List risks for an audit
Retrieves risk population data for an audit.
This endpoint provides access to the risk records visible to auditors
during an audit engagement. Risk data is scoped to a specific risk
assessment snapshot identified by the snapshotId parameter.
Only Controlled Audit View (CAV) audits are supported. Full Audit View audits are rejected with 403.
Supports filtering by:
search: Searches risk scenario descriptions (case-insensitive)
Results are sorted by identified date (newest first) by default.
Use orderBy and orderDirection to customize sorting.
Sort parameters must remain consistent across paginated requests.
Uses cursor-based pagination. To paginate:
- Make initial request with desired
pageSize - Check
results.pageInfo.hasNextPage - Use
results.pageInfo.endCursoraspageCursorfor next request
Documentation Index
Fetch the complete documentation index at: https://developer.vanta.com/llms.txt
Use this file to discover all available pages before exploring further.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
The audit ID
The risk assessment snapshot ID
Query Parameters
Maximum number of results per page (1-100, default 10) Controls the maximum number of items returned in one response from the API.
1 <= x <= 100Pagination cursor from previous response A marker or pointer, telling the API where to start fetching items for the subsequent page in a paginated dataset. Note that the requested page will not include the item that corresponds to this cursor but will start from the one immediately after this cursor.
Search term for filtering by risk scenario description
Field to sort results by. Allowed: "riskId", "riskScenario", "inherentRisk", "treatment", "residualRisk", "reviewStatus", "owner", "categories", "ciaCategories", "identified". Default: "identified"
inherentRisk, riskId, riskScenario, treatment, residualRisk, reviewStatus, owner, categories, ciaCategories, identified Sort direction: "asc" or "desc". Default: "desc" Sort direction: "asc" for ascending, "desc" for descending.
asc, desc Response
Paginated list of risks with pagination metadata