It is a structured review of a vendor’s security controls to judge the risk they pose before and during a business relationship. It usually involves gathering evidence such as SOC 2 or ISO 27001 reports and questionnaires, comparing them to your requirements, and assigning a risk rating. AI-driven platforms now automate much of this so assessments take minutes instead of weeks.
