Run a Vendor Review with the Drata TPRM Agent and Publicly Available Documents
In this training video, you’ll learn how to use Drata’s TPRM Agent to conduct an end-to-end vendor review, from choosing a document collection path and evaluating evidence against your review criteria to assessing the results. You’ll also learn how to review suggested observations and risks, generate an executive summary, and finalize the vendor decision while keeping your team in control.
Key Takeaways
Start a review using the Drata AI chat.
Examine the different documentation collection paths: public documentation, request Trust Center access, upload evidence, or gather a questionnaire.
Learn how the agent determines assessment results, residual risk, observations, and recommended risks to help finalize the vendor decision.
Run a Vendor Review Using the Drata TPRM Agent and Trust Center Access
In this training video, you’ll learn how the Drata TPRM Agent requests access to a vendor’s Trust Center, collects supporting evidence, and assesses the vendor against your review criteria. You’ll also learn how to review the evidence and residual risk before selecting the final vendor decision based on your organization’s governance process.
Key Takeaways
Use chat to request Trust Center access and provide vendor responses, such as an access link or signed NDA.
Learn how the agent collects documents and stores them under Reports and Documents.
Review the assessment and residual-risk recommendation before making the final vendor decision.
Interpreting the TPRM Agent Assessment Results
This video shows how the TPRM Agent uses criteria tied to a vendor’s inherent risk level to evaluate their security posture and categorize findings. You’ll see a security review in progress, including how criteria roll up into Met, Partially met, Not met, and Inconclusive statuses, and how each result links back to the specific requirements and source documentation the agent used.
The video also covers how to turn findings into tracked risks and leverage follow-up questionnaires to close gaps—highlighting why well-tuned criteria are essential so that every flag the agent raises represents a real issue that deserves your attention.
Key takeaways
Understand how inherent risk levels determine which criteria the TPRM Agent applies in each security review.
Learn how to interpret Met, Partially met, Not met, and Inconclusive results and trace them back to underlying requirements and sources.
See how to create risks and generate follow-up questionnaires so only meaningful, well-aligned findings make it through to your workflow.
