This guide details how to manage the end-to-end lifecycle of supplier risk within CISO Assistant, from initial questionnaire design to active supplier assessment.1
Define the Requirement Library: Navigate to the Frameworks domain. You can import the RECCo Supplier Information Security Questionnaire (or a similar template) which covers core themes like Governance, Technical Security, and AI Usage.23
Structure Your Sections: For a mature assessment, your template should include the following sections:23
Section A: Supplier and Service Context (Hosting model, data types processed).
Section B: Assurance Basis (ISO 27001, SOC 2, or Cyber Essentials certificates).
Section C: Security Controls (Access control, patching, backups).
Section D: Privacy & GDPR (Data subject rights, international transfers).
Section E: AI Governance (Model training, human oversight).
Mandatory Evidence Fields: To avoid "self-attestation" traps, ensure each question in your template is configured to require an Attachment or URL as evidence.23
If you have existing supplier data in Excel or CSV, use the Data Wizard or the CLICA command-line tool to bulk-import this history.1
Template Preparation: Download the TPRM Excel template from the "Data Wizard" section in the UI.1
Data Mapping: Map your spreadsheet columns to the standard fields:
CLI Import (For Power Users): Run the following command to import your TPRM data:1
uv run clica.py import-tprm --file your-supplier-data.xlsx --folder "Global"
Once your entities and templates are ready, you can initiate a formal assessment campaign.1
Create the Entity Assessment: Link a specific Supplier (Entity) to a Questionnaire (Framework) and a Perimeter.1
Assign the "Actor":1
Navigate to the Assignments page.
Select the relevant requirements for that supplier.
Enter the supplier's email address as the Actor.
The Supplier Experience:
Review & Closing: Once the supplier clicks "Submit," the status changes to Submitted. You can then review their evidence, provide feedback via the "Request Changes" button, or Close the requirement if it meets your standards.1
After the questionnaire is complete, use the platform's decision model to rate the supplier:23
Scoring Model: Rate responses from 0 (Not Implemented) to 4 (Assured).23
RECCo Decision Fields: Mark the final assessment as Accept, Accept with Condition (e.g., "must fix X within 90 days"), or Reject.23
X-Ray Validation: Run an X-ray scan on the supplier's assessment to instantly find "Compliant" answers that are missing the required evidence files.1
This guide provides a comprehensive workflow for managing supplier risk within CISO Assistant, incorporating industry-best practices for evidence validation and scoring.
CISO Assistant allows you to build modular questionnaires. Rather than a static form, you should structure your template to explicitly demand proof, moving beyond "self-attestation."
Requirement Mapping: Ensure every question is mapped to a standard (e.g., ISO 27001 Annex A or NIST CSF) using the Frameworks domain.
Mandatory Evidence Configuration: When creating requirements in the framework editor, enable the "Require Evidence" flag. This forces the supplier to upload a file or link before they can submit.
Core Assessment Sections:
Governance & ISMS: Security policies, ISO 27001 certificates, and Cyber Essentials status.
Operational Security: Vulnerability management, patching logs, and access control policies.
Resilience: Backup schedules, latest restore test results, and Disaster Recovery (DR) plans.
Data Protection (GDPR): Records of Processing Activities (ROPA) and Data Processing Agreements (DPA).
AI Governance: Policies on prompt retention, model training with client data, and human oversight.1
To consolidate your "legacy" data from Excel or Google Sheets into the platform, use the Data Wizard (UI-based) or CLICA (CLI-based).
Via the Data Wizard (Recommended for End Users):
Navigate to the Import section in the sidebar.
Select "Import TPRM".
Download the Excel Template.
Copy your existing data into the template, ensuring the Entity (Supplier Name) and Domain match your CISO Assistant setup.2
Upload the completed file.
Via CLICA (For Bulk/Automated Imports):
Use the command:
uv run clica.py import-tprm --file "legacy_suppliers.xlsx" --folder "Global"
Once your supplier (Entity) is created, you must invite them to complete the assessment.
Launch the Assessment: Create a Compliance Assessment for the specific supplier entity.
