Overview
Product Level Answers (PLA) provide clients with deeper visibility into a supplier’s security controls at the product level. Instead of viewing risk assessments solely at the organisational level, clients can now differentiate security measures across various products and services. This enables more precise risk assessments and more informed decision-making.
Key Benefits
Identify when security controls vary across different supplier products.
Ensure assessments reflect the security posture of the specific product(s) you use.
Improve compliance tracking by distinguishing product-level security differences.
Facilitate targeted discussions with suppliers regarding specific product risks.
How to view Product Level Answers
To check whether a supplier has provided product-level answers:
Navigate to the Suppliers section and select a supplier profile.
Open their Assessment to review security responses.
Questions that have product-specific answers will display an indicator showing which product(s) the response applies to.
Click on a response to expand and compare product-level security details against the organisation-wide answer.
How to ask questions about product-specific controls
If a supplier has provided a product-level answer but you need further clarification:
Navigate to the relevant question in the supplier’s assessment.
Click Activity & Discussion to open a conversation with the supplier within a specific PLA. Reference the specific product when asking your question to ensure clarity.
Enter your text and click Send.
The supplier will be notified and can respond directly within the platform.
Follow up as needed to confirm security measures or request supporting evidence.
How to ask suppliers to set up a product
If a supplier has not yet set up product-level answers for a product you use, you can request them to do so:
Go to a specific supplier's Overview page and navigate to the Products section in the right sidebar.
Click the edit icon and specify which product(s) you need details for.
The supplier will receive a notification prompting them to provide product-specific responses.
You can track the supplier’s progress and follow up via the platform’s Discussion tool.
How to download an assessment with Product Level Answers
You can download a PDF or CSV file of a supplier's assessment, which will show Product Level Answers within it.
Open the supplier’s Assessment.
Click the burger menu in the top right part of the page, and select either Export as PDF or Export as CSV
The downloaded document will contain both organisational and product-specific responses for reference.
Store and share the document as needed for internal risk assessment processes.
FAQ
Can I apply different policies to different products? Not at the moment, but our team is interested in exploring this. If you have any feedback, do reach out to us.
Can I filter by product? Yes! Just filter as normal and select which Product you'd like to view responses for.
How are compliance scores affected by PLAs? Compliance scores are affected at the answer level. So if you have a control with multiple response levels, these will individually affect your compliance score rather than altogether.
💡 If there is anything we haven't covered, please feel free to contact us at support@riskledger.com or alternatively, select the Chat icon in the bottom right corner.