Vendor onboarding,
a rating before you sign.
Replace the long security questionnaire at the front of every procurement cycle with a rating you can pull in minutes. Check a vendor's posture before the contract, not six months after it.
Vendor Onboarding, step by step
The questionnaire bottleneck
Two hundred questions, several rounds of chasing, and a decision made on the vendor's own self-assessment.
Rate on day one
Add the vendor by domain. The rating and its evidence are ready before your first call with them.
Faster, better-founded decisions
Onboarding stops waiting on paperwork, and the security bar is the same for every supplier.

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out
Security review usually arrives after the decision
In most organisations the vendor security review happens at the point where it can no longer change anything. The business has chosen a supplier, negotiated terms, and set a go-live date. Security is asked to review, and discovers the answer everyone already knows: the review will not stop this.
That is not a governance failure so much as a timing failure. A review that takes six weeks cannot sit inside a procurement cycle that takes four, so it gets moved to the end, where it becomes a formality. Everyone involved knows it is a formality, which is why the questionnaire comes back filled in by someone in sales.
The fix is not more authority for the review. It is making the review fast enough to happen before the decision, when it is cheap to act on.
A rating in 24 hours, from a domain
An external rating needs one input, the supplier's domain, and returns within a day. Nothing to install, nothing to sign, no scheduling with their security team, no waiting for their capacity.
That fits inside a procurement cycle rather than alongside it. You can rate three shortlisted suppliers during evaluation and let posture be one of the inputs to the choice, which is the only point at which it can genuinely influence anything.
It also changes the conversation with the supplier. Arriving at a negotiation with specific, evidenced findings about their external posture is a very different position from asking them to describe it. Findings get fixed before contract signature far more often than after, because before signature you have leverage and after signature you have a renewal date eleven months away.
Not every supplier deserves the same review
The most common failure in vendor onboarding is applying one process to every supplier, which produces a review that is simultaneously too heavy for the stationery vendor and too light for the one processing customer payments.
Rating everything continuously and reserving deep review for what matters is the workable shape. Tier by what the supplier can reach (customer data, production systems, payment flows, the ability to halt operations) rather than by contract value, which correlates poorly with risk. The largest invoice is rarely the largest exposure.
For low-tier suppliers, a rating with alerting is proportionate and it is more than most organisations manage today. For high-tier suppliers, the rating tells you where to point the questionnaire, so the deep review is spent on the things the outside cannot show: access governance, backup testing, segmentation, incident response.
Onboarding is where monitoring should start, not end
The review that happens at onboarding describes the supplier on the day they were onboarded. Everything that follows: the certificate that lapses, the acquisition that brings in unmanaged infrastructure, the subdomain stood up for a campaign and forgotten, happens afterwards, unobserved, until the next annual review or the incident, whichever comes first.
So the useful pattern is to treat onboarding as the moment monitoring begins. The supplier enters the portfolio, the rating refreshes continuously, and a material drop raises an alert against a named owner.
This is also what makes contractual security requirements enforceable. A clause requiring a supplier to maintain a given standard is unenforceable if nobody measures it, and measuring it manually across a hundred suppliers is not going to happen. Continuous rating is what turns that clause from paperwork into a control.
Where a rating fits in the procurement cycle
| Stage | Typical today | With continuous ratings |
|---|---|---|
| Shortlist | No security input | Rate all shortlisted suppliers |
| Evaluation | Questionnaire issued, 4–8 week wait | Posture is an input to the decision |
| Negotiation | Findings arrive too late to use | Specific findings, with leverage to fix |
| Signature | Review closed | Supplier enters continuous monitoring |
| Live | Nothing until next annual review | Alert on material change, named owner |
“We stopped sending questionnaires to small vendors entirely. The rating tells us more, faster.”
Vendor Onboarding | common questions
How quickly can we rate a prospective supplier?
Within 24 hours of supplying their domain. Nothing for them to install, sign or schedule, which is what lets the review happen before the decision rather than after it.
Can we rate a supplier we have not contracted with yet?
Yes. Assessment uses only public information, so no relationship or permission is required. That is precisely what makes it usable during evaluation.
Should we tell the supplier we have rated them?
Most buyers do, and it tends to go well, arriving with specific evidenced findings is a more productive conversation than asking them to self-describe. Findings also get fixed far more often before signature than after.
How should we tier suppliers?
By what they can reach (customer data, production systems, payment flows, ability to halt operations) rather than by contract value. The largest invoice is rarely the largest exposure.
Does a good rating mean a supplier is safe?
It means their external posture is sound. It says nothing about internal controls like segmentation, backup testing or access governance, which is what questionnaires and audit reports are for. Use the rating to decide where deep review is worth the effort.
What happens after onboarding?
The supplier enters the portfolio and is rated continuously, with alerts on material change. Onboarding should be where monitoring starts, not where the review ends.
Where this connects
Third-party risk →
What happens after onboarding: continuous monitoring of the whole portfolio.
RFP filtering →
Using posture as a scored criterion in competitive tenders.
Reports →
Evidence packs for procurement, audit and the supplier conversation.
Put your vendors on the board
Start with ten vendors. Expand when the first alert pays for the year.