Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideUse factor-based tiering to determine governance intensity, then perform due diligence with versioned questionnaire assessments.
Complete the configured tiering factors for the relationship. PurpleWASP stores the factor inputs, scores and rationale so the recommendation can be reviewed later.
Tier definitions can drive governance expectations such as due-diligence frequency, reassessment frequency, contract review, risk assessment or executive approval.
Review the calculated score and recommended tier, then confirm the tier with an appropriate rationale. Confirmation is a governance decision; it does not change the enterprise Risk Register score.
Select the appropriate questionnaire template and assessment type. The assessment can apply to the whole third party or to a specific service, and later assessments can supersede earlier ones while preserving history.
Assessment questions are copied into the assessment so the issued questionnaire remains stable even if a template changes later. Questions can be required, score-bearing, evidence-required and mapped to PurpleWASP Controls.
Use reviewer status, comments, awarded score and failure indicators to distinguish vendor responses from your organisation's review conclusion. Complete the overall result, risk indicator and reviewer summary only after material responses have been reviewed.
Assessment failures can become TPRM findings. Where the finding represents enterprise exposure, link or create the appropriate Risk Management record instead of using the TPRM tier as the Risk score.
Review the individual factor inputs, weights and rationale before overriding the recommendation. Record the reason for the confirmed tier.
Review the failed question independently. A total percentage can hide a material gap, which should be handled through findings and remediation.
The mapping provides assurance context. It does not automatically mark the organisation Control as implemented or effective.