Skip to content
  • There are no suggestions because the search field is empty.

Vendor Risk: Work with Controls and Checks 

Controls and checks let you see how a vendor is performing against the criteria in their assigned control template.

🎵 A check can map to more than one framework or control at once. Updating a check's status (for example, marking it passed, waived, or N/A) updates it everywhere it's referenced.

Search and filter controls and checks

  1. Click Vendor Risk in UpGuard’s left-navigation.
  2. Select a vendor.
  3. Select Security Profile from the expanded navigation.
  4. Make sure you’re on the Controls and checks tab.
  5. Select Controls or Checks. Click a check to see more information, including the frameworks it maps to.
  6. Search or filter:
    1. To search: use the search box at the top of the controls and checks section
    2. To filter: click Apply filters and select the appropriate filters.

🎵 Filters you apply stay in place as you move between individual checks, so you keep your place while reviewing checks one at a time.

 

Review checks (check evidence, request remediation, waive risks)

From the Checks view, you can inspect citations for any evaluated check, request remediation for detected risks, or waive a risk if it’s not applicable.

  1. Vendor Risk > Vendors > select a vendor > Security Profile.
  2. Select the Controls and checks tab.
  3. Switch to the Checks view. 
  4. For all risks (except those with No evidence): click into the check to see the citation(s) referencing the specific text, from uploaded Evidence, that was used to reach this result.
  5. Click Manage risk on checks where a risk is detected.
  6. Select Request remediation or Waive this risk. Each option takes you to the corresponding workflow: either risk remediation or risk waiver.

🎵 If you find that a citation is incorrect or shouldn’t be used, click Exclude citation so that it doesn’t get used. For more information, see Vendor Risk: Work with Evidence Citations.

🎵 When more than one source of evidence applies to a check, UpGuard combines them to reach one result. For how that works, see Vendor Risk: How a check’s result is determined.

View a check’s timeline

The timeline records key changes to a check over time, so you can see what’s happened to it since it was first evaluated.

    1. Go to Vendor Risk > Vendors > select a vendor > Security Profile.
    2. Select the Controls and checks tab
    3. Switch to the Checks view.
    4. Select a check you want to learn more about.
    5. Click Timeline.

    🎵 The timeline is available on evidence-based checks only for now.

    Events the timeline can show include:

    • a risk being detected on the check
    • the check being marked passed or not applicable (including when its control is marked not applicable)
    • evidence being added that passes the check, including new citations
    • a citation being excluded or restored
    • remediation activity on the check

    Mark controls and checks as not applicable

    Mark controls and checks as N/A when a particular vendor should not be evaluated against a control or check in their assigned control template. Alternatively, you can apply a different control template, create a custom template or edit templates.

    1. Vendor Risk > Vendors > select a vendor > Security Profile.
    2. Ensure Controls and checks is selected.
    3. For controls: click the vertical ellipsis on a control’s row and click Mark as N/A > Yes, mark as N/A.
    4. For Checks: click the box next to a check and click Mark as N/A > Yes, mark as N/A.

    When controls that are marked as N/A:

    • That vendor is no longer assessed against that control and all checks are marked as n/a. If a check is associated with multiple controls, it is marked as N/A in all controls.
    • N/A controls are hidden by default, but you can adjust filters to see them again.

    When checks that are marked as N/A:

    • That vendor is no longer assessed against that check.

    Any risks associated with the control remain visible on Risk Profile.

    Bulk actions

    1. Vendor Risk > Vendors > select a vendor > Security Profile> Controls and checks tab>Controls or Checks view.
    2. Click the check box next to each check you want to select.
    3. Bulk action options will appear. Different actions are available on different checks. The bulk action options you see are determined by the checks you select.
    4. Follow the prompts to complete your action.