This video walks through creating a Processing Operation Assessment (POA) for a vendor, step by step.
From the left-hand menu, select Vendor Assessment, then Vendor Log. Select an existing vendor and click Create POA.
Complete the popup's five fields; Title and Owner are mandatory. You'll then move into the main form.
Work through the six steps: Processing Operation Description, Processing Compliance, Safeguarding, Security and Systems, Assessment Summary, and Review & Approval.
Note: You can click between steps, but after making changes use the primary buttons at the bottom to save and continue.
The title and a reference number beginning with POA always appear at the top.
Describe the processing operation, including whether personal data is transferred to another country (for example by email, overseas cloud storage or access from abroad), as cross-border transfers can carry extra risk.
Select the data subjects and their data types; each appears as a pill.
Tip: Use +Other to add a missing type for your whole organisation; the Answered pill shows the total selected.
Answer the compliance questions. Choosing N/A, Yes, No or Don't Know opens a field for details.
In Safeguarding, answering Yes to the first question reveals more questions, each with a field for explanation.
In Security and Systems, selecting Yes or Don't Know reveals further technical questions.
Tip: Complete this step with your IT team.
Use +New (top-right) at any point to create a New Issue, New Risk, New Lesson or New Task; these are added to the Summary of Activities in Step 5.
In Step 6, record review and approval details, including responsible persons, dates and current status.
Tip: Use additional notes and attachments to keep extra details in one place.