How to run a vendor risk assessment as Small IT and ITOps Teams
You're a two-person IT team supporting 300 employees, and vendor risk assessment is the compliance task that always gets bumped. You have SaaS sprawl across 40-plus tools — Okta, Jamf, Jira, Zoom, Slack, AWS, half of which were approved by a department head who emailed you after the fact. When audit season or a security review hits, you're manually pulling SOC 2 reports from vendor portals, cross-referencing them against contracts buried in a Google Drive folder, chasing data processing agreements over email, and trying to remember whether that new AI vendor anyone signed up for last quarter even answered your security questionnaire. Nobody owns this. It's you, a spreadsheet, and hope.
What you'll set up
Apps, data, and prompts
The combination of Starch apps, the data sources they pull from, and the prompts you use to drive them.
Starch connects to Notion from its integration catalog — the agent queries your Notion databases live to pull contract and vendor records. Starch connects directly to Slack (scheduled sync) to send weekly digest alerts. For vendor trust portals and security pages that don't have an API — like a vendor's dedicated trust.vendorname.com page or their SOC 2 download form — Starch automates those through your browser, no API needed. Contract Lifecycle Management (coming soon — beta access available) will handle structured contract storage and renewal tracking natively once it launches.
Step-by-step
See this running on Starch
Connect your tools, describe what you want, and the agent builds it. Closed beta is free.
Q1 2026 Security Audit Prep — 43-Vendor Stack Review
| Vendors in Notion database | 43 |
| Vendors flagged high-risk (PII + no DPA or expired SOC 2) | 7 |
| Vendor trust portals visited via browser automation | 19 |
| Missing DPAs identified | 4 |
| SOC 2 reports older than 12 months | 5 |
| P1 remediation tasks auto-created in Task Manager | 4 |
| Hours saved vs. manual portal visits and spreadsheet cross-referencing | 11 |
Your company's external auditor is requesting evidence of vendor risk controls in three weeks. You have 43 SaaS vendors in Notion — some with contracts, some just Okta SSO entries that an employee connected six months ago. You tell Starch to build a vendor risk register from the Notion database, apply your risk-scoring rules, and visit 19 vendor trust portals through browser automation to pull SOC 2 links and last-updated dates. Starch returns the populated register in under an hour. Seven vendors are flagged high-risk: four are missing DPAs (including one HR tool that processes employee PII for 300 people), and five have SOC 2 reports last updated in early 2024. Starch creates P1 tasks in Task Manager for the four missing DPAs, drafts follow-up emails from Gmail to each vendor's security contact, and generates a Jira ticket for your security escalation queue. You send the auditor a clean vendor risk summary — not a half-finished spreadsheet — and close out the four DPAs before the audit window opens.
How you'll know it's working
What this replaces
The other ways teams handle this today, and how the Starch version compares.
One platform — contract lifecycle management, task manager all running on connected data. Setup in plain English; numbers stay current via scheduled syncs and live agent queries.
Try it on Starch →Frequently asked questions
We don't have a formal vendor database yet — just contracts scattered across Google Drive and a few Notion pages. Can Starch still work?
Can Starch actually visit vendor trust portals and download SOC 2 reports automatically?
Is Starch SOC 2 certified? Should I be putting vendor contract data into it?
What about Contract Lifecycle Management — I saw that listed?
We use Okta and already have a partial vendor list there. Can Starch pull from Okta?
How is this different from just setting calendar reminders for renewal dates?
Related guides for Small IT and ITOps Teams
Vendor and category spend analysis means knowing, at any point in time, where your money is actually going — which vendors are getting paid, how much, how often, and whether that number is creeping up or down relative to last month.
Read guide →A customer knowledge base is the document — or collection of documents — that answers the questions your customers ask repeatedly.
Read guide →SOC 2 evidence collection is the part of an audit where you prove that your controls actually work — not just that they're written down somewhere.
Read guide →A Slack announcement sounds simple — you're just telling your team something.
Read guide →Run a Vendor Risk Assessment for other operators
The AI stack built for small in-house legal and compliance teams.
Read guide →The AI stack built for emerging fund managers.
Read guide →The AI stack built for small finance teams.
Read guide →The AI stack built for the founder's office.
Read guide →Ready to run run a vendor risk assessment on Starch?
Request closed-beta access. Everything is free during beta.