the four risk levels, Low, Medium, High, and Critical, and choose the questionnaire template to send to vendors in each tier. Select Save to keep your changes; closing the panel without saving discards them. To learn how scores are calculated, see About inherent risk scoring
Mapping a questionnaire template to each tier is not preconfigured and must be set before you use the form. It lets the platform tier an incoming vendor and send the right assessment automatically. You can use a different template per tier, reuse one for every tier, or leave a tier blank to skip it, such as low-risk vendors. Only templates you already created appear in the dropdown, so create them first.
Publish and share the form
Before you publish, select Access and sharing to add the email domains allowed to open the form; you must add at least one. Select Publish to make the form active and generate the shareable URL.
Note: The URL is a permanent, reusable link. Share the same link with everyone rather than generating a new one per vendor, so you can post it in an internal channel such as Slack or a process document. Business partners do not need a SecurityScorecard account; the domain verification step gives them access.
How business partners complete the form
When a business partner opens the shared URL, they enter their work email and will receive a six-digit verification code by email if the domain is on your allowed list. After verifying the code, they select the vendor organization, answer the questions, and submit.
Review submissions in the Intake tab
You can review completed submissions in the Intake tab found on the All Companies page. Every vendor submitted through the form is added automatically as a partially monitored company.
Select a vendor to open a panel showing the vendor's automatically calculated inherent risk tier, when and how they were added, and the submitted answers you can review and edit.
When viewing a vendor in the table, select Take action to open a list of actions you can take on the vendor: add contacts, add to a portfolio, send a questionnaire, view company details, mark the vendor as read, or remove it from intake.
When you are ready to start assessing the vendor, select Send questionnaire. The Questionnaires page opens with the vendor, the recipient (from the vendor contact), and the template (from the vendor's tier) already filled in, ready to send.
Get notified about new submissions
You have three ways to know when a new vendor arrives:
- A count badge on the Intake tab shows how many vendors you have not viewed, and unseen rows are visually distinguished. Opening a vendor's flyout marks it as seen for everyone in your organization.
- An in-app notification links you directly to the Intake tab.
- An email notification includes the vendor name and a link to the Intake tab.
All users in roles eligible to access the Intake tab receive these notifications. You can opt out of emails in your notification preference settings.