Vendor Risk: Work with Evidence Citations
Citations are the specific passages, from uploaded evidence, that the AI used to decide a check’s result. On an evidence-based check, citations are grouped by the result they support, so you can see which evidence passed the check and which indicated a risk. Learn more about controls and checks in Vendor Risk Security Profile
🎵 Before you begin
The information on this page relates to Security Profile in Vendor Risk. You can navigate to a vendor’s Security Profile by following these steps:
- Click the Vendor Risk icon in UpGuard’s left-hand navigation panel.
- Ensure you’re on the Vendors tab.
- Select a vendor (or monitor a new vendor).
- Select Security Profile from the expanded options under the vendor’s name in the left-nav.
Exclude a citation
If a citation is incorrect or shouldn’t be used, you can exclude it so it’s no longer counted as evidence for a check.
- When viewing a check, scroll down to the list of citations.
- Find the citation you want to exclude, and click Exclude citation.
The citation stays visible on the check — grouped with the check’s other excluded citations — but is no longer used as evidence for this check.
Restore a citation
You can bring an excluded citation back into use at any time.
- Navigate to Excluded citations, and find the citation you want to restore.
- Click the three vertical dots (⋮), then click Restore citation.
The citation is counted as evidence for this check again.
See also
- For more on how to review a check and its evidence, see Work with Controls and Checks.
- To learn about adding evidence that citations are drawn from, see Vendor Risk Security Profile: Add Evidence.
- To learn about how UpGuard decides if a check has passed or failed, see Vendor Risk: How a check’s result is determined