Table of Contents
Summary
There are four different ways to create new vendors in your Whistic account, each designed for different use cases and workflow preferences. Whether you need to add a single vendor quickly, allow external stakeholders to submit vendor information, upload multiple vendors at once, or leverage pre-existing vendor data from trusted sources, Whistic provides flexible options to meet your organization's needs.
Choose the method that best fits your situation:
- Vendors Tab: Best for quick, individual vendor additions by internal users
- External Intake Form: Ideal for allowing external stakeholders to submit vendor information independently (user does not need to be registered to add a vendor through this method, only the intake form link)
- Bulk Import: Perfect for adding multiple vendors simultaneously
- Trust Center Exchange: Efficient for importing vendors with existing compliance documentation
⚙️ Steps
Method 1: Vendors Tab - Add Vendor Button
This is the most common method for creating individual vendors directly within your Whistic account.
Steps to Add a Vendor
- Navigate to the Assess tab at the top of the platform and click on 'Vendors':
- Click the '+ Add Vendor' button located at the top of the page:
- Enter in the domain of the vendor to be added (required) & click Continue
- Enter the URL domain with the format: [companyname].com. Please do not use LinkedIn.com or Google.com as these are real websites that may restrict access depending on their account with Whistic.
- A website is required for all vendors added to the list. If a vendor does not have a website, please do not use your own company's URL. Type in a custom domain that is some combination of your company's and vendor's names (i.e. CustomerVendor.com). This ensures there will not be any kind of confusion in our system or for your team.
* Adding a vendor via the 'Add Vendor' link does not trigger a notification email to the Whistic admins listed on the account that's adding the vendor. It does trigger an email, however, if the vendor is added via the external intake form.
- Complete the vendor intake form with the following details:
- Vendor name (required)
- Vendor website URL (required)
- Product/Service (required) - necessary to differentiate vendor records between product/service
- Primary vendor contact information (required unless the requirement is removed from the intake form)
- Business description
- Any additional custom fields your organization has configured
- Click 'Submit' to add the vendor
Method 2: External Intake Form
The External Intake Form allows stakeholders outside your immediate team to submit new vendor requests that will be reviewed and approved by your team. The users who have access to the external intake form do not need to be registered in Whistic to submit the information, so please ensure you handle the link with care. A new intake form link can be made if you need to ensure that the old link is no longer used. More information can be found here.
How External Users Submit Vendors
- Access the intake form using the provided link
- Complete all required fields including:
- Vendor name (required)
- Vendor website URL (required)
- Product/Service (required)
- Primary vendor contact information (required unless the requirement is removed from the intake form)
- Business description
- Any additional custom fields your organization has configured
- Submit the form
Method 3: Bulk Vendor Import Template
The Bulk Import feature allows you to upload multiple vendors simultaneously using a structured template, making it efficient for large-scale vendor onboarding.
Steps for Bulk Import
- Navigate to Assess > Vendors in your Whistic account
- Click on Actions > Upload Vendors:
- Download the bulk import template (Excel format) from the upper right hand corner:
- Complete the template with your vendor information:
- Follow the column headers exactly as shown in the template
- Include all required fields (marked in the template)
- DO NOT remove columns or headers as there is metadata that maps the fields back into the platform.
- Save your completed file in the required format (Excel)
- Upload your completed template using the import function on the Secure Uploads page or from the Vendors tab directly (actions > upload vendors)
- Confirm the vendors have been added via the success message
For more details on this feature, go here to learn more.
Method 4: Import From Trust Center Exchange
The Trust Center Exchange allows you to import vendors that already have compliance documentation and assessments available, streamlining your vendor evaluation process.
Steps to Import from Trust Center Exchange
- Navigate to the 'Trust Center Exchange' from the 'Trust Center' menu at the top of the Whistic platform:
- Search for your desired vendor using the search function
- Browse available compliance documentation such as:
- SOC 2 reports
- ISO certifications
- Industry-specific compliance documents
- Security questionnaire responses
- Click the vendor profile you want to import
- Review the available compliance materials to ensure they meet your requirements
- Click 'Import' to add the vendor to your account.
- Go to Assess > Vendors (from the drop-down menu) and begin assessing!
🏆 Benefits of Trust Center Exchange Import
- Pre-completed assessments: Many vendors come with existing security documentation
- Verified compliance data: Information sourced from trusted industry databases
- Time savings: Reduces manual data entry and initial assessment work
- Comprehensive documentation: Access to multiple compliance frameworks and certifications
❓ FAQ
Which method should I use to create new vendors?
The method depends on your specific needs:
- Use +Add Vendor for quick, individual vendor additions
- Use External Intake Form when you want stakeholders or vendors to submit their own information
- Use Bulk Import when adding many vendors at once
- Use Trust Center Exchange when you want to leverage existing compliance documentation
Can I switch between methods for different vendors?
Yes, you can use any combination of these methods. Each vendor creation method results in the same vendor Trust Center structure, so you can manage all vendors consistently regardless of how they were created.
What information is required when creating a new vendor?
At minimum, you'll need:
- Vendor name
- Vendor Domain
- Contact information (required unless the requirement is removed from the intake form)
- Basic business description
- Additional fields may be required based on your organization's custom configuration.
Can I edit vendor information after creating them?
Yes, vendor information can be updated at any time after creation. Navigate to the vendor's Trust Center and click "Edit" to modify any details. The one exception is the URL/domain which cannot be modified.
What happens after I create a new vendor?
After creation, you can:
- Send security questionnaires
- Upload and review compliance documents
- Set up assessment workflows
- Add vendor contacts and stakeholders
- Configure monitoring and renewal reminders
Can I archive vendors if they're no longer needed?
Yes, vendors can be archived and unarchived when needed. You can archive; unarchival's must be done by our Support team (support@whistic.com)
How do I know which tier level to assign to new vendors?
Tier levels should align with your organization's risk assessment framework. Consult your internal risk management policies or contact your Customer Success Manager for guidance on tier assignment best practices.