Vendor risk, scored and evidenced - not a questionnaire graveyard.
First-class supplier records, tiered assessments, weighted 0–100 scoring, and a guest portal vendors actually finish. Every third party bound to the obligations that govern it - DORA ICT oversight, NIS2 supply-chain, GDPR processor duties.
0–100
Weighted, gated scoring
Tiered
Assessments by criticality
Guest portal
Email-OTP, no account
Bound
To DORA / NIS2 / GDPR
Vendor risk stuck in spreadsheets
Questionnaires that don't come back, scores you can't defend, duties left unmapped.
Questionnaire graveyard
Spreadsheets emailed to vendors, half returned, never scored, never revisited until the next audit.
Scores you can't defend
A colour or a number with no method behind it - no weighting, no gating, no evidence an auditor would accept.
Unmapped to obligations
Vendor risk tracked in isolation from DORA ICT third-party oversight, NIS2 supply-chain duties and GDPR processor requirements.
Third-party risk as defensible data
One supplier record, scored transparently, bound to the duties that govern it.
Supplier as the single record
Each counterparty is a first-class record - assessments, DPA state, scores and evidence in one place, not scattered across tools.
Weighted, gated 0–100 scoring
Transparent scoring with weightings and gates, so a critical gap can't be averaged away. Defensible to an auditor.
Tiered assessments
Assessment depth scales to the vendor's criticality - a contractor answers a handful, a critical cloud provider the full set.
A portal vendors finish
Email-OTP guest access, no account to create - the reason questionnaires actually come back completed.
DPA state unified
Data-processing-agreement status tracked as first-class state, bound to GDPR processor obligations.
Bound to your obligations
Each supplier maps to the third-party duties that govern it under DORA, NIS2 and GDPR - oversight that traces to the law.