Configure Vendor Risk Scoring, Fields, and Documents
Learn how to configure vendor risk scoring, AI-based due diligence, custom fields, and shared documents in Sprinto.
Sprinto’s Configuration tab in the Vendors section allows you to tailor your vendor risk management framework to suit your compliance and operational needs. From defining custom scoring logic to managing metadata fields and documents, the configuration workspace ensures your vendor workflows are aligned with internal policies and industry frameworks.
1. Configure Vendor Risk Auto-Scoring
Sprinto provides a default scoring model that you can customise by editing or adding your own risk factors.
Steps:
Navigate to Data Library > Vendors > Configuration.
Under Vendor Risk Auto-Scoring, click Manage.

Configure the Vendor risk factors by:
Enabling/Disabling the risk factor by using a toggle.
Add a new risk factor value by adding value name, score and description.
Edit Risk factor value, description and score.
Archive the risk factor value

To add a new factor:
Scroll to the bottom and click Add Risk Factor.

Choose a response type (single or multi-select).
Define scoring values and click Add.

2. Enable AI-Powered Due Diligence
Sprinto AI helps you automatically evaluate security documents submitted by vendors.
Steps:
In the Configuration tab, locate the Automate Due Diligence using Sprinto AI section.
Click Manage to see details of AI-supported frameworks (e.g., SOC 2, ISO).
Enable Sprinto AI for supported documents.
3. Manage Custom Fields for Vendors
Custom fields allow you to capture organisation-specific metadata (e.g., business unit, compliance contact, renewal date).
Steps:
In the Configuration tab, scroll to Custom Fields.
Click Manage.

You’ll be redirected to Settings > Custom Fields.
To learn about this in detail refer to the Custom Fields document.
4. Define Shared Vendor Documents
You can predefine a list of documents that must be collected from vendors during due diligence.
Steps:
In the Configuration tab, find the Documents for Vendors section.
Click Manage.
Add, edit, or remove required document types.
Examples: SOC 2 Report, Penetration Test Report, Privacy Policy
Changes apply across all vendors.

Last updated