Home › Use Cases › Catch what changed in a vendor's report, year to year
Use caseUC0069

Catch what changed in a vendor's report, year to year

A vendor's report looks fine on its own, but recertification means answering what changed since last year. This app lines up both years control by control and shows what's new, what repeated, and what quietly disappeared.

For the third-party risk deskCross-domain · Banking

Why it matters

Today's manual process, and the same job with the app

A third-party risk desk at a bank or company, checking a vendor's report against last year's at recertification time.

✕Today's manual process

1Pull both reports this year's assurance report and last year's, for the same vendor.
2Match every control by id, and reword it in your head when the auditor renumbered them.
3Decide what moved new, dropped, repeated, or resolved, control by control, in a spreadsheet.
4Miss a dropped control and a vendor that quietly stopped being checked stays approved.
Every report compared manually, control by control

✓With the app

1Both reports are read control by control, matched even when the ids changed.
2Renumbered controls stay one row with last year's id shown beside this year's.
3Every change gets a call added, dropped, repeated, or resolved, from the two reports' own words.
4Dropped controls come forward so a vendor that stopped being checked never slips through quietly.
The worksheet compares itself, row by row

See it work

One real case, read by the app, step by step

Vendor VEN-4194's control C-013 was renumbered from CM-01, but it's the same repeat exception as last year.

Catch what changed in a vendor's report, year to yearReference appBuilt to be shaped to your process
  1. 1One packet, both years PKT-0014's current and prior assurance reports, compared in one pass.
  2. 2New controls come forward a control missing last year now appears, marked added.
  3. 3Renumbered, not lost last year's id shown beside this year's, still the same finding.
  4. 4Dropped controls stand out a control the prior report tested is missing this year, flagged red.
  5. 5One answer, whole packet a tested control didn't come back this year, and nothing explains why.

For engineers

How it is built, and how we measured it

All fourteen steps of the build are written up, from the business case to running it in your own environment.

Kit overview →
605 of 605controls matched across both yearsmeasured in 01 Business case →
100 of 100renumbered controls resolved to one rowmeasured in 01 Business case →
0 of 72rows called without real proofmeasured in 01 Business case →
61¢to compare all 50 packetsmeasured in 07 Unit cost →

The build, step by step

14 steps

Make it yours

What you see is a reference app. We shape it to how you work.

Every part of it is built to change, and none of it means starting over.

Your rulesYour own comparison rulebook: what counts as a repeat, a drop, or a real renumbering.
Your recordsYour own assurance reports, in the format your third-party risk team already receives them.
Your systemsReads from wherever your recertification packets are filed, and can hand results to your risk register.
Your screensThe worksheet's columns, labels and wording, matched to how your own reviewers already talk about a file.

Want this for your team?

Talk to us

We can run this on your own vendor packets, with your own rulebook, inside your environment.

Talk to us →
A living map of modern AI — kept current every morning