Assessing Third-parties for Security Review

Last updated: September 10, 2026

Third-party risk assessment in Mycroft is facilitated by the TPRM AI Agent, saving time and effort and helping you complete risk assessments rapidly & with confidence.


The assessment checklist helps guide you through the process (note that you need to be a Business or Security Owner of the vendor to do these tasks):

  • Create a vendor record by providing the required information on Details page, the TPRM AI Agent automatically initiates Open-source risk data collection to kick-off the risk assessment process

  • Upload vendor Security and Compliance Reports and any additional evidence for assessment of the vendor (see the list below)

  • AI Agent will use provided evidence to answer the questions about the vendor and generate a draft Assessment

  • (Optional) Review the AI Agent questionnaire answers and approve them or send to the vendor to confirm the answers

  • Flag findings if any answers do not meet the security requirements of your organization

  • Add flagged risks to your Risk Management Risk Register

  • Review the assessment and make any changes, if necessary

  • Finalize the assessment by recommending a decision on the vendor: Approved, Conditionally approved, or Not approved

  • If Reviewers are assigned to the Third-party, they will need to review and approve the entire assessment before it can be published

  • Once complete, Publish the risk assessment

  • After publishing, the vendor decision will be updated on the third-party, and the risk assessment will become visible to auditors

What evidence to collect for Third Party Risk Assessments:

Essential:

  • SOC 2 Type II (if unavailable, SOC 3)

  • Privacy Policy

  • Terms of Service

  • Data Processing Agreements (for vendors processing your customer data)

  • Subprocessor list

Beneficial (for critical/high vendors):

  • Other relevant compliance certifications/reports/questionnaires

  • Security whitepapers

  • Pentest reports

  • Disaster recovery plan/test

  • Company policies