Every vendor carries some level of risk before you evaluate their security controls — how critical they are to your operations, what data they touch, and what access they have. That starting point is the vendor's inherent risk.
Drata assigns inherent risk for you. You define the risk levels your organization uses and write the classification guidance that describes how vendors should be tiered — in your own words, or generated automatically from the vendor risk classification policy you already have. When a vendor is added, Drata's AI evaluates that vendor's profile against your guidance, recommends a risk level, and explains its reasoning rule by rule. You keep the final say: every recommendation can be reviewed, overridden, or re-assessed later as you learn more about the vendor.
The result is that new vendors arrive with a consistent, defensible risk tier instead of waiting for manual triage — and the reasoning behind every tier is recorded for your team, your auditors, and your stakeholders.
After following this article, you will be able to:
Define the risk levels your organization scores vendors against.
Write classification guidance, or generate it from your existing risk classification policy.
Test your guidance against real vendors before you save it.
Review, override, and re-assess a vendor's inherent risk level.
Prerequisites
You need permission to manage vendor settings in Drata.
Have your vendor risk classification policy or tiering matrix handy. Drata can read it and generate your rules for you.
Classification guidance changes apply to vendors added going forward. Existing vendor classifications are not re-scored automatically when you edit your guidance. To re-assess a vendor you already have, see Re-assessing a vendor with Drata AI.
Additional Notes:
Risk Rules and Risk levels need to match
How inherent risk classification works
Three pieces work together:
Risk levels — the scale your organization scores against. You can configure up to seven levels and choose the names at Vendor Settings. (Unscored is always available for vendors without an assigned level.)
Classification guidance — a set of rules, each with a name and description, that tells Drata how to classify a vendor. This is where your tiering policy lives. This is configurable at the Vendor Settings
Vendor context — the information on the vendor's profile. Drata reads both structured fields—data and access (data accessed or processed, access to environments, stored data, PII and sub-processor flags) plus business context (category, cost, location, type, integrations)—and free-text fields such as Provided services and Additional notes. A well-written description of what a vendor does carries real weight in the outcome.
When a vendor is added—or re-assessed later—Drata evaluates the vendor's context against each rule, recommends a risk level, and shows which rules applied and why. You can also test this against any vendor in the Preview panel before you save (see Step 3).
Step 1: Define your risk levels
Risk levels apply to both inherent risk and residual risk assessments, so set these up before writing your classification guidance.
Go to Vendors > Settings > Vendor fields.
Find the Risk levels card.
Select Edit.
Edit your levels:
Rename any level by typing directly in its field.
Select Insert risk level to add a level above or below an existing one, up to a maximum of seven.
Select the trash icon to remove a level.
Use the Preview risk levels panel on the right to see how your current vendors are distributed across the levels for both inherent risk and residual risk. This is a useful sanity check before you commit to a change.
Note: Vendors without an assigned risk level appear as Unscored. Unscored is always present and cannot be removed or renamed.
Expected outcome: The Risk levels card on the Vendor fields tab lists your levels in order, with your names and their assigned colors. These names now appear everywhere vendors are scored — the risk level dropdown on each vendor, the inherent and residual risk columns in your vendor list, and the scale shown with every AI recommendation.
Step 2: Configure your classification guidance
Go to Vendors > Settings > Vendor fields.
On the Inherent risk classification card, select Edit.
The Edit inherent risk classification page has two panes: Classification guidance on the left, where you author your rules, and Preview classification on the right, where you test them.
Option A: Generate rules from your risk classification policy
If you already have a tiering policy or risk classification matrix, let Drata build the rules from it.
Select Upload risk classification file.
Select Upload files, or drag your document onto the drop zone.
Select Upload.
Drata reads the document and replaces the rule set with rules derived from your policy — one rule per tier, with the description drawn from your own language.
Expected outcome: The rule list is replaced with one rule per tier found in your document, each named after the tier and populated with a description in your policy's own wording. Uploading a policy overwrites the rules currently in the editor, so review every generated rule — and confirm the tier order — before you save.
Option B: Write or edit rules directly
Author and manage your rules in the guidance editor. Each rule has two fields:
Rule name — a short label, such as Tier 2: High-Risk or Essential Vendors.
Description — the criteria in plain language, up to 1,500 characters. Strong descriptions state what the tier means, give examples of vendor types that belong in it, and describe the assessment, due diligence, monitoring, and risk tolerance expectations for that tier.
Manage the rule set: Select Add rule at the bottom of the list to add one.
Drag the handle (
) at the top-left of a rule to reorder it—rules are evaluated top to bottom, and the highest-positioned matching rule wins.
Select the trash icon to delete a rule.
Bulk-edit as Markdown or JSON: Use the MD / JSON toggle above the list to switch the whole rule set into a single editable text field—the fastest way to bulk-edit, reorder, or move guidance between Drata workspaces. Edit or paste in a revised set (each numbered line becomes one rule, up to 20 rules), then select Apply to convert the text back into individual rule cards.
If a line doesn't become its own rule, check that it's numbered and that you haven't exceeded 20 rules.
Two related controls sit alongside the toggle:
Copy prompt copies your guidance so you can refine it in an AI assistant of your choice and paste the result back in.
Reset to defaults restores Drata's out-of-the-box rule set. This discards your customizations.
