How we work
01Supplier inventory
One list reconciled across procurement, IT and finance, with the access each supplier holds.
02Classification
Criticality derived from the function the supplier supports, not from the supplier's size.
03Due diligence
Questionnaires proportionate to criticality, with evidence rather than assurances.
04Contractual clauses
Security requirements, incident notification duties and audit rights.
05Monitoring
Reassessment on a cycle and on change, recorded in the GRC platform.
What you get
Supplier register
Criticality classification
Questionnaires and findings
Contract clauses
Monitoring plan
Measures of Annex II this service covers
02 Management of software and hardware assets
03 Risk management
08 Supply chain security
Sectors where it is most in demand
Check for yourself before we talk
Entity categorisation check
Readiness check against the 13 measures
Incident reporting deadline calculator
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.