Skip to main content

Vendor Automated Impact Assessment (New Experience)

Updated this week

💡 Still using the classic Drata experience? Refer to Vendor Automated Impact Assessment for the original UI.

Automated Impact Assessment helps you determine the potential impact a vendor poses to your organization based on how they interact with your data, operations, and environments. Drata uses this assessment to recommend an impact level and guide appropriate security review actions.

Availability

⚠️ Plan requirement: Automated Impact Assessment is available only to customers on the TPRM Pro plan.


Why impact assessment matters

Impact assessment helps you:

  • Consistently evaluate vendor risk during onboarding

  • Prioritize security reviews based on vendor criticality

  • Support audit requirements for vendor risk classification

  • Drive downstream workflows such as review scope and risk creation


When impact assessment occurs

Impact assessment is completed when you:

  • Add a prospective vendor, or

  • Add a new vendor and choose to assess impact

If the assessment is not completed, the vendor’s impact level is marked as Unscored.


Complete an impact assessment

To complete an impact assessment during vendor creation:

  1. Go to Vendors.

  2. Select Prospective vendors or Current vendors.

  3. Select Add vendor.

  4. In the Impact assessment section, select the best-fit options for:

    • Data accessed or processed

    • Operational impact

    • Access to environments

Drata evaluates your selections and displays a recommended impact level.


Recommended vs modified impact level

  • The recommended impact level is calculated automatically based on your inputs.

  • You can override this recommendation if needed.

  • If overridden, the field updates to Modified impact level.

  • You can revert back to Drata’s recommendation at any time.


Operational impact scale

Level

Impact

Description

None

1

No or negligible operational, financial, or reputational impact

Low

2

Limited process disruption, minimal financial or reputational impact

Normal

3

Some reduction in effectiveness, moderate financial or reputational impact

Important

4

Significant disruption to primary processes, measurable financial loss

Critical

5

Loss of mission-critical operations, severe financial and reputational damage


Impact level definitions

Impact level

Description

Insignificant

Minimal loss or damage, no regulatory reporting

Minor

Minor financial loss, limited reputational impact

Moderate

Noticeable process disruption and financial loss

Major

Significant financial loss, regulatory reporting required

Critical

Severe financial loss, regulatory action, major reputational damage

Unscored

Impact assessment not completed

Did this answer your question?