Articles on: Resources
This article is also available in:

Supplier Management

🤝 Supplier & Third-Party Management in Brainframe


"One place for every vendor — contracts, assessments, risks, and the assets they touch."
Brainframe treats each supplier as a governed hub document: link NDAs, DPAs, certificates, reviews, and risks in one register, connect the vendor to your core and digital assets, and track onboarding through process kanban and integrated tasks.


Supplier management in Brainframe works much like asset management — but the focus is third-party and supply-chain risk, not procurement workflows or accounts payable. You are not replacing your ERP or ticketing system. You are building a GRC-grade vendor register where every subcontractor, SaaS provider, MSP, or critical supplier has one central record, with all compliance evidence linked around it.


For CISOs and compliance professionals, this answers: Who are we dependent on? What did we agree with them? What is the impact if they fail or breach? And which of our business assets does this vendor support?



1️⃣ Why Supplier Management Exists


Outsourcing and cloud services mean your security perimeter extends to vendors you do not control directly. Regulations and standards expect you to govern that exposure:


Framework theme

What Brainframe supports

ISO/IEC 27001:2022 — A.5.19 Information security in supplier relationships

Central supplier register with linked policies and agreements

A.5.20 Addressing security within supplier agreements

Contracts, NDAs, DPAs, and security commitment documents linked to the supplier

A.5.21 Managing information security in the ICT supply chain

Dependencies between suppliers and digital/physical assets

A.5.22 Monitoring, review and change management of supplier services

Supplier reviews, offboarding records, process kanban stages

A.5.23 Information security for use of cloud services

Cloud/SaaS vendors linked to supporting digital assets

GDPR Art. 28 Processor relationships

Data processing agreements and DPIAs linked to the vendor

SOC 2 / NIS2 Third-party risk

Risk documents, certificates, and control evidence per vendor


Brainframe is designed so vendor evidence feeds risk assessment and audit — not so it replaces contract negotiation or vendor billing systems.


💡 Think vendor risk register, not procurement portal. Brainframe tells you whether the vendor is governed and what breaks if they do — not how much you pay them this quarter.



2️⃣ One Supplier, One Central Hub


The core idea mirrors asset management: one governed document per vendor (or vendor class), with everything else linked to it.


Traditional approach

Brainframe approach

DPA in SharePoint, SOC report in email, review in spreadsheet

All documents linked to the Supplier record

"Which systems does Vendor X touch?" — answered in meetings

Supporting assets column and Dependencies graph

Vendor risk in a separate tool

Legal, business, and security risks linked on Governance and in the register

Onboarding status in someone's inbox

Process kanban stage on the supplier row + tasks linked to the vendor


A single Supplier document becomes the index page for that third party. Auditors open one record and see agreements, assessments, linked assets, risks, tasks, and review history — without hunting across folders.


📌 Like assets, you typically model one Brainframe supplier per governed vendor relationship — not one record per invoice, support ticket, or individual contact at the vendor (those belong in linked documents or your operational tools).



3️⃣ The Suppliers Register


Open the left sidebar → Resources → Suppliers.


The register opens as a table view with a document-type dropdown covering the supplier lifecycle:


Document type

Typical use

Supplier

Main vendor / subcontractor record — the central hub

Supplier review

Periodic due-diligence and performance reviews

Supplier technical and organisational security measures

Documented security commitments, questionnaires, SOC summaries

Supplier offboarding

Exit checklist when terminating a vendor relationship


Use the dropdown to focus on one type or Show all to see the full vendor population in one list.


The supplier management table is richer than a standard document list. Key columns include:


Column

What it shows

Status

Current process kanban stage when a supplier is linked to a workflow (e.g. Onboarding → Due diligence → Approved → Review due)

RACI

Responsible, Accountable, Consulted, Informed — people or roles for vendor ownership

Task

Linked tasks (including integration tasks from JIRA, Asana, Monday, Azure DevOps)

Supporting assets

Core business, digital, and physical assets this vendor supports or accesses

Documents

Linked supporting documents grouped by type (NDAs, contracts, DPAs, etc.)

Business requirement

Free-text ISMS / business requirements specific to this vendor

Related risks

Linked risk documents with latest risk readings where configured


💡 Columns such as Documents and Supporting assets are built from linked records. When you edit a supplier, you configure which document types appear in each automatic filter — so your register shows exactly the evidence categories your programme cares about.



4️⃣ Creating and Documenting Suppliers


✨ Create new (with template)


  1. Open Resources → Suppliers.
  2. Select Supplier (or another supplier document type) in the dropdown.
  3. Click Create new.
  4. Complete the template — supplier document types include structured sections to capture vendor scope, services provided, data handled, criticality, and compliance context.


Templates keep vendor documentation consistent across the organisation, which matters for ISO audits and GDPR processor registers.