Expected outcome: Your rules appear as cards in evaluation order, top to bottom, each showing a character count beneath its description. Nothing is live until you select Save.
Each rule has two fields:
Rule name — a short label, such as Tier 2: High-Risk or Essential Vendors.
Description — the criteria in plain language, up to 1,500 characters. Strong descriptions state what the tier means, give examples of vendor types that belong in it, and describe the assessment, due diligence, monitoring, and risk tolerance expectations for that tier.
To manage the rule set:
Select Add rule at the bottom of the list to add a rule.
Drag the handle at the top-left of a rule to reorder it.
Select the trash icon to delete a rule.
Expected outcome: Your rules appear in the order they will be evaluated, top to bottom, each showing a character count beneath its description. Nothing is live yet — changes take effect only after you select Save.
Step 3: Preview the classification before you save
The Preview classification panel shows how your guidance would score a real vendor, without changing anything.
In the Vendor field, search for and select a vendor.
Drata generates the analysis and returns:
The recommended risk level, shown against your risk level scale.
An Analysis summary explaining the recommendation.
Select Reset to clear the preview and try another vendor.
Tip: Preview against a few deliberately different vendors — one you consider critical, one clearly low-risk, and one with a sparse profile. If the results do not match your expectations, the reasoning text tells you which rule to sharpen.
Expected outcome: You see a recommended risk level for the selected vendor and a rule-by-rule explanation. Nothing about the vendor changes — the preview is read-only, and the vendor's actual risk level is untouched until you save your guidance and the vendor is classified.
Step 4: Add a vendor and review its inherent risk
Inherent risk assessment is the final step of the Add vendor flow.
Go to Vendors > Current and select Add vendor.
On Vendor details, enter the vendor name and describe what the vendor does in Provided services. This description feeds the classification directly, so be specific about what the vendor is used for and what data is involved.
On Internal details, record how your organization uses the vendor: status, type, business unit, stored data, PII and sub-processor flags, integrations, owners, contract value, and any additional notes.
On Risk details, select the Data accessed or processed categories, the Operational impact, and the level of Access to environments.
On Inherent risk assessment, review the recommendation. You can change the level in the Recommended inherent risk dropdown before you finish.
Select Complete.
Tip: The structured fields on Risk details are optional, and Drata can still classify a vendor without them by reading your free-text descriptions. Filling them in gives the AI more to work with and produces a more confident recommendation.
Expected outcome: Before you select Complete, the step shows a recommended risk level positioned on your risk scale, an Analysis summary in plain language, and a Risk guidance applied list showing which rule matched and why each of the others did not. After you select Complete, the vendor is created and its Inherent risk appears in the header summary and on the Inherent risk level card on the Overview tab.
Step 5: Review and override a vendor's inherent risk
Open any vendor and look at the Inherent risk level card on the Overview tab.
To override the recommendation:
Select Edit on the Inherent risk level card.
Choose a different level from the Recommended inherent risk dropdown.
Expected outcome: The vendor's inherent risk changes to the level you chose, and the card keeps a record of the difference — it displays Drata recommends: [original level] alongside a Revert link, so anyone reviewing the vendor can see that a human made a different call. Select Revert at any time to return to Drata's recommendation.
Re-assessing a vendor with Drata AI
Editing a vendor's details — adding an incident to their notes, describing new services they provide — does not automatically change their inherent risk. To re-score the vendor against your current guidance, ask Drata AI.
Open the vendor, then open the Drata AI panel.
To see the guidance that will be used, ask: what are my inherent risk rules?
Ask Drata AI to re-evaluate this vendor, for example: yes assess inherent risk for this vendor [Enter the vendor name].
Review the response. Drata AI states the risk level it believes the vendor should be and explains why.
If you agree, tell Drata AI to apply it, for example: yes please apply.
Drata AI asks for confirmation before making the change. Select Approve to apply the new level, or Decline to leave the vendor as-is.
Expected outcome: After you select Approve, the vendor's Inherent risk updates in the header summary and on the Inherent risk level card.
Example: A vendor added as a marketing asset tool with no data access was classified at the lowest tier. After its profile was updated to describe payroll processing with employee SSNs, no backup provider, and a confirmed breach exposing employee records, re-assessing moved it to the highest tier — because the incident history and service description now matched the top-tier rule. The classification is only as good as the vendor information behind it, so re-assess whenever a vendor's profile materially changes.
Troubleshooting
A vendor is recommended as Unscored or lower than expected. The vendor's profile is probably too thin for the AI to apply any rule. The reasoning text names the missing fields — commonly provided services, data stored, operational impact, access to environments, and category. Fill those in, re-assess with Drata AI, and confirm your guidance includes a fallback rule.
I updated a vendor's details but the risk level did not change. This is expected. Inherent risk is not recalculated automatically when vendor details change. Use Drata AI to re-assess the vendor and apply the new level, or set it manually on the Inherent risk level card.
My guidance changes did not update existing vendors. Also expected. Classification guidance applies to vendors added after the change. Re-assess existing vendors individually with Drata AI.
A vendor matched two classification rules. When a vendor fits more than one rule, the rule listed higher in the list applies. To change which one takes priority, go to the Vendor Settings page, open the classification rules section, and drag that rule higher in the list.
