Table of Contents
Summary
Whistic will help you serve up the right questions, to the right vendors, at the right times. This feature does require 'To get started, set up your Whistic account by customizing the following areas under Program Automation.
📊 Data Classifications
These are your risk levels and will also give you the option to set up a renewal cadence for your vendors based on risk level.
- Business Units - Departments within your organization that help identify which group has a relationship with your vendors.
- Connected Systems - Software tools or services that you currently use that new vendors may integrate with in some capacity.
- Vendor Criticality Levels - How critical the tool is to your business processes. We offer a good starting point here but you can add or edit to this list if needed.
🔍 Define Data Types
Define Data Types - Identify the types of data that a vendor would be accessing and the corresponding risk levels. Your vendors will be automatically assigned an inherent risk level based on how this question is answered in the intake form.
⚙️ Define Pre-Questionnaire Workflow & Logic
Define Pre-Questionnaire Workflow & Logic - Create helpful automation when new vendors are added through the intake form. You can specify actions such as assigning risk levels, sending questionnaires, and sending an email notification when certain conditions are met on the intake form.
- If you decide to set up logic to send out an email based on how the intake form is filled out then be sure to customize which questions in the form you want to include in the email.
📏 Establish Baselines & Rules
Establish Baselines & Rules - Set up scoring rules to get notified right away when a vendor completes a questionnaire request and scores in a range you specify. You can also set up an email notification based on how a vendor answers a specific question within a questionnaire.
You can get to this section by going to Assess Assess Settings Program Automation Establish Baselines & Rules
🎯 Scoring Rules
Set up scoring rules to get notified right away when a vendor completes a questionnaire request and scores in a range you specify.
For Example: An email alert will be sent if a vendor's inherent risk is High Risk and their score is less than 300.
📧 Questionnaire Level Rules
Set up an email notification based on how a vendor answers a specific question within a questionnaire using this feature.
For Example: If a vendor completes the CAIQ and they answer No (Not completed) on Question 10.1.1, i.e an email notification will be sent to all admins.
📌 Program Automation Guides
Below are different guides that walk through Program Automation information/steps: