Off-Network Assessments

Off-Network Assessments lets you conduct vendor assessments using documentation collected outside of Trust Management Hub (TMH), while keeping the same workflow, governance, findings, and scoring as an on-network assessment. Instead of relying on manual tracking outside the platform, you can upload documentation the vendor sent you directly — email attachments, Trust Center exports, shared drive files — and Bitsight matches it against open requirements, updates progress and scoring, and carries it through the same review process as any other vendor.

Key capabilities:

  • Flexible Assessments: Run the full assessment workflow for vendors who aren't on TMH.
  • Unified Governance: Same governance, findings, and scoring model as on-network assessments.
  • Evidence Integration: Upload and attach vendor-provided evidence directly to requirements.

How Off-Network Assessments Work

You collect evidence from the vendor outside the platform, upload it to Vendor Profile → Internal Documents, and VRM matches it against open requirements. Once a document is linked to a requirement, that requirement is marked fulfilled and the assessment's progress and Trust Score update immediately — the same way they would if the vendor had submitted through TMH.

The workflow has six stages: 

  1. Receive artifacts
  2. Upload and categorize them
  3. Let the platform auto-match them to requirements
  4. Select Link or Change for each match
  5. Complete any questionnaires
  6. Review and report findings.

Step-by-Step Instructions

Step 1: Receive Vendor Artifacts

Collect assessment artifacts from the vendor outside of TMH, such as from the vendor's own Trust Center, an email attachment, or a shared secure location.

Step 2: Upload and Categorize Documents

Go to Vendor Profile → Internal Documents and upload the artifacts you received. Categorize each one into a requirement category:

  • Questionnaires
  • Certifications & Assurance Reports
  • External Audits & Assessments
  • Insurance

Some categories require additional metadata, such as expiration date, date received, or certification scope.

Step 3: Auto-Match Artifacts to Requirements

Go to Vendor Profile → Requirements. The platform scans your uploaded documents in Internal Documents and attempts to automatically match them to open requirements based on their category.

Step 4: Link or Change a Match

For each suggested match, choose to Link or Change it:

  • Link — Attaches the document to the requirement and marks it fulfilled. The Requirements page, assessment progress, and Trust Score all update immediately.
  • Change — Lets you select a different document from Internal Documents to fulfill the requirement instead of the match. The requirement stays outstanding until you select a replacement document.

Step 5: Complete Questionnaires

Questionnaires don't go through auto-match. From the Requirements page, select the questionnaire to open its details, then choose one of three options:

  • Download a CSV template to send to the vendor to fill out.
  • Upload a completed CSV template to populate the answers directly.
  • Fill out the questionnaire directly in the UI on the vendor's behalf.

Populated answers update assessment progress and score the same way linked documents do.

Step 6: Review and Report

Once requirements are fulfilled, review the documentation directly in the platform and add findings and notes as needed — the same review workflow used for on-network assessments. When the review is complete, export and share the Findings Overview report with the vendor outside the platform, then update its status based on their response.

How the Trust Score Changes

By default, Trust Score for monitored vendors is calculated only from the Bitsight Rating, normalized to a 0–100 scale:

Trust Score =

(Bitsight Score × 100%)

(Findings Deductions) ±

(Manual Adjustments)

Once you link the first document to a requirement for a monitored vendor, the Trust Score shifts to also factor in the performance of each linked document category, weighted according to your VRM scoring configuration.

Trust Score =

(External Audit Score × weight) +

(Certification Score × weight) +

(CISO Score × weight) +

(Insurance Score × weight) +

(Questionnaire Score × weight) +

(Bitsight Score × weight)

(Findings Deductions) ±

(Manual Adjustments)

Important Notes

  • Automatic shift: The Trust Score formula shifts automatically the moment the first document is linked to a requirement; no configuration is needed to trigger it.
  • Linked documents only: Only documents explicitly linked to a requirement count toward the score. Documents uploaded to Internal Documents but not linked to a requirement have no effect.
  • Monitored vendors without linked documents: Vendors with no linked documents keep using the Bitsight Rating-only Trust Score formula.
  • Questionnaires skip auto-match: Unlike other document categories, questionnaires are always completed manually through the CSV download/upload or in-UI options, not matched automatically.
Publish Date or Recent Edits
  • September 24, 2026 Published
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.