VeriSAQ

VeriSAQ vendor security assessments for the third-party risk lifecycle

Send a VeriSAQ assessment, let each vendor complete it in a scoped portal, and turn the result into a structured, reviewable part of your vendor risk program — connected to ratings, risk decisions, evidence, and audit history instead of a spreadsheet.

VeriGRC's own vendor security assessment

Chasing vendor security questionnaires over email and spreadsheets is slow to run and hard to prove later. VeriSAQ is VeriGRC's own vendor security assessment, run end-to-end in your workspace — so the result is connected to the rest of your third-party risk program from the start, not reassembled at audit time.

Match the assessment to the vendor

Not every vendor needs the same depth of review. VeriSAQ gives you a family of assessments so you can match how deeply you review a vendor to how much risk that vendor carries — from a fast baseline for low-risk vendors to a comprehensive review for the ones that matter most. When a vendor needs a closer look in a specific area, companion assessments add focused depth alongside any tier.

VeriSAQ Lite

A fast baseline

For low-risk vendors with limited access to your systems, data, or critical business processes.

A streamlined vendor security assessment that covers the essentials without the overhead. VeriSAQ Lite gives you a quick, consistent read on vendors that don't touch sensitive data or critical operations — so low-risk relationships move fast and still get reviewed.

VeriSAQ Core

The standard review

For common SaaS, service provider, technology, and business vendor relationships.

A standard vendor security assessment for vendors with moderate access to your systems, data, or business processes. VeriSAQ Core gives you a balanced review of security, privacy, vendor management, and operational controls — the default for most of the vendors you work with.

VeriSAQ Extended

Most critical vendors

For high-risk or critical vendors with sensitive data access, privileged or production access, customer-impacting services, or significant business dependency.

A comprehensive vendor security assessment that goes deeper across security, privacy, cloud, resilience, and vendor-risk controls. VeriSAQ Extended is built for the vendors whose disruption or compromise would hurt most — the ones that warrant your closest review.

Companion assessments — added depth when you need it

When you need a closer look at a specific area of a vendor's risk, companion assessments layer focused depth onto Lite, Core, or Extended — covering AI systems and AI-related vendor risk, privacy and data governance, cloud and SaaS security, and operational resilience. You assign them alongside a tier when that dimension is in scope, not instead of one.

What you can do

Send the right assessment, let vendors complete it securely, and turn the result into a scored, connected part of your vendor risk picture.

Matched to the vendor

Send Lite for a fast baseline, Core for standard vendors, or Extended for your most critical vendors — matched to how much risk the vendor carries.

Scored in a reviewable workflow

Assessment results can be scored consistently, with supporting context available for your team to review and act on — not just a raw questionnaire to read line by line.

Completed in a scoped portal

Vendors complete their assigned assessment in a secure portal, seeing only the items assigned to them and nothing else in your organization's workspace.

Ready for review

Assessment responses, scoring context, and supporting materials are organized in one place, so your team can review the result before it feeds ratings, risk decisions, and audit history.

Feeds your risk picture

Results can feed vendor security ratings, composite vendor risk scoring, and risk-register decisions — connected on one data model, without manual exports.

Auditable by design

Invitations, submissions, scoring activity, and review history are captured in an append-only audit log behind every assessment, so the history stays reviewable over time.

How a vendor completes a VeriSAQ

From your invitation to a scored result that feeds the rest of your program.

  1. 1

    You send a VeriSAQ assessment

    An authorized user on your team invites the vendor to the VeriSAQ assessment they need to complete.

  2. 2

    The vendor gets scoped access

    The vendor accepts the invitation, sets up access, and signs in with a local login or configured single sign-on.

  3. 3

    They see only what is assigned

    The vendor sees only the VeriSAQ items assigned to them — nothing else in your organization's workspace.

  4. 4

    They answer and attach evidence

    The vendor completes the assessment and uploads supporting evidence directly in the portal, where it stays attached to the record.

  5. 5

    The result is scored and reviewed

    The completed assessment is scored in a structured workflow, with results and supporting context available for your team to review before they feed the rest of your program.

  6. 6

    Results feed your program

    Results can feed vendor security ratings, composite vendor risk scoring, and risk-register decisions — with every step captured in the audit history.

Connected to the rest of your program

VeriSAQ is the assessment step inside third-party risk management. Vendors complete it through the vendor portal, results feed vendor security ratings and risk-register decisions, and the assessment record stays connected to evidence and audit history across the platform.

VeriSAQ — frequently asked questions

What is a vendor security assessment?

A vendor security assessment is a structured review of a third party's security practices, controls, evidence, and risk posture. VeriSAQ provides a branded assessment family that helps teams collect responses, organize evidence, and review results as part of the third-party risk lifecycle.

What assessment tiers does VeriSAQ offer?

VeriSAQ includes tiered assessment options so teams can match the depth of review to the vendor relationship. Current options include Lite, a streamlined baseline for low-risk vendors with limited access; Core, the standard review for common SaaS, service provider, technology, and business vendors with moderate access; and Extended, a comprehensive review for high-risk or critical vendors with sensitive, privileged, or production access, or significant business dependency. Companion assessments add focused depth in specific areas alongside any tier.

How do I choose the right tier for a vendor?

Match the tier to how much risk the vendor carries. Choose Lite when a vendor has limited access to your systems, data, or critical processes. Choose Core for the common vendors with moderate access — the default for most relationships. Choose Extended for vendors with sensitive data access, privileged or production access, customer-impacting services, or significant business dependency. If a vendor needs a closer look in a specific area, add a companion assessment alongside the tier you pick.

How do vendors complete a VeriSAQ?

Your team invites the vendor, who accepts, sets up access, and signs in to a secure portal with a local login or configured single sign-on. The vendor sees only the assigned assessment, completes it, and uploads evidence directly — with every action tracked and auditable.

How is a VeriSAQ scored?

Each assessment can be scored in a structured, consistent workflow, with the result and supporting context available for your team to review and act on — rather than a raw questionnaire to interpret. Scoring results can feed the vendor's security rating and composite vendor risk scoring.

How does VeriSAQ connect to the rest of my vendor risk program?

Because the platform shares one data model, VeriSAQ results can feed vendor security ratings and composite vendor risk scoring, flow into risk-register decisions, and stay connected to evidence and audit history — without manual exports.

Can I add more depth to an assessment in a specific area?

Yes. Alongside any tier, you can assign companion assessments that add focused depth in a specific dimension — covering AI systems and AI-related vendor risk, privacy and data governance, cloud and SaaS security, and operational resilience. Companions are assigned alongside Lite, Core, or Extended when that area is in scope; they add depth to a tier rather than replacing it.

Ready to consolidate your GRC stack?

Book a walkthrough and see third-party risk, compliance, and audit evidence on one platform.