Supplier Assessment
Choose the level of assurance you need — no more, no less
Supplier assessments are often required by regulators, auditors, or industry standards — but building an internal vendor risk process is costly and slow. This service provides structured, auditable supplier assessments with clear scope, fixed timelines, and predictable outcomes.
You always know:
- what is being assessed,
- how long it will take,
- what deliverable you will receive,
- and what the assessment does and does not cover.
Automated OSINT Screening
Best for: quick initial checks, lead qualification, low-risk suppliers
What you get
- Automated company background check
- Public security & privacy signals
- High-level risk indicators
- Downloadable summary report
How it works
- Fully automated
- No supplier contact
- Immediate results
Limitations
- No questionnaires
- No validation of supplier-provided information
- Not sufficient for formal audits on its own
👉 Included as a lead-in product. Usage limits apply.
Supplier Security & Privacy Assessment
Best for: ISO 27001 / GDPR / NIS2 / DORA supplier due diligence, audit preparation
Delivery: Final report within 8 calendar days
What is included
- Expanded OSINT screening
- Structured security & privacy questionnaire sent to the supplier
- Up to 2 automated follow-up reminders
- Analysis of responses and evidence (within defined limits)
- Risk scoring and clear recommendations
- Downloadable final assessment report
How it works
- You provide supplier contact details
- The system sends a structured questionnaire
- Responses (if received) are analysed and cross-checked
- A final assessment is issued within the defined timeframe
Important: Supplier non-response or incomplete responses are treated as risk indicators and reflected in the report.
Enhanced Supplier Assessment
Best for: critical suppliers, high-risk vendors, regulatory scrutiny
What it includes
- Extended questionnaires
- Manual clarification rounds
- Evidence deep-dive
- Optional interviews
- Tailored risk analysis
This level is closer to an audit engagement and is not fully automated.