Skip to main content

Vendor risks (New Experience)

Updated this week

💡 Still using the classic Drata experience? Refer to Vendor Risks & Risk Overview for the original UI.

The Vendor risks page centralizes risks associated with your vendors so you can assess, track, and treat third-party risk in one place.

Vendor risk management is commonly reviewed during audits (such as SOC 2). Drata helps you document identified vendor risks, evaluate impact and likelihood, and track remediation or acceptance decisions over time.


How vendor risk management works in Drata

Vendor risks represent security, compliance, or operational concerns identified during vendor reviews or ongoing monitoring. Examples include:

  • Vendor does not meet internal password or MFA requirements

  • Vendor does not complete penetration testing

  • Vendor does not have a SOC 2 report

  • Vendor lacks required security controls or device management

Each vendor risk is evaluated using impact, likelihood, and treatment status. Risks can be reviewed individually or across all vendors.


Prerequisites

  • Vendor risks are available to customers with TPRM Pro

  • Vendors must exist in Current vendors before risks can be associated


Access vendor risks

To view vendor risks, select Vendors → Vendor risks.

From this page, you can:

  • View all vendor risks across your organization

  • Filter risks by status, impact, likelihood, risk score, owner, or vendor

  • Search for risks by name

  • Download risk data for reporting or audit review

This page provides a consolidated view of your vendor risk posture.


Add a vendor risk

You can add a risk from a vendor profile or directly from the Vendor risks page.

Step 1: Add a risk from a vendor profile

  1. Open Vendors → Current vendors.

  2. Select a vendor.

  3. Open the Risks tab.

  4. Select Add risk.


Step 2: Complete risk details

When adding or editing a vendor risk, provide details to help your team understand the source of the risk, assess severity, and track remediation.

  1. Start by selecting whether the risk is internal (originating within your organization) or external (introduced by a third party such as a vendor or subcontractor).

  2. The vendor will already be selected.

  3. Choose the appropriate risk status to reflect its current stage.

Next, enter the core risk information, including a title, description, the date the risk was identified, and any relevant fields such as category, owner, or supporting documentation.

You can optionally complete an inherent risk assessment by selecting impact (the potential severity if the risk occurs) and likelihood (the probability of occurrence). Drata automatically calculates the overall risk score based on these values.


View vendor risk status

From Vendors → Vendor risks, you can:

  • Track active, closed, and archived risks

  • Monitor overdue or untreated risks

  • Review or update inherent vs residual risk levels

  • Assess overall vendor risk exposure

This view helps prioritize remediation and supports audit evidence.

Did this answer your question?