✨ Asset wizard (digital / physical supplier types)


On supplier-related document types configured as assets, the Create asset wizard (✨ button next to Create new) offers the same AI-assisted flow as for digital and physical assets: describe the vendor, link controls, assess risks, build a mitigation plan, and create the document with governance links persisted.


Use this when onboarding a critical vendor where you want structured risk and control mapping from day one.



5️⃣ Linking Evidence to a Supplier


Open a supplier → Edit (from the register) or manage links from the document's Dependencies and Governance tabs.


📄 Supporting documents (central evidence locker)


Link documents that prove and govern the vendor relationship. Workspaces commonly include:


Evidence category

Examples of linked document types

Confidentiality

Non-disclosure agreements (NDA)

Data protection

Data processing agreements (DPA), DPA reviews

Privacy assessments

Data protection impact assessments (DPIA)

Commercial terms

Contracts, statements of work, terms & conditions

Assurance

Certificates (ISO 27001, SOC 2, PCI), penetration-test summaries

Security posture

Supplier technical and organisational security measures

Reviews

Supplier review records, audit reports

General files

PDFs, uploaded documents, policies addressed to the vendor


Auto filter supporting documents — When editing a supplier, choose which document types appear in the Documents column and automatic filters. Default configurations often include NDAs, contracts, DPAs, DPIA, and general documents — your administrator can extend this to vulnerabilities, legal risks, or any custom type.


You can upload files directly when linking supporting documents, so signed PDFs land in the vendor folder and attach to the supplier in one step.


🏗 Supporting assets (what the vendor touches)


Link core business, digital, and physical assets that depend on or are exposed through this vendor:


  • A SaaS HR platform → linked to Payroll process (core business) and HR application (digital)
  • A managed SOC provider → linked to Security monitoring service and SIEM platform
  • A hosting provider → linked to Customer portal and Production database


Auto filter supporting assets — Configure which asset types surface in the Supporting assets column (typically digital, physical, and core business types).


This is how you answer audit questions like "Show all vendors with access to personal data systems" — filter the register or open a supplier and read its asset links.



Link legal risks, business risks, risk scenarios, and other risk document types configured for your workspace. The Related risks column shows linked risks with latest risk readings (severity scores) when available.


Typical vendor risks:


  • Sub-processor breach exposing customer data
  • Vendor service outage impacting critical business process
  • Non-compliance with contractual security clauses
  • Fourth-party (supply chain) exposure


✅ Tasks and integrations


Link tasks from Brainframe's integrated task management — including tickets synced from JIRA, Asana, Monday, or Azure DevOps. Tasks appear in the supplier row so remediation, onboarding steps, and audit actions stay tied to the vendor.



6️⃣ Metadata — Owner, Criticality, and RACI


Supplier records support the same metadata properties as assets, configured per document type under Workspace Settings → Document types:


Property

Purpose

Owner

Internal owner of the vendor relationship (e.g. procurement lead, business sponsor)

Criticality

High / Medium / Low — how essential or sensitive this vendor is

RACI

Responsible (does the work), Accountable (owns the outcome), Consulted, Informed

Service category

SaaS, MSP, subcontractor, data processor, etc.

Review due date

Next scheduled vendor review

Data classification

Highest classification of data shared with the vendor


Owner and Criticality appear as table columns and filters — e.g. "All High-criticality suppliers without a review in the last 12 months."


RACI is edited on the supplier and displayed directly in the register, giving auditors a clear accountability line for each vendor.



7️⃣ Governance — Maximum Impact on the Supplier


Supplier document types use governance classification "This is an asset" (the same governance model as business and technology assets). This unlocks the Governance tab on each supplier document.


What you configure


Area

Description

Risk type

Risk methodology (matrix) applied to this vendor

Maximum impact (Max impacts)

For each consequence dimension — financial, reputational, operational, legal, personal/safety, and others defined in your risk type — set the worst credible outcome if this vendor breaches, fails, or mishandles data

Linked risks

Risk documents that apply to this vendor

Linked controls

Controls that govern the relationship (vendor assessment, contract clauses, monitoring, access reviews)

Mitigation overview

How well linked controls cover identified vendor risks

AI identify

Suggest additional controls, risks, or related records (when Confidential AI is enabled)


Why max impact matters for vendors


A payroll SaaS provider and a marketing flyer printer have different breach profiles. Configuring max impacts on the supplier document means:


  • Risk assessments use realistic consequence bounds for vendor scenarios
  • Board and management reporting can rank vendors by inherent business harm
  • DPIA and processor risk analysis align with the same impact dimensions as your enterprise risk framework


📌 Example: A cloud HR processor might have High legal/personal impact (employee PII) and Medium operational impact (payroll delay tolerance). A stationery supplier might be Low across all dimensions. Both get one supplier record — with different governance profiles.



8️⃣ Process Kanban — Following Suppliers as a Workflow


Suppliers can be linked to a process kanban board (process checklist) so vendor lifecycle stages are visible in the register.


