Skip to main content

Vendor insights (New Experience)

Updated this week

💡 Still using the classic Drata experience? Refer to Vendor Insights Dashboard for the original UI.

The Vendor insights dashboard provides a high-level view of your third-party risk management (TPRM) program. It helps you understand vendor risk posture, review status, and lifecycle health at a glance, and makes it easier to communicate program status to internal stakeholders and auditors.

Prerequisites

Vendor insights are available to customers with TPRM.


Access Vendor insights

To open the Vendor insights dashboard, select Vendors → Vendor insights.

The dashboard displays aggregated metrics across all vendors in your environment. Vendor insights is a read-only overview. It summarizes data from Current vendors, Prospective vendors, and Vendor risks.


Lifecycle overview

The Lifecycle overview section shows vendor counts by lifecycle stage and review urgency. You can view:

  • Active vendors

  • Vendors under review

  • Vendors on hold

  • Flagged vendors

  • Reviews due soon

  • Reviews overdue

Selecting any card redirects you to Current vendors with the corresponding filter applied.

Use this section to quickly identify vendors that require action, such as overdue reviews or vendors currently under evaluation.

Vendor Insights Graphs

The Vendor Insights dashboard includes several graphs that summarize vendor distribution across impact, risk, and key security attributes.

These graphs help you quickly assess overall third-party exposure and identify vendors that may require additional review.

  • Impact Level: Shows how vendors are grouped based on their assigned impact rating. This view helps you understand how significantly your organization could be affected if a vendor were compromised or became unavailable.

  • Risk Level: Shows how vendors are distributed by overall risk classification. Use this graph to identify vendors that may require heightened oversight or more frequent reviews.

  • Type: Categorizes vendors by relationship type. This helps you understand the composition of your third-party ecosystem.

  • Password Policy: Shows how vendors authenticate users. This view can help identify vendors that may require stronger authentication controls.

  • PII Storage: Indicates whether vendors store personally identifiable information. Vendors storing PII may require closer oversight and more frequent review.


Lifecycle status and business units

The final section shows vendor counts by:

  • Lifecycle status: Active, Under review, Approved, Rejected, On hold, Offboarded, Flagged, Archived

  • Business unit: Engineering, Product, Marketing, Customer Success, Sales, Legal, Finance, Administrative, Human Resources, Security

Results are ordered by vendor count to highlight concentration areas.

Did this answer your question?