Back to Documentation

Technical Manual

Risk Assessments Guides

In-depth articles and tutorials for risk assessments.

Cybersecurity Assessments

Our Cybersecurity Assessment helps you evaluate your organization's defense against cyber threats comprehensively.

Key Areas Covered:

  • Data Protection & Encryption
  • Network Security & Firewalls
  • Incident Response Planning
  • Employee Training & Awareness
  • Vulnerability Management

Upload your security policies, incident response plans, and network diagrams for AI-powered analysis to get a comprehensive risk score and actionable recommendations.

Third-Party Risk Evaluation

Managing risks from third-party vendors is crucial for maintaining your organization's security posture. RiskShield AI simplifies this complex process.

Vendor Onboarding

Add vendors to your platform via the Vendors page. Enter basic information such as company name, primary contact, industry, and relationship type.

Send Invitations: Use the Third-Party Management page to send secure assessment links to your vendors.

Track Progress: Monitor submission status for each vendor and receive notifications when assessments are completed.

Continuous Monitoring: Track vendor status and schedule periodic re-assessments.

Vendor Status Lifecycle Management

RiskShield AI uses a streamlined vendor status system with three statuses that track each vendor's lifecycle. Understanding these statuses helps you maintain proper oversight, control your active-vendor count, and stay compliant.

Status Definitions

Active: The vendor is currently providing services and is being actively monitored. Only Active vendors can have assessments, questionnaires, and document/evidence requests performed for them. Active vendors are included in all risk calculations, reporting, and monitoring, and they are the only vendors that count toward your plan's active-vendor limit.

Under Review: The vendor is monitored but temporarily gated from new assessment activity — for example while a decision is pending or a relationship is being re-evaluated. While Under Review, new assessments and document requests are disabled; reactivate the vendor to resume that activity.

Inactive: Monitoring is paused and no assessment activity is allowed. Use this when a relationship has ended, a contract has lapsed, or services are no longer needed. Historical assessment data and documents are always preserved. A vendor can be reactivated later, subject to your plan's active-vendor limit at that time.

Status Transitions

  • Active → Under Review: Pause assessment activity while a decision or re-evaluation is pending
  • Active → Inactive: End or pause the relationship (stops monitoring and assessment activity)
  • Under Review → Active: Approve and resume full monitoring and assessment activity
  • Under Review → Inactive: End or pause the relationship after review
  • Inactive → Active: Reactivate the vendor — allowed only if you are within your plan's active-vendor limit

Active-Vendor Limit & Billing

Your plan includes a maximum number of active vendors. Only vendors in the Active status count toward this limit — Under Review and Inactive vendors do not. If you try to activate a vendor when you are already at your limit, RiskShield will prompt you to either set an existing Active vendor to Inactive or upgrade your plan.

To prevent gaming the limit, a vendor that was activated during your current billing period keeps consuming its slot until the period resets, even if you set it to Inactive in the meantime. The slot frees up automatically at the start of your next billing period.

Changing Vendor Status

Only administrators can change vendor statuses. To change a vendor's status:

  1. Navigate to the Vendors page
  2. Click on the vendor to open their details modal
  3. Locate the "Vendor Status Management" card (admin only)
  4. Click the appropriate action button based on current status
  5. Confirm the status change when prompted (deactivating asks you to confirm)

All status changes are automatically logged in the vendor's activity history with timestamp, user, and previous status for audit purposes.

Best Practices

  • Keep Active lists clean: Set vendors to Inactive when a relationship truly ends so your active-vendor count reflects live relationships
  • Use Under Review deliberately: Remember it pauses new assessment activity — reactivate the vendor when you need to run an assessment
  • Document decisions: Use the activity log to capture the reason for significant status changes
  • Plan around billing periods: Because activated vendors hold their slot until the period resets, avoid rapid activate/deactivate cycling
AI-Powered Analysis

Leverage the power of AI to accelerate your risk assessments while maintaining accuracy and compliance.

How it Works:

Document Upload: Upload your organization's policies, procedures, SOC reports, and other relevant documents.

AI Processing: Our AI models analyze the content, extract key information, and match it against assessment questions.

Suggested Answers & Evidence: The AI provides suggested answers with direct quotes from your documents as supporting evidence.

Review & Approve: You review the AI's suggestions, make any necessary edits, and approve the final answers.

This significantly reduces the time and effort required to complete complex assessments.