Documents and evidence
Questionnaires, certificates, audit reports and contracts: everything a provider claims about itself, in one place instead of four.
Vendor risk means assessing what a provider promises and showing what the assessment rests on. This domain runs on the Leapfacto engine today; the four use cases below build on each other.
A vendor risk assessment is only as good as the documents it rests on and the trail it leaves behind.
Questionnaires, certificates, audit reports and contracts: everything a provider claims about itself, in one place instead of four.
Every extracted data point stays tied to document, section and page. You read the reasoning, not just the result.
Evidence expires, contracts get renewed, subprocessors change. The vendor file records when the next review falls due.
The first run: read the documents, present findings with sources, approve the assessment.
The second run: repeat the review when evidence expires or something changed.
The evidence you send out: cite answers from the documents instead of collecting them again.
The internal check: where a policy promises something the documents do not support.
No finding without a passage: the system cites the place every data point comes from.
Assessments are presented for approval and only become valid once a person confirms them.
Who decided what and on which basis is recorded in the decision log and can be exported.
It is the risk that comes from working with providers: missing evidence, unclear subprocessors, expiring certificates, gaps in contracts.
No. Leapfacto assesses the documents for a provider and presents findings for approval. Procurement, contract management and master data stay where they are.
With a provider that is due right now. One assessment from your own practice shows faster than any demo whether the assessment fits the way you work.
We go through your documents with you and show the assessment with its sources before you decide on a pilot.
Book a demo →