Vendors

Troubleshooting & FAQ

This page answers common questions about vendor assessments, risk classifications and questionnaires.

Frequently asked questions

How do I determine the correct risk classification for a vendor?

With the standard vendor assessment, risk classification is automatically calculated based on assessment answers:

High Risk indicators:

  • Full access to sensitive/regulated data
  • Business-critical services
  • Regulated data processing (financial, health, personal data)
  • Organisation-wide scope

Medium Risk indicators:

  • Limited data access
  • Moderate business impact
  • Basic business data processing
  • Department level services

Low Risk indicators:

  • No data access
  • Minimal business impact
  • Physical services only
  • Limited project scope
Tip

Manual adjustment: Correct the classification manually if the automatic classification doesn't fit the business context.

Does finishing a questionnaire approve a vendor?

No. Finishing records the answers and evidence for the vendor, but approval still happens through Approve assessment on the vendor's rating. A finished questionnaire gives reviewers the evidence behind that decision. If a vendor is approved without a finished questionnaire, the assessment records that none was available at the time.

How is the vendor's risk rating set when I use questionnaires?

When your own questionnaires are in use, you choose the vendor's risk rating. It is not calculated from the five built-in answers.

Common problems

Vendor risk classification is not being saved

Complete all mandatory questions first

Still can't figure it out?

Send an email to support@tidalcontrol.com, and we'll get back to you as soon as possible.

Info

Gathering support info: Note which browser you're using, exact error messages, and which steps you've already tried. This significantly speeds up the solution.