How it works


Step

Action

1. Link process

In the Status column, select Link process and choose a kanban board (e.g. "Vendor onboarding", "Annual vendor review")

2. Track stage

Move the supplier through stages — Requested → Due diligence → Legal review → Approved → Active → Review due → Offboarding

3. Link tasks

Attach tasks to the supplier for each stage; assign owners and due dates

4. Monitor

The Status column shows the current stage with colour-coded kanban state


Document types can have a default process configured so new suppliers automatically join the right workflow.


This connects third-party risk management to Brainframe's integrated task system — onboarding questionnaires, security reviews, and contract sign-offs become trackable work items on the vendor record, not orphaned emails.


💡 Pair process kanban with Supplier review and Supplier offboarding document types for a complete lifecycle: onboard → operate → review → exit.



9️⃣ Dependencies and Visual Maps


Supplier relationships use the same dependency tools as assets.


On the supplier document


Dependencies panel:


Section

Meaning

Parent documents

What this supplier depends on (e.g. a parent Contract framework, a Policy governing procurement)

Child documents

What depends on this supplier (linked DPAs, reviews, vulnerabilities, sub-vendor records)


Show dependencies in graph diagram — Interactive graph centred on the supplier; drill into linked documents and return without losing the view.


Suppliers table — Dependencies & Graph tabs


From Resources → Suppliers, switch the table from List to:


Tab

Use

Dependencies

Tree of each supplier and linked children — see which assets and documents hang off each vendor

Graph

Network diagram of suppliers and links in the current scope — useful for workshops and TPRM presentations


Resources → Dependencies (helicopter view)


Configure a visual collection that includes Supplier plus core business, digital, and physical asset types. The helicopter graph shows vendor → asset → business service chains across the organisation — ideal for supply-chain and concentration-risk analysis.



🔟 ISO 27001 & GDPR Best Practices


Build the register (top-down)


  1. List critical and personal-data vendors first — processors, SaaS, MSPs, subcontractors with system access.
  2. Create one Supplier record per governed relationship (not per contract amendment — link amendments as child documents).
  3. Set Owner, Criticality, and RACI before deep due diligence.
  4. Link the process kanban for onboarding if your programme uses a standard workflow.


Attach evidence (bottom-up)


  1. Link NDA, contract, and DPA before production data flows.
  2. Store certificates and security questionnaires as linked documents or dedicated security-measures records.
  3. Complete a DPIA where required and link it to the supplier.
  4. Record supplier reviews on a schedule (annual for critical, less often for low-risk).


Connect risk and controls


  1. Set max impacts on the Governance tab using your risk type's consequence dimensions.
  2. Link controls — vendor assessment, contract security schedule, monitoring, sub-processor approval.
  3. Link or create risks for credible vendor failure modes.
  4. Use Related risks column in the register for management review dashboards.


Keep it lean


Do

Avoid

One supplier record per governed vendor relationship

Duplicate records per project phase

Link asset classes the vendor supports

Listing every endpoint the vendor could theoretically access

Use Supplier review documents on a schedule

One-off spreadsheet reviews outside Brainframe

Track offboarding with Supplier offboarding type

Leaving terminated vendors in "Active" status


Evidence auditors expect


  • "Show your supplier inventory."Resources → Suppliers with Owner and Criticality
  • "Show processor agreements." → Filter suppliers → Documents column → DPA types
  • "How do you monitor vendors?"Supplier review records + process kanban stages
  • "What is the impact of vendor X failing?" → Supplier → GovernanceMax impacts
  • "Which systems does vendor X access?"Supporting assets + Dependencies graph



1️⃣1️⃣ Day-to-Day Workflows


CISO / third-party risk lead


Task

Where

Review critical vendors

Suppliers table → filter Criticality = High

Check missing DPAs

Filter suppliers → inspect Documents column for DPA gaps

Map vendor to business impact

Supplier → Governance → max impacts + linked core business assets

Annual TPRM report

Export Dependencies helicopter graph including suppliers + assets


Compliance / privacy officer


Task

Where

Maintain GDPR processor register

Suppliers + linked DPA and DPIA documents

Schedule vendor reviews

Supplier review documents + process kanban Review due stage

Evidence for Art. 28

Open supplier → Documents → DPA, security measures, sub-processor list

Track legal/compliance risks

Related risks column or Governance → linked legal risks


Procurement / business owner


Task

Where

Onboard new vendor

Create new Supplier → link process kanban → add tasks per stage

Document business need

Business requirement field on supplier row

Assign accountability

RACI on supplier record

Link what the vendor supports

Supporting assets → core business and digital assets


Risk owner


Task

Where

Assess vendor-related risk

Risk document → Governance → link Supplier as affected asset

Understand vendor consequence ceiling

Supplier → Governance → Max impacts

See control coverage

Supplier → Governance → linked controls + mitigation chart

Updated on: 13/07/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!