Which best describes your typical interaction with third-party risk disclosures?
- I regularly review full disclosures and mitigation plans
- I occasionally review full disclosures
- I rely on summaries but not full disclosures
- I do not review these
In the past 3 months, how often did you review vendor risk disclosures?
Where do you typically access third-party risk information? Select all that apply.
- Email digests
- GRC dashboard
- Policy or vendor risk reports
- Meeting briefings
- Slack/Teams updates
- Wiki/knowledge base
- Other
How easy is it to locate key risk and mitigation details in the GRC dashboard (or your primary tool)?
In the last 3 months, how easy was it to find the current mitigation and residual risk for a specific vendor?
How clear are the following elements in our third-party risk disclosures (past quarter)?
Overall, how plain-language are our risk write-ups and mitigation descriptions (past quarter)?
How visible is vendor risk status within the tools you use (e.g., dashboards, trackers)?
Rank the improvements that would be most helpful for clarity (drag to rank, top = most helpful).
Which mitigation elements are hardest to interpret? Select all that apply.
- Technical controls (e.g., encryption, segmentation)
- Process changes or compensating controls
- Timelines and milestones
- Residual risk quantification
- Ownership and escalation path
- None — it’s clear
- Other
If a vendor incident were reported today, how confident are you that you’d know the next steps?
Please share one recent example (last 60 days) where clarity helped or hindered a decision.
Max 600 chars
Overall satisfaction with the clarity of third-party risk disclosures and mitigations (past quarter).
What is your primary role?
What is your seniority level?
How long have you been in your current role?
Which region are you primarily based in?
Attention check: To confirm you are reading carefully, please select “Agree.”
- Strongly disagree
- Disagree
- Agree
- Strongly agree
Welcome! This short survey asks about the clarity and usefulness of third-party risk disclosures and mitigations. Please answer based on your experience in the past quarter.
Any other feedback on making third-party risk disclosures clearer for you?
Max 600 chars
AI Interview: 2 Follow-up Questions on third-party risk clarity
Thank you for your time—your input will help us improve how we communicate third-party risks and mitigations.