Wrong entity
The assessment is attached to a trading name, a parent or a lookalike, not the company you contract with.

Regulated vendor decisions
KnightGrid determines what must be verified for each vendor, evaluates the evidence against those requirements, and records the basis for every approval.
Where approvals fail
Most vendor files show that work was done. Few show what was decided, on what basis, and whether it still holds.
The assessment is attached to a trading name, a parent or a lookalike, not the company you contract with.
The evidence exists, but it doesn’t cover the controls the approval relies on.
The decision was right when it was made; the evidence behind it has since expired.
Five connected stages determine what must be checked, what the evidence proves, who owns the judgment, and when the decision must be revisited.
Resolve who the vendor is, check prior history, and apply the E0 exposure gate before any control work begins.
Learn moreFive dimensions determine the tier and select only the controls that this vendor must prove.
Learn moreverifiedacceptedverifiedacceptedverifiedEvidence is mapped to the controls it supports and evaluated for strength, coverage, freshness, entity match, and conflicts.
Learn moreRules produce the traffic light. Named people own evidence acceptance, exceptions, overrides, and the final approval.
Learn more22 APR 2026Initial decisionapproved · frozen22 OCT 2026Scheduled reviewupcoming14 FEB 2027Evidence expirySOC 2 renewal15 SEP 2026Material changereassessment triggeredScheduled reviews, evidence expiry, legal-entity changes, incidents, and material service changes bring the decision back into review.
Learn moreSealed at sign-off
A vendor approval is a chain of people relying on the one before: the vendor’s answers, the reviewer’s judgment, the approver’s signature. KnightGrid seals the decision when it is signed. Change one character afterwards and the seal no longer matches.
Try to alter it →Security & CISO teams verify control outcomes. Internal Audit tests the decision trail. Risk and Compliance monitor the portfolio—without maintaining three different versions of the truth.
| Control | Outcome | Evidence basis |
|---|---|---|
| MFA enforcement | Pass | Config + logs |
| Logging and monitoring | Pass | System logs |
| Role-based access | Pass | Access config |
| Vulnerability management | Pass | Scan report |
| Independent pen test | Review | Report · 9 mo. |
| Incident response | Pass | Plan + exercise |
Security sees which controls passed automatically, which evidence supports them, and where human attention is still required.
See the Security & CISO workflow →verifiedboundcompleteloggedidenticalAudit can trace the outcome from frozen inputs, evidence references, rule versions, reviewer actions, and the accountable approval.
See the audit workflow →| Vendor | Tier | Confidence | Decision expiry | Current state |
|---|---|---|---|---|
| Castor Payments UK | 1 | Moderate | 22 OCT 2026 | Approved |
| Meridian Cloud Services | 2 | 0.76 | 14 MAR 2027 | Approved |
| Halford Data | 2 | 0.68 | 08 JUL 2026 | Conditional |
| Trentside Analytics | 3 | 0.91 | 19 FEB 2027 | Approved |
| Holborn Risk Solutions | 2 | 0.71 | 15 APR 2027 | Approved |
Teams can find expiring evidence, active exceptions, material changes, and reassessments while every previous decision remains frozen and traceable.
See the risk & compliance workflow →