Vendor Risk: How a check’s result is determined
What is a check?
A check is a specific criterion a vendor is evaluated against in their Security Profile. UpGuard evaluates each check against the evidence available and either marks it as pass or fail (and assigns a severity).
For evidence provided as documents, UpGuard uses AI to read the evidence, match it to each check, and produce the citations behind the result. You stay in control of what's used; you can exclude a citation you don't agree with, or manually mark a check as passed or not applicable. Learn more about controls and checks in Security Profile
How UpGuard determines if a check has passed
A single check can be informed by more than one source of evidence, and those sources don’t always agree. UpGuard combines them in a set order of precedence to reach one result for the check.
| Source | How it affects the check result |
| Documents | These are policies, audit reports, and other evidence you or the vendor provide. When several documents address the same check, UpGuard detects a risk if even one of them indicates the check has failed — regardless of how many other documents indicate it’s passed. |
| Gap questionnaire answers | Where a gap questionnaire answer addresses the check, it takes precedence over document evidence for that check. |
| Trust Center data | If the vendor has published a result for this check on their Trust Center, that result determines the check’s outcome — overriding document and gap questionnaire evidence, whether the published result is a pass or a risk. |
| Manual override | If you manually mark a check as passed or not applicable, your decision applies and takes precedence over every other source above. |
See also
- Work with Controls and Checks
- Vendor Risk: Security Profile
- Vendor Risk Security Profile: Add Evidence