Configuring Evaluation Criteria & Inherent Risk
This video walks through how to review and tailor Drata’s TPRM Agent criteria so your vendor security assessments reflect your organization’s real-world expectations. You’ll learn how criteria and their underlying requirements work together, how they map to inherent risk levels, and why it’s important to refine the default set of 45 criteria provided by Drata’s GRC team.
The video also shows how to edit existing criteria and Expected Response Guidance in the criteria table, adjust mapped risk levels, and use the TPRM Agent to generate new criteria from a past questionnaire so your assessments stay aligned with your own review standards.
Key takeaways
Understand how criteria, requirements, and inherent risk levels shape AI-driven vendor assessments.
Learn how to edit default criteria and Expected Response Guidance to match your security expectations.
See how to generate custom criteria from past questionnaires using the TPRM Agent.