Assign Actors: Go to the Assignments page. Select the requirements and enter the supplier's email address as the Actor.2
Supplier Invitation: The platform sends an automated email. The supplier clicks the link to access a scoped dashboard where they only see their specific questionnaire.2
Submission: Suppliers must assess every requirement and attach the necessary evidence. Once complete, they hit "Submit for Review", which locks their view and notifies you.2
To ensure robust assurance, use this checklist when reviewing supplier uploads:
Section
Expected Evidence Artifacts
Information Security
Redacted Security Policy, ISO 27001 SoA, or SOC 2 Type II Report.1
Vulnerability Mgmt
Sample vulnerability scan report and documented remediation SLAs.1
Incident Response
Incident Response Plan (IRP) and a record of the latest tabletop exercise.1
Backups & DR
RTO/RPO definitions and the results of the most recent backup restore test.1
Secure Development
SDLC Policy and evidence of SAST/DAST tool integration in the pipeline.1
AI Usage
List of approved AI tools and prompt-cleansing policy.1
Use the internal review fields to move from a "Description" to a "Decision."
Maturity Scoring (0-4):
0 (Not Implemented): No control exists.
2 (Documented): Policy exists, but evidence of operation is missing.
4 (Assured): Control is implemented, tested, and independently verified (e.g., via audit).1
Final Decision Status:
Accept: Meets all expectations.
Accept with Condition: Minor gaps that must be fixed within a set timeframe (e.g., 90 days).
Reject: Supplier security posture is unacceptable for the risk level.1
Before finalizing a supplier review, run the X-Rays tool on the assessment. It will automatically flag:
Requirements marked "Compliant" that have no attached evidence.
Controls that have expired or are past their review date.
Logical inconsistencies (e.g., a critical supplier with only "Low" impact risks).2
This template is designed for use when a supplier's evidence (e.g., ISO certificates, penetration tests, or policies) fails to meet the "Evidence Quality" standards defined in your TPRM process.1
Subject: Action Required: Evidence Rejection for [Supplier Name] Security Assessment
Dear [Respondent Name],
Thank you for submitting your responses for the [Assessment Name].
Upon review, certain evidence artifacts provided have been rejected. To maintain compliance with our security standards and, please address the following requirements:1
Requirement ID: [e.g., B.1 Certification]
Status: Changes Requested2
Reason for Rejection: [e.g., The provided ISO certificate has expired / The document appears cropped and is illegible].3
Required Action: Please provide [e.g., an alternate document for verification such as a valid ISO 27001 certificate].3
How to re-submit:
Log in to your Auditee Dashboard in CISO Assistant.2
Locate the assignment marked "Changes Requested".2
Review the specific observations for each rejected item.2
Upload the corrected evidence and click "Submit for Review" once all items are addressed.2
Please note that all assigned requirements must be assessed and evidenced before the system will allow a final re-submission.2
Regards,
[Your Name/Role]
[Organization Name] Information Security Team
To minimize re-work, ensure suppliers adhere to these quality benchmarks before submission:
Section
Common Rejection Reason
Mandatory Evidence Standard
Assurance
Expired or out-of-scope certificates.3
Valid certificate with a Statement of Applicability (SoA) explicitly including the contracted service.1
Technical
Self-attestation without proof.1
Redacted Penetration Test Executive Summary or actual tool-generated vulnerability scan reports.1
Resilience
"We have a plan" (Narrative only).
Documented BCP/DR Runbook and a log of the most recent successful Restore Test.1
Privacy
Missing transfer mechanisms.
Signed Data Processing Agreement (DPA) and a list of all geographic hosting locations.1
In CISO Assistant, you can manage this process through the Assignments page:
Request Changes: Use this status to notify the respondent of exactly what needs fixing. The respondent will receive an automated notification.2
Review Responses: Click this link to see the "Respondent's View," ensuring the corrected evidence is visible and correctly mapped.2
Close: Once the "Evidence Quality" is assessed as Strong or Adequate, mark the assignment as "Done" to finalize the review.12
Report Date: Jul 08, 2026
Assessment Period: [Start Date] – [End Date]
Overall Risk Rating: [e.g., Medium / High]
Recommendation: [e.g., Accept with Conditions]
This report summarizes the security posture of [Supplier Name] following their completion of the [Questionnaire Name]. The assessment was conducted via CISO Assistant to ensure a data-driven, evidence-based review.
