Configure Vendor Risk Scoring, Fields, and Documents
Learn how to configure vendor risk scoring, AI-based due diligence, custom fields, and shared documents in Sprinto.
Sprinto’s Configuration tab in the Vendors section allows you to tailor your vendor risk management framework to suit your compliance and operational needs. From defining custom scoring logic to managing metadata fields and documents, the configuration workspace ensures your vendor workflows are aligned with internal policies and industry frameworks.
1. Configure Vendor Risk Auto-Scoring
Sprinto provides a default scoring model that you can customise by editing or adding your own risk factors.
Steps:
Navigate to Data Library > Vendors > Configuration.
Under Vendor Risk Auto-Scoring, click Manage.
Review existing risk factors, such as:
Type of data shared
Operational impact
Access to company systems
To edit a factor:
Click the three-dot menu next to a factor.
Select Edit or Add Value.
To add a new factor:
Scroll to the bottom and click Add Risk Factor.
Choose a response type (single or multi-select).
Define scoring values and save.
2. Enable AI-Powered Due Diligence
Sprinto AI helps you automatically evaluate security documents submitted by vendors.
Steps:
In the Configuration tab, locate the Due Diligence using Sprinto AI section.
Click Manage to see details of AI-supported frameworks (e.g., SOC 2, ISO).
Enable Sprinto AI for supported documents.
3. Manage Custom Fields for Vendors
Custom fields allow you to capture organisation-specific metadata (e.g., business unit, compliance contact, renewal date).
Steps:
In the Configuration tab, scroll to Custom Fields.
Click Manage.
You’ll be redirected to Settings > Custom Fields.
Click Create Custom Field and define:
Field name and type (e.g., dropdown, date, text)
Module (Vendor is selected by default)
Selection values or constraints
Save the field and return to vendor profiles to start using it.
4. Define Shared Vendor Documents
You can predefine a list of documents that must be collected from vendors during due diligence.
Steps:
In the Configuration tab, find the Documents for Vendors section.
Click Manage.
Add, edit, or remove required document types.
Examples: SOC 2 Report, Penetration Test Report, Privacy Policy
Changes apply across all vendors.
Last updated