Uploading a Third-Party’s Security and Compliance Report
Last updated: March 23, 2026
Uploading the vendor’s security and compliance reports (and other documents) gives the TPRM AI Agent the information it needs to analyze the third party and answer your security questionnaire. These uploads are part of the Evidence for the assessment.
When to Use
When you have the vendor’s security documentation, SOC report, or compliance report and want the AI to use it in the assessment.
How to Upload Security and Compliance Reports
Open the third-party detail page from Third Party Risk Management.
Navigate to the Assessments tab and open the draft assessment by clicking the View Assessment button.
Navigate to the Evidence tab.
Use the upload interface to select security and compliance documents (e.g. PDF, DOC, DOCX).
Optionally add a description for each file.
Submit the upload.
The files are added to the evidence list and the TPRM AI Agent can use them to analyze documents and update questionnaire answers.
Note: A SOC 2 or SOC 3 report is required for Critical or High criticality third parties. The assessment checklist will show this step as complete once a document with “SOC 2” or “SOC 3” in the filename has been uploaded.