Table of Contents
Summary
This article provides step-by-step instructions for generating a Vendor Summary using Whistic's AI-powered assessment tool. You'll learn how to select the appropriate framework, initiate the generation process, and monitor progress as AI analyzes your vendor's security documentation.
✅ Before You Begin
Ensure you have the prerequisites covered in Getting Started with Vendor Summary:
- Smart Search is enabled for the vendor
- Document processing is complete
- You have available Summary credits
- The vendor has shared relevant security documentation
📋 Steps to Generate a Vendor Summary
To generate a Vendor Summary you will first locate the vendor by going to Assess > Vendors and open the vendor details of the vendor you wish to conduct an assessment on.
1. Click Start Assessment using either of the following paths:
- From the Overview tab (displayed by default when opening a vendor record)
- From the Vendor Summary tab in the left-side navigation — if no summary has been generated yet, you'll see "No Vendor Summary Yet. Start an assessment and select sources to generate a vendor summary." Click Start Assessment from this screen.
2. On the next page you will see the option to:
- 'Launch Trust Center Capture' - Option 1 of using an AI Agent to go to the vendor's trust center to capture publicly available documents.
- 'Use Existing Sources' - Option 2 to assess using existing information you already have for the vendor, or you have the option to upload
-
'Request New Sources' - Otherwise, you can select from Option 3 and request new sources.
- You can select from questionnaire(s) or document(s):
3. Next, after the vendor returns the assessment/document or you have selected Option 2 where you had the source available, you will see 'Launch Whistic AI' on the screen.
4. Upon selecting Launch Whistic AI you will be presented with the options of Generating a Vendor Summary.
A pop-up window will appear with framework options. Review available frameworks:
- CAIQ (Cloud Security Alliance)
- CIS-IG 1, CIS-IG 2, CIS-IG 3 (Center for Internet Security)
- HECVAT (Higher Education Cloud Vendor Assessment Tool)
- BCBS Full (Blue Cross Blue Shield)
- NIST CSF (NIST Cybersecurity Framework)
- SIG Lite (Shared Information and Data Management)
- Whistic Vendor Summary Framework (Recommended)
Select your preferred framework by clicking on it OR create a custom questionnaire if you need organization-specific questions.
Want to set your default framework? No problem! Click the checkbox to save your changes to save you time in the future.
If you do not wish to customize the controls, click 'Create Now' to generate the vendor summary.
5. Optional - Customize Your Controls
Once you've selected a framework, you can fine-tune exactly which controls are included in your Vendor Summary rather than running the full framework:
- Use the "Customize Which Security Controls to Use" checkbox to customize the controls included in the selected framework
- Check or uncheck individual controls to include only the ones relevant to this vendor assessment
- This lets you scope the summary to the specific security areas you care about, rather than assessing every control in the framework
6. Click 'Next', then 'Generate with Custom Controls'
7. Monitor Progress:
- Watch real-time progress as each control is measured against available sources
- Monitor the progress bar at the top of the assessment window
- View individual sections being processed on the left side navigation
The system will show:
- Number of questions or controls being assessed in each section
- Real-time compliance determination
- Processing status for each framework area
🔍 Understanding the Generation Process
What Happens During Generation?
AI Analysis Process:
- Whistic AI searches through all available vendor sources
- Each security control question is evaluated against the documentation
- Sources are analyzed for relevant information and compliance indicators
- Confidence scores are calculated based on available evidence
- Results are compiled into a comprehensive summary