Why have we released framework sizes?
Organisations need flexibility when using Risk Ledger's Standardised Assessment Framework to assess their suppliers. Not all suppliers are equal, therefore not all suppliers require the same depth of review and assurance.
With different framework sizes, Clients can adapt the framework to meet their needs, while maintaining the standardisation that enables faster supplier connections, better data quality, benchmarking and actionable insights.
What does it involve?
Framework Sizes introduces three depths of assessment: Small, Flexible and Full. This approach allows for flexibility whilst maintaining standardisation across security domains. The new sizes enable suppliers to efficiently complete assessments tailored to their size and maturity, whilst offering clients with a more customisable purpose-fit approach to gathering the right information from their suppliers.
The three framework sizes are:
Small (53 control questions)
The small framework is designed for smaller or less mature suppliers, allowing them to engage more easily with your third-party risk management process. It's suitable for suppliers who may have limited resources or are in the early stages of developing their security practices.
Flexible (Depends on the policies applied)
The flexible framework is designed for smaller or less mature suppliers, or if there's a specific use where were only some parts of the assessment are relevant (for example a supplier fulfilling a niche role or during procurement when a supplier in review just needs to meet your minimum security levels).
Full (220 control questions)
The full framework is designed for larger or more critical suppliers, providing you with a comprehensive view of their security posture. This size is ideal for suppliers who handle sensitive data, provide critical services, or have mature security processes in place.
💡 If you’d like to see the exact content for the Small and Full framework, please send us a message and we can provide this in a spreadsheet.
How to select a framework size when sending a connection request to an existing supplier
It’s easy to set a Framework Size during the usual connection request flow:
Navigate to Suppliers → Add Supplier
Find the supplier you wish to connect with and click on their profile
On the supplier's profile, click the Add Supplier button
Within the connection workflow, you'll be prompted to select which framework size you'd like to apply to the supplier's assessment:
Note: Select "Policy-driven" for the Flexible Framework. Learn more about the Flexible Framework here.
How to change a supplier’s framework size after initial set up
Changing a supplier's framework size allows you to adjust the scope of assessment questions based on your evolving relationship with the supplier or changes in their risk profile.
This flexibility enables you to:
Focus on the most relevant security questions for each supplier
Reduce the assessment scope for smaller or lower-risk suppliers, encouraging their engagement
Increase the assessment depth for critical or high-risk suppliers
When you change the framework size:
For the supplier: They will be notified to complete any new questions if the framework includes more questions, or their assessment scope will be reduced if moving to a framework with fewer questions.
For you (the client): You'll gain a more appropriately tailored view of your supplier's security posture, allowing for more efficient risk management.
Here's how to change a supplier's Framework Size:
Go to Suppliers → All Suppliers and select a supplier
On the Overview page, locate the Framework Size section in the right-side column
Click the Edit icon (pencil symbol) next to Framework Size
4. In the pop-up window, select the desired Framework Size for your supplier:
How to set global defaults for framework sizes
Go to Settings → Framework & Add-ons
In this section, you'll be able to specify which Framework Size you'd like to be the default for all of your suppliers.
💡 Setting global defaults means that the Framework Size will be pre-filled when you send a connection request to a supplier. However, you can override this default for individual suppliers as described in previous sections. Remember, changing global defaults will only affect new supplier connections going forward, not existing ones.
How are suppliers notified about changes to their assessment based on framework size?
When a client changes the required framework size for a supplier (e.g., from Small to Full, or by editing the policies impacting the Flexible Framework), the supplier is notified in two ways:
Email Notification: The supplier will receive an email informing them of the changes to their required Framework Size.
2. Activity Feed: Suppliers can track all change requests by following these steps:
a. Go to Clients → Activity
b. Here, all changes are logged in an audit trail, including Framework Size
modifications.
What happens when you change a supplier's framework size?
Changing a supplier's framework size allows you to tailor your risk assessment process, but it's important to understand how this affects your existing policies, risks, and compliance scores. Here's what you need to know:
Controls required by a policy but not present in the new framework will not contribute to compliance.
Risks open on controls not in the newly selected framework size will be automatically closed, but don’t worry you can still access these.
If moving to a smaller size, the following elements related to removed controls will be affected: Exceptions, Risks, Remediations, Discussions will be closed.
You'll see a confirmation prompt before making changes:
Upgrading to Full Framework Size:
Supplier will be notified to complete the new framework
Compliance score may change immediately
Downgrading to Small Framework
Risks associated with removed controls will be closed
Discussions related to removed controls will be archived
Remediations linked to removed controls will be closed
Changing to Flexible Framework
Risks associated with removed controls will be closed
Discussions related to removed controls will be archived
Remediations linked to removed controls will be closed
💡 Remember: These changes ensure that assessment and compliance scores are based on the appropriate framework size for each supplier.
How to submit responses for new framework requirements
If you're a supplier who has completed the Small Framework and your client requests you to complete additional controls because they've changed your framework size:
You'll receive a notification by email about the change.
When you access your Assessment page, you'll see a banner at the top indicating the new requirements:
Below this banner, complete the additional questions in your assessment, following the same process you used for the Small Framework.
💡 If there is anything we haven't covered, please feel free to contact us at support@riskledger.com or alternatively, select the Chat icon in the bottom right corner.










