Vendor Risk: Additional evidence documents
- What is additional evidence?
- Upload a document
- Request documents from your vendor
- Document statuses
- Capture identified risks
- Convert an existing document to additional evidence
- Download, archive, or delete a document
What is additional evidence?
Additional evidence lets you capture security and compliance documentation for a vendor — audit reports, certificates, completed security questionnaires — and record any risks you identify in it. Those risks can feed the vendor's risk profile and support your risk assessments.
⛔ You must be monitoring a vendor before you can capture additional evidence for it. To learn more, see Monitor a new vendor.
Upload a document
- Click Vendors under Vendor Risk in the left-hand navigation panel.
- Click the vendor you want to capture evidence for.
- Click Additional Evidence.
- Click Click to upload new documents, or drag and drop your files into the box.
You can upload several documents at a time. Each file can be up to 5 MB.
Once a document is uploaded, add its classification details:
- Name — by default, the name of the uploaded document with the date appended to the end.
- Document type — a questionnaire, SOC 1 or SOC 2 report, ISO 27001 certificate, audit report, penetration test, or breach or incident disclosure.
- Expiry date — for example, the expiry date of a compliance report or certificate.
- Comments — click the comments section to leave notes on the document.
🎵 Add your own document types in Settings > Vendor Management.
Request documents from your vendor
Request evidence directly from a vendor so they can upload documents to UpGuard themselves, instead of you collecting them outside the platform.
- Navigate to Vendor Risk > Vendors > [your vendor] > Additional Evidence.
- Click Request documents.
- Select the document types you want the vendor to share. You can add several documents to a single request, and mark any of them as high priority.
- Assign the recipients in the vendor's organization who should respond to the request.
- Configure the message that goes to the vendor with the request.
The documents you requested appear in your additional evidence list with the status Requested. When the vendor uploads one, you can open it to review it, edit its details, and add comments, then mark it Active.
🎵 Set a default request message in Settings > Templates.
Document statuses
Additional evidence documents can carry the following statuses:
| Status | Meaning |
| Requested | You've asked the vendor for this document and they haven't uploaded it yet. |
| Ready to review | The vendor has uploaded the document in response to your request, and it is waiting for your review. |
| Active | The document has been reviewed and marked as active. |
| Archived | The document has been archived. It is no longer available for risk assessments, and any risks identified on it no longer appear in the vendor's risk profile. |
Capture identified risks
Once you've reviewed a document, record any risks you found in it.
- Click Add risk on the reviewed document.
- Choose an existing risk type, or create a new one: click the observation text box, type your risk, and click create.
- Enter the impact or consequence of the risk, and its severity.
- Click Add Risk.
- Repeat for each risk you identified in the document.
You can edit or delete risks at any time after adding them.
Include or exclude identified risks
Toggle the option to the right to include a document's identified risks in the vendor's risk profile. Included risks:
- Show their finding, severity, and impact in the vendor's risk profile.
- Can be cited as supporting evidence in a risk assessment.
- Can be managed from the risk profile page, where you can request remediation from the vendor and waive risks.
Convert an existing document to additional evidence
Convert a general document or a questionnaire response into additional evidence so you can classify it, add risks to it, and use it in your vendor risk assessments.
- Navigate to: Vendor Risk > Vendors > [your vendor] > Documents.
- Click the three-dot icon on the document you want to convert.
- Select Convert to Additional Evidence.
- Classify the document and add any detail.
- Click Convert.
The document is added to the vendor's Additional Evidence page, where you can add and manage its risks.
Download, archive, or delete a document
You can download, archive, and delete the documents on a vendor's Additional Evidence page. Each document row has three icons at the right-hand end of the table: Download, Archive, and Delete.
- Navigate to: Vendor Risk > Vendors > [your vendor] > Additional Evidence.
- Click the Documents tab.
- Click Active or Archived, depending on which documents you want to work with.
- Click the Download, Archive, or Delete icon on the document's row. On the Archived tab, Archive is replaced by Unarchive.
🎵 To handle several documents at once, select the checkbox beside each one — or click the arrow beside the checkbox in the table header and choose All or None — then use the buttons in the action bar at the bottom of the page.
Bulk actions are available on the Documents tab only, not under Security and privacy pages.
When a document can't be downloaded or deleted
- A document with no file attached can't be downloaded. One still at the Requested status is the usual case, because the vendor hasn't uploaded anything yet. If you’ve selected several documents, Download shows how many of them have a file — for example, Download (11/12) — and is unavailable if none do.
- Shared documents can't be deleted, so their Delete icon is unavailable. Shared documents show UpGuard in the Source column. If you have selected several documents, the action bar tells you how many can't be deleted and offers Deselect shared documents to drop them from your selection so you can delete the rest.
❗ Deleting a document can't be undone.
Some documents are also evidence sources in the vendor's Security Profile. The confirmation dialog tells you when one of these is involved. Archiving or deleting it removes the matches and citations that rely on it.
What happens when you archive
Archived documents move to the Archived tab and their status changes to Archived. They stay available to download, and you can return them to the Active tab at any time with Unarchive.
❗ Archiving a document removes it from further risk assessments, and any risks identified on it stop appearing in the vendor's risk profile.
🎵 The Documents tab count covers both active and archived documents, so it doesn't change when you archive something.
See also: