---
title: Vendor Management in Vanta
description: Vendor Management in Vanta
---

[Skip to content](https://knowledge.sensiba.com/vendor-management-in-vanta#main-content)

English

Show submenu for translations

- Sensiba

Open main navigation

Close main navigation

- Sensiba
- English
  
  Show submenu for translations
- [Go to sensiba.com](https://sensiba.com/)

[Go to sensiba.com](https://sensiba.com/)

 Hi There! How can we help you?

- There are no suggestions because the search field is empty.

1. [Sensiba Knowledge Base](https://knowledge.sensiba.com/?hsLang=en)
2. [Platform](https://knowledge.sensiba.com/platform?hsLang=en)
3. [Vanta](https://knowledge.sensiba.com/platform?hsLang=en#vanta)

# Vendor Management in Vanta

## How to Log, Classify and Manage your Third-Parties

#### **Quick Checklist**

- Add all material vendors to Vanta
- Confirm or adjust risk ratings
- Complete annual security reviews for high-risk vendors
- Document findings and ratings

For more details, visit: [https://www.vanta.com/products/vendor-risk-management](https://www.vanta.com/products/vendor-risk-management) 

#### **OVERVIEW**

Vendor management is a key part of every information security and compliance program. If you use third-party software, cloud infrastructure, or other services, you rely on those vendors to support your security and compliance. Vanta helps automate and simplify vendor management.

**Tip:** Take time to scope and risk score your vendors. This saves time and reduces hassles during audits!

#### **STEP 1: SCOPE YOUR MATERIAL VENDORS**

- Vanta automatically identifies vendors in use. Hover over a vendor and select 'Add vendor' to include it in your register.
- Include all vendors that collect, store, or process sensitive data, or those you depend on for business operations.
- If a vendor isn't automatically identified, add it manually via the 'Add vendor' button on the managed vendors page.

**Tip**: Consider whether all third-party services need to be included. A shorter list allows for greater focus and prioritisation when monitoring and managing them.

**Common vendor types**

- Infrastructure (e.g. AWS)
- Code repository (e.g. GitHub)
- Authentication/SSO (e.g. Okta)
- Workspace software (e.g. Google Workspace)
- Password manager (e.g. 1Password)
- CRM (e.g. Hubspot)
- Communications (e.g. Slack)
- Knowledge management (e.g. ClickUp)
- Compliance management (e.g. Vanta)

#### **STEP 2: CONFIRM OR ADJUST THE RISK RATINGS**

Vanta auto-scores vendors based on data processed, business criticality, and integration.

Adjust these ratings as needed, or set your own risk rating.

Make sure the risk rating matches your business context and risk profile.

**Tip**: Accurate risk ratings help you focus security reviews on higher-risk vendors and save time.

#### **STEP 3: COMPLETE SECURITY REVIEWS**

For vendors rated **High** and **Critical**, complete an annual security review.

Review the vendors security compliance report if available. SOC 2 or SOC 3 reports are easier to access and may be sufficient.

If no compliance report is available, use a security questionnaire (Vanta provides a template).

Document your findings and assign an approved, conditionally approved, or not approved rating.

 

 

- [Platform](https://knowledge.sensiba.com/platform?hsLang=en#main-content)

    - [Vanta](https://knowledge.sensiba.com/platform?hsLang=en#vanta)
    - [Drata](https://knowledge.sensiba.com/platform?hsLang=en#drata)
    - [Scrut](https://knowledge.sensiba.com/platform?hsLang=en#scrut)
    - [Sprinto](https://knowledge.sensiba.com/platform?hsLang=en#sprinto)
- [Best Practices Series](https://knowledge.sensiba.com/best-practices-series?hsLang=en#main-content)

    - [Risk management & internal controls](https://knowledge.sensiba.com/best-practices-series?hsLang=en#risk-management-internal-controls)
    - [Information & communication](https://knowledge.sensiba.com/best-practices-series?hsLang=en#information-communication)
    - [Data protection](https://knowledge.sensiba.com/best-practices-series?hsLang=en#data-protection)
    - [System security](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-security)
    - [Change management](https://knowledge.sensiba.com/best-practices-series?hsLang=en#change-management)
    - [System operations](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-operations)
    - [Control environment](https://knowledge.sensiba.com/best-practices-series?hsLang=en#control-environment)
- [Consumer Data Right Guides](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#main-content)

    - [Network Security](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#network-security)
    - [Vulnerability Management](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#vulnerability-management)
    - [Security Awareness](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#security-awareness)
    - [Anti-malware](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#anti-malware)
    - [Information Asset Lifecycle](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#information-asset-lifecycle)
    - [Access Control](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#access-control)
    - [Governance Requirements](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#governance-requirements)
- [ISO 27001](https://knowledge.sensiba.com/iso-27001?hsLang=en)
- [Control Environment](https://knowledge.sensiba.com/control-environment?hsLang=en)
- [Information and Communication](https://knowledge.sensiba.com/information-and-communication?hsLang=en)
- [Risk Management](https://knowledge.sensiba.com/risk-management?hsLang=en)
- [Vendor Management](https://knowledge.sensiba.com/vendor-management?hsLang=en)
- [System Security](https://knowledge.sensiba.com/system-security?hsLang=en)
- [System Operations](https://knowledge.sensiba.com/system-operations?hsLang=en)
- [Change Management](https://knowledge.sensiba.com/change-management?hsLang=en)
- [Confidentiality](https://knowledge.sensiba.com/confidentiality?hsLang=en)
- [Privacy](https://knowledge.sensiba.com/privacy?hsLang=en)
- [CDR Reps](https://knowledge.sensiba.com/cdr-reps?hsLang=en)
- [Access reviews](https://knowledge.sensiba.com/access-reviews?hsLang=en)
- [Governance](https://knowledge.sensiba.com/governance?hsLang=en)
- [Employee management](https://knowledge.sensiba.com/employee-management?hsLang=en)
- [FAQs](https://knowledge.sensiba.com/faqs?hsLang=en)
- [Sensiba Audit Tools](https://knowledge.sensiba.com/sensiba-audit-tools?hsLang=en)

- Sensiba

[![Sensiba Logo](https://knowledge.sensiba.com/hs-fs/hubfs/Sensiba_Logo_Hubspot-01.png?width=247&height=48&name=Sensiba_Logo_Hubspot-01.png "Sensiba Logo")](https://sensiba.com/)

Copyright © 2026, Sensiba LLP