← Back to the blog
Workflows & assessments

An assessment is not a form. It is a workflow with an outcome.

Questions collect evidence. A workflow turns that evidence into a reviewed, accountable decision—and carries the result back to the vendor or contract.

Most assessment tools begin and end with a questionnaire. That is enough to collect answers. It is not enough to decide whether a supplier, contract or proposed use is acceptable—and it is certainly not enough to make the decision operational.

A vendor risk assessment, for example, may begin with questions for the supplier. But the answer to “Will you process personal data?” should change what happens next. Security may need to review the response. Procurement may need evidence. A manager may need to step in if the work stalls. The result should have an owner, a validity period and a visible place on the vendor record.

That is why Fratera treats an assessment as a workflow pattern rather than a separate island of forms.

The form gathers evidence. The workflow decides who sees it, what happens next and when the organisation can rely on the result.

Start with the path, not the questionnaire

A controlled process can be built from a small set of understandable blocks: forms, approvals, decision gates, record updates, notifications and a final outcome. Each block has one job, and the path between them makes the process visible.

The same foundation can support different procurement processes. A new-vendor request may collect internal context first, invite the supplier to answer a questionnaire, route data-processing suppliers to Security and finish with a traffic-light risk outcome. An annual compliance re-check can reuse the pattern with a shorter form and a new validity period.

Product concept based on the current workflow beta. The finished interface may evolve before general availability.

Give every stage an accountable owner

A process should not depend on somebody forwarding an email to the right colleague. Workflow assignments can resolve to the person who started the request, the owner of the subject record, a named person, a work group, a permission holder or a contract stakeholder role.

Suppliers and other outside participants can receive a focused response link without becoming full application users. An optional PIN adds a second shared secret when the process needs it. Internal reviewers still work inside Fratera, where their existing permissions apply.

Let answers change the route

Not every assessment needs every reviewer. Conditional gates can inspect an answer, a record field or a decision and choose the appropriate path. A low-risk supplier can continue to the final review; a supplier handling personal data can be routed to Security; a rejected answer can return to the requester for correction.

This keeps the normal path short without weakening the exceptions. It also makes the rule visible: teams can see why a request took a particular route instead of reconstructing the logic from an email chain.

Design for the work after submission

Submission is usually where the important work begins. A reviewer may need clarification. An assignment may need to move. A due date may pass. Fratera workflows support return, reassignment and manager step-in, with reminder and escalation timing attached to the step.

  1. 01
    Collect

    Use staged forms with required questions, conditional sections and a traffic-light question where it helps.

  2. 02
    Route

    Send work to the relevant person, group or external respondent and branch when an answer changes the risk.

  3. 03
    Review

    Return incomplete work, reassign ownership and escalate overdue steps without losing the request history.

  4. 04
    Decide

    Finish with a traffic-light, approved/rejected or custom outcome and set how long it remains valid.

  5. 05
    Record

    Save reviewed answers and the outcome back to the relevant vendor or contract fields, with optional human confirmation.

Make the outcome useful—and temporary when it should be

An assessment result should be more than “complete”. It may be Green, Amber or Red; approved or rejected; or a set of labels that matches the organisation’s own policy. It may also be valid for six or twelve months rather than forever.

The workflow can show that result on the subject record and write selected, reviewed answers into structured fields. That means a vendor owner can see the current position without opening the original response, while the workflow run preserves how the decision was reached.

Change the template without rewriting history

Operational processes evolve. A new risk question appears, ownership changes or a routing rule needs to be tightened. Published workflow versions are immutable, and each live request remains pinned to the version that started it. A new version can improve future runs without silently changing the rules under work already in progress.

Before publishing, a draft can be validated and tested against a real vendor or contract without starting work, assigning people or writing fields. Fratera can also draft a workflow from a plain-language description; the result remains unpublished until a person checks and publishes it.

One foundation, many procurement decisions

The first obvious uses are vendor onboarding, security and privacy reviews, AI-use assessments, contract intake and annual compliance checks. The common requirement is not a particular questionnaire. It is a repeatable decision involving evidence, ownership and a controlled result.

Bringing those pieces into one workflow reduces the distance between asking a question and acting on the answer. Procurement gets a visible process. Contributors get focused work. Reviewers get the context they need. The vendor or contract record gets a result the wider organisation can use.

Workflows & assessments in Fratera

Build the route from request to accountable outcome.