Risk level rules automatically turn your intake form’s answers into a risk level for each vendor. Each rule is a condition, or a combination of conditions, paired with the risk level it should produce. When a submission comes in, Titan AI checks your rules in order, from top to bottom, and assigns the risk level from the first rule that matches. If no rule matches, the vendor gets your default risk level instead.
Before you begin
Risk level rules are built from your vendor intake form's questions, so you'll need an existing form before you can set them up. See Set up vendor intake in Titan AI if you haven't created one yet.
Build a risk level rule
- Go to My Network > Vendor Intake, open the Form builder, and select the Risk level tab.
- Select Add rule, then choose the questions and answers the rule should check. A single rule can check just one question, or combine several, for example "data type shared" AND "business impact", and you can nest a small number of these groups together for more complex conditions.
- Choose the risk level the rule should produce when its condition is met, for example, High.
- Add as many rules as you need, then arrange them by priority. Rules are checked top to bottom, and only the first match is used, so put your most specific conditions above your more general ones.
- Set a default risk level for vendors whose answers don’t match any of your rules.
- Use dry run to test your rules before publishing: select sample answers to see which risk level they’d produce, and adjust the rules or their order if the result isn’t what you expected.
Before you can publish, go to the Access tab and add at least one allowed email address or domain. This is the allowlist of who can use your public form. Once you’ve added one, select Publish form in the header. Publishing makes the form live at its public link and starts collecting submissions; you can unpublish it at any time. Unpublishing takes effect immediately: anyone in the middle of filling out the form when you unpublish will be unable to finish or submit it.
Example
Say your form asks about the type of data shared with a vendor and their business impact. You could set up rules like this:
- If data type shared is PI or sensitive AND business impact is Medium or High, then risk level is High.
- If data type shared is PI or sensitive AND business impact is Low, then risk level is Medium.
- If business impact is High (regardless of data type), then risk level is Medium.
- Default: risk level is Low.
With these rules in place, a vendor who reports sharing sensitive data with a medium business impact matches rule 1 and is scored High, even though they’d also technically satisfy rule 3, it’s never reached because rule 1 came first. A vendor who reports no sensitive data and a low business impact doesn’t match any rule, so they fall through to the default of Low.
The risk level generated by these rules appears on the request when you review it, and carries over to the vendor’s record when you approve the request; you can still adjust it by hand at that point if needed.