An End-to-End Vendor Risk Workflow in TITAN AI
Here’s a walkthrough of a complete vendor risk workflow in TITAN AI, from initial intake through continuous monitoring and remediation.
Step 1: Build the Vendor Intake Form
The workflow starts in vendor intake. You can build a form to send out to different stakeholders across the business, choosing which questions to include and assigning risk scores to each response.
Those risk scores determine how the vendor is classified:
Critical
High
Medium
Low
Step 2: Review the Intake Request
Once the form comes back, you can choose how to review the request. From here you can:
- See responses to the questions you asked, giving you more detail about the vendor being requested
- Send an assessment
Step 3: Set Up the Assessment
To send an assessment, set up a new one by:
- Selecting a template — a standard assessment or any custom assessment you’ve uploaded
- Titling the assessment
- Picking a due date
Once you hit save, the assessment appears on your assessments list.
Step 4: Send the Assessment
When it’s time to send, open the assessment to see the questions going out to the vendor. From here, you can upload existing documentation you already have from the vendor to prefill as much of the assessment as possible. Whatever’s left gets sent to the vendor — select your contact there and hit send.
Back in the assessments view, you can see all active assessments currently out to vendors.
Step 5: Review Assessment Responses
Once a vendor submits an assessment back to you, you can review the responses. Clicking into a questionnaire shows you the results, including where the vendor failed to respond properly.
The AI agent flags areas where the vendor hasn’t submitted sufficient evidence or where their response doesn’t match your policies. You can also view detailed responses to every individual question.
Step 6: Complete the Vendor Intake
Once you’re satisfied with the assessment and the back-and-forth with the vendor is complete, go back into vendor intake and complete the intake. This officially adds the vendor to your vendor directory.
From there, you can view vendor details — many pulled in automatically from the intake form — and fill out additional details ad hoc at any point, or integrate them from a third-party tool.
Step 7: Continuous Vendor Monitoring
Once a vendor is in your directory, TITAN AI continuously monitors them. Anytime a new critical finding emerges — a CVE or other security issue you care about — you’re notified if any of your monitored vendors are affected.
From there, you can drill into findings, see the details, and decide whether remediation is needed.
Step 8: Request Remediation
If remediation is needed, select the finding and request it directly from the impacted vendors. This pulls in any contacts you have on file for that vendor. You can enter a custom message, preview it before it goes out, then save and continue to send.
Step 9: Monitor Widespread Security Events
TITAN AI also monitors for widespread security events that may impact your monitored vendors. You can browse actively occurring security events and click into any one for more detail, including background on the breach and an impact summary based on the vendors you monitor.
In one example, 42 vendors could potentially be impacted by an alleged breach. You can see who those vendors are and how they’re impacted, drill into the technical details of the connection, and reach out directly to request a response — all from the same view.