From Months to Weeks: How a Manufacturer Cut Vendor Risk Assessments to Less than 2 Weeks
For most manufacturing organizations, suppliers and service providers are a growing concern. They host data, connect to internal systems, and keep operations running smoothly. And the risk keeps growing.
To keep up, this manufacturer turned to SAFE’s Third Party Risk Management (TPRM) to reduce assessment time, increase coverage, and scale their process globally.
Here’s how they did it!
The Challenge: 200-Question Vendor Security Questionnaires that Took Months
This story begins with a common challenge. The security team took third-party risk seriously, and its process reflected that. Every vendor request arrived by ticket, an analyst found the vendor’s trust center, reviewed its SOC 2 report or ISO certification, and wrote up a recommendation.
The rigor was there. The problem was time. Assessments relied on lengthy security questionnaires that could exceed 200 questions, tracked through spreadsheets and email alongside a security ratings tool. Each review meant sending the questionnaire, waiting, following up, and following up again. A single vendor risk assessment could take one to two months from start to finish.
As the vendor portfolio grew toward 100 essential third parties, the team set a clear goal: keep the same depth of review for the vendors that matter most, and stop spending analyst hours on logistics.
Success At a Glance
- Assessment turnaround: from roughly 1–2 months to 1–2 weeks, depending on vendor risk level
- Coverage: about 90–100 third parties managed in a single view of exposure scores, findings, and remediation
- Follow-ups: no more manually chasing vendors for questionnaire responses
- Scale: full workflow automation lets the program grow without growing the team at the same rate
The Approach: Rebuilding the Vendor Risk Assessment Process Around Tiering
Rather than moving the old process into a new tool as-is, the security team rebuilt it from the ground up in SAFE TPRM, starting with how vendors are classified.
1. A simple, defensible tiering model
The team replaced its previous tiering with three levels, each tied to a clear question about data and dependency:
- High: the vendor hosts, processes, or transmits restricted or regulated company data, or is an operational dependency.
- Medium: the vendor has access to internal or confidential data, or limited integrations.
- Low: the vendor has no access to company data or systems, no integration, and no operational dependency.
Tier questions were captured as custom fields at intake, and each tier maps to an assessment approach, from monitoring only, to light touch, to full assessment and monitoring. That means review depth is decided by risk, not by habit.
2. Workflows that run the process
SAFE workflows now assign each vendor to its tier automatically and trigger the matching assessment. Follow-up reminders go out on their own, and an alert fires when a vendor’s exposure score crosses a set threshold. The team’s time goes to reviewing results, not sending emails.
3. AI-assisted questionnaires and evidence review
AI-managed questionnaires and document review help analysts work through vendor responses and supporting evidence faster, so they can focus on the answers that raise real concerns.
4. One view of every vendor
All third parties now sit in one place, with exposure scores, findings, and remediation status side by side. Issue management gives the team a working vendor risk register, and clear score drivers and notifications make it easier to escalate the right vendors to leadership quickly.
The Results: Vendor Risk Assessments in 1–2 weeks
Assessments dropped from 1–2 months to 1–2 weeks. The biggest change was cycle time. With tiering, automated questionnaires, and built-in follow-ups, a vendor assessment that once took one to two months now takes one to two weeks, depending on the vendor’s risk level.
No more chasing vendors. Automated reminders and AI-assisted questionnaires removed the back-and-forth that used to consume analyst time.
Coverage that scales. With the workflow automated end-to-end, the team can extend coverage across its portfolio without adding headcount at the same pace.
Better, faster decisions. Leadership escalations are now risk-based and backed by clear score drivers, rather than assembled by hand from spreadsheets.
What’s next
The team has set a north star for the program: automate third-party risk, empower continuous visibility, and scale security without limits. Next on the roadmap are deeper automation, including agentic workflows and bulk management of assessments, so that even more of the program runs on its own.
Lessons for other security teams
- Tier by data and dependency. Three tiers tied to plain-language questions are easier to apply consistently than a complex scoring model.
- Match effort to risk. Not every vendor needs a 200-question questionnaire. Monitoring-only and light-touch paths free up time for high-risk vendors.
- Automate the logistics first. Follow-ups and reminders are where assessment time disappears. Automating them delivers the fastest win.
- Keep one source of truth. A single view of scores, findings, and remediation makes escalation and reporting straightforward.
Frequently asked questions
How long should a vendor risk assessment take?
It depends on the vendor’s risk tier. Low-risk vendors with no data access or integrations may need only ongoing monitoring, while high-risk vendors that handle restricted data or support operations need a full assessment. In this case, risk-based tiering and automated follow-ups cut assessments from one to two months to one to two weeks.
How do you tier vendors for third-party risk management?
A practical approach is to tier by data access and operational dependency: high for vendors that handle restricted data or that operations rely on, medium for vendors with internal data access or limited integrations, and low for vendors with no data access or integration.
Can TPRM scale without adding headcount?
Yes, when the process is automated. Automated tiering, questionnaires, reminders, and score alerts let a small team cover a growing vendor portfolio.