Assessing Third-parties for Security Review
Last updated: September 10, 2026
Third-party risk assessment in Mycroft is facilitated by the TPRM AI Agent, saving time and effort and helping you complete risk assessments rapidly & with confidence.
The assessment checklist helps guide you through the process (note that you need to be a Business or Security Owner of the vendor to do these tasks):
Create a vendor record by providing the required information on Details page, the TPRM AI Agent automatically initiates Open-source risk data collection to kick-off the risk assessment process
Upload vendor Security and Compliance Reports and any additional evidence for assessment of the vendor (see the list below)
AI Agent will use provided evidence to answer the questions about the vendor and generate a draft Assessment
(Optional) Review the AI Agent questionnaire answers and approve them or send to the vendor to confirm the answers
Flag findings if any answers do not meet the security requirements of your organization
Add flagged risks to your Risk Management Risk Register
Review the assessment and make any changes, if necessary
Finalize the assessment by recommending a decision on the vendor: Approved, Conditionally approved, or Not approved
If Reviewers are assigned to the Third-party, they will need to review and approve the entire assessment before it can be published
Once complete, Publish the risk assessment
After publishing, the vendor decision will be updated on the third-party, and the risk assessment will become visible to auditors
What evidence to collect for Third Party Risk Assessments:
Essential:
SOC 2 Type II (if unavailable, SOC 3)
Privacy Policy
Terms of Service
Data Processing Agreements (for vendors processing your customer data)
Subprocessor list
Beneficial (for critical/high vendors):
Other relevant compliance certifications/reports/questionnaires
Security whitepapers
Pentest reports
Disaster recovery plan/test
Company policies