💡 Still using the classic Drata experience? Refer to Vendor Automated Impact Assessment for the original UI.
Automated Impact Assessment helps you determine the potential impact a vendor poses to your organization based on how they interact with your data, operations, and environments. Drata uses this assessment to recommend an impact level and guide appropriate security review actions.
Availability
⚠️ Plan requirement: Automated Impact Assessment is available only to customers on the TPRM Pro plan.
Why impact assessment matters
Impact assessment helps you:
Consistently evaluate vendor risk during onboarding
Prioritize security reviews based on vendor criticality
Support audit requirements for vendor risk classification
Drive downstream workflows such as review scope and risk creation
When impact assessment occurs
Impact assessment is completed when you:
Add a prospective vendor, or
Add a new vendor and choose to assess impact
If the assessment is not completed, the vendor’s impact level is marked as Unscored.
Complete an impact assessment
To complete an impact assessment during vendor creation:
Go to Vendors.
Select Prospective vendors or Current vendors.
Select Add vendor.
In the Impact assessment section, select the best-fit options for:
Data accessed or processed
Operational impact
Access to environments
Drata evaluates your selections and displays a recommended impact level.
Recommended vs modified impact level
The recommended impact level is calculated automatically based on your inputs.
You can override this recommendation if needed.
If overridden, the field updates to Modified impact level.
You can revert back to Drata’s recommendation at any time.
Operational impact scale
Level | Impact | Description |
None | 1 | No or negligible operational, financial, or reputational impact |
Low | 2 | Limited process disruption, minimal financial or reputational impact |
Normal | 3 | Some reduction in effectiveness, moderate financial or reputational impact |
Important | 4 | Significant disruption to primary processes, measurable financial loss |
Critical | 5 | Loss of mission-critical operations, severe financial and reputational damage |
Impact level definitions
Impact level | Description |
Insignificant | Minimal loss or damage, no regulatory reporting |
Minor | Minor financial loss, limited reputational impact |
Moderate | Noticeable process disruption and financial loss |
Major | Significant financial loss, regulatory reporting required |
Critical | Severe financial loss, regulatory action, major reputational damage |
Unscored | Impact assessment not completed |