Current Risk Score: [Score, e.g., 2.8/4.0]
Critical Gaps Identified: [Number]
Evidence Validation Rate: [Percentage]%
Executive Recommendation: The supplier demonstrates a foundational security posture but currently presents a [Risk Level] risk due to insufficient evidence in [Specific Area, e.g., Incident Response]. Access to [Data/System] should be granted only after the conditions in Section 4 are met.
The following critical integrity issues were identified during the automated audit of the supplier's submission:
Finding Type
Observation
Business Impact
Evidence Gap
[Number] controls marked as "Assured" have no supporting documentation.
High: We are currently relying on self-attestation for critical controls.
Stale Certification
The provided [ISO 27001/SOC 2] report expired on [Date].
Moderate: No independent assurance of the current control environment.
Mapping Inconsistency
Supplier claims compliance with [Requirement], but internal policy contradicts this.
Low: Potential misunderstanding of technical requirements.
Performance is rated on a maturity scale of 0 (None) to 4 (Assured).
Governance & ISMS: [Score] – [Brief Insight, e.g., Policies are in place but lack annual review dates.]
Operational Security: [Score] – [Brief Insight, e.g., Patching cycles meet our 30-day requirement.]
Resilience (DR/BCP): [Score] – [Brief Insight, e.g., No evidence of recent backup restoration tests provided.]
AI & Data Privacy: [Score] – [Brief Insight, e.g., Data Processing Agreement (DPA) is fully executed.]
To move this supplier to an "Accepted" status, the following actions are required:
Immediate (Before Go-Live): Provide a valid, in-scope ISO 27001 certificate and the most recent Statement of Applicability (SoA).
Short-Term (30 Days): Upload a redacted executive summary of the most recent penetration test.
Ongoing: Submit the results of the Q3 Tabletop Exercise for Incident Response.
The assessment of [Supplier Name] has been conducted in alignment with the Supplier & Third-Party Risk Management Policy, ensuring proportionality to the sensitivity of the data involved. Final approval is subject to the remediation of "Changes Requested" items within the CISO Assistant platform.1
This comparison allows you to benchmark your current supplier, [Supplier Name], against existing high-criticality vendors in your inventory. This "at-a-glance" view helps management understand where this supplier sits within your overall risk tolerance.
Risk Category
[Supplier Name] (Current)
Tier 1 Provider A (EES)
Tier 1 Provider B (GES)
Benchmark Standard
Maturity Score
[Score]
3.2 / 4.01
1.5 / 4.01
> 3.0 (Target)
Compliance Status
[Status]
Partially Compliant1
Non-Compliant1
Compliant
Critical Gaps
[Number]
101
7+1
0
Evidence Validation
[Rating]
High (Review Pending)1
Low (Missing Certs)1
100% Verified
AI Governance
[Rating]
Verified (No Usage)1
Unassessed1
Fully Disclosed
Based on recent internal reviews of other Enquiry Services providers, several systemic themes have emerged that should be used to contextualize the current assessment:
Proactive vs. Reactive Security: Like many current providers (e.g., EES), there is a trend of performing penetration testing only "upon customer request". [Supplier Name] should be pushed toward a proactive, annual schedule to meet modern security baselines.1
The "Shadow AI" Risk: Previous audits have shown discrepancies where suppliers state no AI usage but utilize 3rd-party AI robustness services. Ensure [Supplier Name] provides specific details on their supporting infrastructure.1
Documentation Gaps: A common failure across the supply chain (notably in the GES audit) is the provision of simple "Yes/No" answers without the mandatory physical evidence (ISO certificates, policies, etc.). No "Assured" rating should be granted to [Supplier Name] without these artifacts being uploaded to the Applied Controls section.1
Sub-processor Oversight: Ensure the same level of scrutiny applied here is extended to any sub-processors (like Correla Limited in other service areas), verifying that contractual security alignment is backed by operational evidence.1
Run X-Ray Analysis: Execute the "Evidence Integrity" and "Review Staleness" X-rays within the platform to confirm no requirements were closed without valid documentation.2
Cross-Framework Mapping: If this supplier supports your ISO 27001 goals, use the Apply Mapping tool to automatically seed their responses into your internal audit, identifying immediate gaps in your certification readiness.
Final Risk Acceptance: Once remediation is verified, use the Review Submissions workflow to formally "Close" the assessment and record the final risk decision.