Skip to content

Vendor management

Know which vendor supports which operation.

KaitoSec connects the vendor, sub-processors, contract, security assessment and continuity dependency. Procurement, privacy, security and process owners work from the same reviewed state.

Where friction starts today

Your supply chain risk lives in an inbox and three spreadsheets

Vendor security usually means a folder of returned questionnaires, a spreadsheet of contract dates, and a vague sense of which suppliers would actually hurt if they went down. The DPAs are in legal's drive, the sub-processor list is on someone's laptop, and when DORA or NIS2 asks for a register of ICT providers, you assemble it from scratch under deadline. The information exists; it just never lives in one place.

A supplier is not one risk, it is several at once. They hold your data, they sit in your recovery path, and they carry their own sub-processors behind them. Track those facts in separate tools and a contract change quietly breaks your GDPR position while your continuity plan still assumes the old setup. One record per vendor, linked to the assets and processes that depend on them, is the only way the picture stays straight.

One data model

What you enter here, the other modules already know

Modules are views on the same record, not separate databases. A change made here is the change every other module reads, with no export step and no second entry.

A change in this module is written to the shared data model, which the other modules read immediately.

This module

Vendor Management

Shared data model

One asset, one risk, one control, one piece of evidence

  • Risk ManagementCurrent at once
  • Business ContinuityCurrent at once
  • Asset ManagementCurrent at once

Entry to evidence

Every change carries its own proof

An auditor rarely asks what the register says today. They ask who changed it, when, and on what basis. That trail is written while the work happens, so nothing has to be reconstructed at the end of the year.

One change writes its previous value, its owner and its date, and surfaces in the management report, the audit evidence and the customer questionnaire.

One change

A risk is re-assessed

Written with it

  • Previous value and version
  • Person responsible
  • Date and reason

Where it surfaces

  • Management report
  • Audit evidence
  • Customer questionnaire

What changes for your team

01

See critical dependencies together

All suppliers, cloud providers and service partners sit in one searchable register. Each record carries contract status, risk classification, DPA state, continuity dependency and the assets or processes that rely on the vendor.

02

Turn questionnaires into accountable follow-up

Send prepared or custom questionnaires, review responses and connect them to the vendor risk profile. Open points become traceable follow-up tasks for the responsible owner.

03

Keep contracts, DPAs and sub-processors together

DPAs, sub-processor lists, standard contractual clauses and contractual SLAs live on the vendor record. KaitoSec alerts owners before agreements expire and when a scope change affects GDPR, NIS2 or DORA exposure.

The workflow

01

Vendor risk scoring across resilience and compliance

Assess questionnaire results, data criticality, continuity dependency and contractual safeguards together. New evidence remains connected to the decision it supports.

02

Sub-processor register tied to your RoPA

Sub-processors are linked to the parent vendor and to the processing activities they touch in your record of processing. The Article 28 chain of accountability stays explicit without parallel spreadsheets.

03

DORA and NIS2 supply-chain reporting

Compile DORA- and NIS2-relevant vendor data from the same register. Findings, continuity dependencies and incident records remain traceable to the vendor record.

FAQ

How does KaitoSec help with GDPR Article 28 compliance?

Every processor and sub-processor is tracked in a structured register linked to the processing activities they support. DPA status, expiry, standard contractual clauses and sub-processor changes are recorded per vendor, with alerts before renewal becomes urgent.

Can vendors complete questionnaires without a KaitoSec account?

Yes. Vendors receive a secure link to a hosted form and submit responses without creating an account. Submissions are ingested directly and linked to the vendor risk profile, with follow-up routed to your team.

How does vendor management support DORA?

DORA requires financial entities to maintain a register of ICT third-party service providers and to perform regular risk assessments. KaitoSec is structured to meet those requirements, including the contractual content checklist and concentration risk view, and produces the supervisory reporting artefacts.

Can we track vendor incidents and service disruptions?

Yes. Vendor-related incidents log against the vendor record and feed your incident management workflow. The same data drives NIS2 supply-chain incident reporting and DORA major-incident analysis without parallel paperwork.