Vendor Registers
Create vendor registers, map vendors to compliance zones, and perform periodic vendor risk assessments in Sprinto.
Vendor Registers allow you to group vendors and map them to specific compliance zones. This enables structured vendor governance and ensures that vendor risk is assessed in a controlled, auditable manner.
Each register acts as a scoped unit where:
Vendors are grouped
Zones are mapped
Risk assessments are performed
Review history is maintained
Vendor Risk Assessment (VRA) is conducted at the register level, enabling periodic evaluation of vendor risk posture and due diligence status.
How it works
Register creation and mapping
You create a vendor register by:
Defining a name and description
Mapping one or more compliance zones
Selecting vendors to include in the register
Once created, the register becomes the unit for managing vendor risk assessments.
Vendor Risk Assessment lifecycle
Each register follows a periodic risk assessment workflow:
Assessment is triggered
A scheduled assessment appears with a due date
Assessment is initiated
You start the assessment from the register
Vendors are evaluated
Risk classification is reviewed or updated
Due diligence status is verified
Vendors can be included or excluded for the assessment
Assessment is completed
A snapshot of vendor risk posture is recorded
History is maintained
Completed assessments are logged with metadata
Vendor inclusion logic
All active vendors are included by default in an assessment
You can exclude vendors that:
Are not yet onboarded
Are not applicable for the current cycle
Excluded vendors:
Are skipped for the current assessment
Remain part of the register
Are included again in future assessments by default
Features
Create and manage vendor registers
Map vendors to compliance zones
Perform periodic vendor risk assessments
Edit assessment name and scope
Include or exclude vendors dynamically per assessment
Track risk classification across vendors
Monitor due diligence status for high-risk vendors
Resume in-progress assessments
Maintain assessment history with audit trail
Use cases
Compliance segmentation
Group vendors based on regulatory or organisational zones
Audit readiness
Maintain periodic vendor risk assessments with historical records
Risk governance
Track and manage vendor risk posture across business units
Flexible assessments
Exclude vendors that are not relevant for a specific cycle
Due diligence tracking
Ensure high-risk vendors are reviewed appropriately
Operational continuity
Resume incomplete assessments without data loss
Dashboard actions
Create a vendor register
Log in to the Sprinto dashboard.
Navigate to Data Library → Vendors → Vendor registers.

Click Create Register.
In the Register Details panel:
Enter the Name of the register.
Enter a Description (optional but recommended).
Under Zones:
Click the dropdown field.
Select one or more zones from the list.
You can select multiple zones based on your compliance requirements.
Under Vendors:
To select all vendors:
Enable the Select all vendors checkbox.
To select specific vendors:
Uncheck the Select all vendors checkbox.
Manually select vendors one by one from the list.
Click Create Register.

Edit or archive a vendor register
In the Vendor registers tab, select the required vendor register.
Click Edit on the register page.

In the Register Details panel:
Update the Name.
Update the Description.
Modify Zones:
Add or remove zones using the dropdown.
Modify Vendors:
Use the Select all vendors checkbox to include all vendors
Or uncheck it and manually select/deselect specific vendors
Click Save Changes.

Archive a vendor register
Click Archive.

In the confirmation dialog, review the impact message.
Click Archive to confirm.

Perform a Vendor Risk Assessment
Select the required vendor register.
Go to the Vendor risk assessment tab.
Click Start assessment.

On the assessment page:
Review the risk classification summary at the top.
Review due diligence status for high-risk vendors.

Under Assess active vendors:
Review all vendors included in the assessment
Use Edit if you want to Include or exclude vendors from the assessment.

For each vendor:
Verify or update the Risk level.
Review the Due diligence status.
Check associated due dates and evidence files.
Use Filter or search to narrow down vendors if required.
Complete or pause an assessment
Once you have reviewed all vendors:
Click Complete risk assessment to finalise.
If you want to continue later:
Click Resume later.
If the assessment is paused:
It remains in an active state within the register
You can return to the register and click Resume assessment to continue
View assessment history
Log in to the Sprinto dashboard
Navigate to Data Library → Vendors → Vendor registers.
Select the required vendor register.
Go to the Vendor risk assessment tab.
Scroll to the Vendor risk assessment history section.
Here you can view:
Assessment name
Assessment date
Assessed by
Summary (for example, number of vendors assessed)
Summary
Vendor Registers provide a structured way to group vendors and manage them within compliance zones. Vendor Risk Assessments extend this by enabling controlled, periodic evaluation of vendor risk posture.
With support for dynamic vendor inclusion, editable assessments, and resumable workflows, the system ensures both flexibility and audit readiness for third-party risk management.
Last updated

