Supplier Management
π’ Supplier Management
"Manage vendors, contracts, dependencies, and risks in one place."
Track obligations, document ownership, and ensure compliance with regulations like NIS2 and DORA.
Third-party vendors are a frequent source of security and privacy risks. Brainframe GRC provides a centralized Supplier Management feature that not only documents suppliers but also maps their dependencies up to four levels deep, making compliance with regulations like DORA achievable.
1οΈβ£ Vendor Overview
The Vendor menu centralizes all supplier information. The general workflow:
- Create dedicated folders for each vendor.
- Store information inside with one main document (
Supplier or subcontractor
). - Link this document to related records β such as Data Processing Agreements, NDAs, Terms & Conditions, risks, or vulnerabilities.
2οΈβ£ Supplier Hierarchy View
The Hierarchy view enables you to:
- Visualize the dependency chain of suppliers.
- Document potential business impact if a supplier is compromised.
3οΈβ£ Creating a New Supplier
- Enter the supplier name or select an existing one.
- Store basic information (expand later as needed).
- Once saved, it appears in your supplier list and you can add information on how it relates to your operations.
4οΈβ£ Add Supporting Assets
Supporting assets are resources dependent on the supplier. If disrupted, they can directly impact operations.
- Click the [+] next to the supplierβs name. This opens a window where you can link an existing document, or pick a document of a certain type to create.
- Choose the document type, fill in details, and link it to the supplier.
5οΈβ£ Add Existing Assets as Vendors
If a vendor document exists but isnβt yet linked:
- Click the three dots on the document.
- Select Add to β Add as vendor.
6οΈβ£ Supplier List View
The List view provides a spreadsheet-style overview of all suppliers:
[](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/supplier-list_12kmnnc.png =958xauto)
Key features include:
- Create new vendors.
- Search and filter vendors.
- Loada additional risk information like properties and last readings, and add a color to the different risks.
- Configure the columns that are shown and export to Excel.
- List of vendor documents (click to open).
- Track and select checklist stage (Kanban).
- View RACI ownership.
- View linked tasks.
- See related supporting assets, generated automatically from the assets you linked to the supplier.
- View linked documents.
- Free text field that allows you to define business requirements (e.g. RTO, RPO).
- Review vendor-related risks.
7οΈβ£ Supplier Management in Processes
From the List view, track supplier lifecycle stages with the Workbench Kanban
8οΈβ£ Documenting Ownership (RACI Model)
Define responsibilities clearly with the RACI model:
- Responsible (R): Executes the work.
- Accountable (A): Ultimately owns the outcome.
- Consulted (C): Provides expertise.
- Informed (I): Stays updated.
9οΈβ£ Related Tasks
π Supporting Assets
1οΈβ£1οΈβ£ Document Management
Maintain supplier-related documentation:
- Audit reports
- NDAs
- Terms & conditions
- Due diligence evidence
1οΈβ£2οΈβ£ Business Requirements
Capture operational requirements for each supplier. Example (ISO 27001):
- π Confidentiality β Prevent unauthorized access.
- π Integrity β Ensure data/process accuracy.
- π Availability β Define uptime requirements.
- π Proof β Document evidence needed by auditors/regulators.
- β± RTO β Max downtime allowed.
- πΎ RPO β Max acceptable data loss.
- β Regulatory β Requirements based on data type or geography.
1οΈβ£3οΈβ£ Best Practices
- π Dedicate folders for each supplier to keep records organized.
- π Always link documents (DPAs, NDAs, risks) to the supplier file.
- π³ Use hierarchy view to identify critical dependencies across tiers.
- π Define RACI ownership early to avoid confusion in audits.
π― Visual Checklist
- [x] Supplier created with dedicated folder
- [x] Vendor linked to contracts and risks
- [ ] Supporting assets documented and connected
- [ ] Supplier lifecycle stage tracked in Workbench
- [ ] Business requirements (RTO/RPO) defined
Updated on: 05/09/2025
Thank you!