> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://docs.brainframe.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Supplier Management

# 🤝 **Supplier & Third-Party Management in Brainframe**

> **"One place for every vendor — contracts, assessments, risks, and the assets they touch."**
> *Brainframe treats each supplier as a governed hub document: link NDAs, DPAs, certificates, reviews, and risks in one register, connect the vendor to your core and digital assets, and track onboarding through process kanban and integrated tasks.*

Supplier management in Brainframe works much like **asset management** — but the focus is **third-party and supply-chain risk**, not procurement workflows or accounts payable. You are not replacing your ERP or ticketing system. You are building a **GRC-grade vendor register** where every subcontractor, SaaS provider, MSP, or critical supplier has one central record, with all compliance evidence linked around it.

For CISOs and compliance professionals, this answers: *Who are we dependent on? What did we agree with them? What is the impact if they fail or breach? And which of our business assets does this vendor support?*

---

## 1️⃣ Why Supplier Management Exists

Outsourcing and cloud services mean your security perimeter extends to **vendors you do not control directly**. Regulations and standards expect you to govern that exposure:

| Framework theme | What Brainframe supports |
| ---- |
| **ISO/IEC 27001:2022 — A.5.19** Information security in supplier relationships | Central supplier register with linked policies and agreements |
| **A.5.20** Addressing security within supplier agreements | Contracts, NDAs, DPAs, and security commitment documents linked to the supplier |
| **A.5.21** Managing information security in the ICT supply chain | Dependencies between suppliers and digital/physical assets |
| **A.5.22** Monitoring, review and change management of supplier services | Supplier reviews, offboarding records, process kanban stages |
| **A.5.23** Information security for use of cloud services | Cloud/SaaS vendors linked to supporting digital assets |
| **GDPR Art. 28** Processor relationships | Data processing agreements and DPIAs linked to the vendor |
| **SOC 2 / NIS2** Third-party risk | Risk documents, certificates, and control evidence per vendor |

Brainframe is designed so **vendor evidence feeds risk assessment and audit** — not so it replaces contract negotiation or vendor billing systems.

> 💡 **Think vendor risk register, not procurement portal.** Brainframe tells you *whether the vendor is governed* and *what breaks if they do* — not how much you pay them this quarter.

---

## 2️⃣ One Supplier, One Central Hub

The core idea mirrors asset management: **one governed document per vendor** (or vendor class), with everything else linked to it.

| Traditional approach | Brainframe approach |
| ---- |
| DPA in SharePoint, SOC report in email, review in spreadsheet | All documents **linked to the Supplier record** |
| "Which systems does Vendor X touch?" — answered in meetings | **Supporting assets** column and **Dependencies** graph |
| Vendor risk in a separate tool | **Legal, business, and security risks** linked on Governance and in the register |
| Onboarding status in someone's inbox | **Process kanban** stage on the supplier row + **tasks** linked to the vendor |

A single **Supplier** document becomes the **index page** for that third party. Auditors open one record and see agreements, assessments, linked assets, risks, tasks, and review history — without hunting across folders.

> 📌 Like assets, you typically model **one Brainframe supplier per governed vendor relationship** — not one record per invoice, support ticket, or individual contact at the vendor (those belong in linked documents or your operational tools).

---

## 3️⃣ The Suppliers Register

Open the left sidebar → **Resources → Suppliers**.

The register opens as a **table view** with a document-type dropdown covering the supplier lifecycle:

| Document type | Typical use |
| ---- |
| **Supplier** | Main vendor / subcontractor record — the central hub |
| **Supplier review** | Periodic due-diligence and performance reviews |
| **Supplier technical and organisational security measures** | Documented security commitments, questionnaires, SOC summaries |
| **Supplier offboarding** | Exit checklist when terminating a vendor relationship |

Use the dropdown to focus on one type or **Show all** to see the full vendor population in one list.

The supplier management table is richer than a standard document list. Key columns include:

| Column | What it shows |
| ---- |
| **Status** | Current **process kanban** stage when a supplier is linked to a workflow (e.g. Onboarding → Due diligence → Approved → Review due) |
| **RACI** | **Responsible, Accountable, Consulted, Informed** — people or roles for vendor ownership |
| **Task** | Linked **tasks** (including integration tasks from JIRA, Asana, Monday, Azure DevOps) |
| **Supporting assets** | Core business, digital, and physical assets this vendor supports or accesses |
| **Documents** | Linked **supporting documents** grouped by type (NDAs, contracts, DPAs, etc.) |
| **Business requirement** | Free-text ISMS / business requirements specific to this vendor |
| **Related risks** | Linked **risk documents** with latest risk readings where configured |

> 💡 Columns such as **Documents** and **Supporting assets** are built from **linked records**. When you edit a supplier, you configure which document types appear in each automatic filter — so your register shows exactly the evidence categories your programme cares about.

---

## 4️⃣ Creating and Documenting Suppliers

### ✨ Create new (with template)

1. Open **Resources → Suppliers**.
2. Select **Supplier** (or another supplier document type) in the dropdown.
3. Click **Create new**.
4. Complete the **template** — supplier document types include structured sections to capture vendor scope, services provided, data handled, criticality, and compliance context.

Templates keep vendor documentation **consistent across the organisation**, which matters for ISO audits and GDPR processor registers.

### ✨ Asset wizard (digital / physical supplier types)

On supplier-related document types configured as assets, the **Create asset wizard** (✨ button next to **Create new**) offers the same AI-assisted flow as for digital and physical assets: describe the vendor, link controls, assess risks, build a mitigation plan, and create the document with governance links persisted.

Use this when onboarding a **critical vendor** where you want structured risk and control mapping from day one.

---

## 5️⃣ Linking Evidence to a Supplier

Open a supplier → **Edit** (from the register) or manage links from the document's **Dependencies** and **Governance** tabs.

### 📄 Supporting documents (central evidence locker)

Link documents that prove and govern the vendor relationship. Workspaces commonly include:

| Evidence category | Examples of linked document types |
| ---- |
| **Confidentiality** | Non-disclosure agreements (NDA) |
| **Data protection** | Data processing agreements (DPA), DPA reviews |
| **Privacy assessments** | Data protection impact assessments (DPIA) |
| **Commercial terms** | Contracts, statements of work, terms & conditions |
| **Assurance** | Certificates (ISO 27001, SOC 2, PCI), penetration-test summaries |
| **Security posture** | Supplier technical and organisational security measures |
| **Reviews** | Supplier review records, audit reports |
| **General files** | PDFs, uploaded documents, policies addressed to the vendor |

**Auto filter supporting documents** — When editing a supplier, choose which document types appear in the **Documents** column and automatic filters. Default configurations often include NDAs, contracts, DPAs, DPIA, and general documents — your administrator can extend this to vulnerabilities, legal risks, or any custom type.

You can **upload files** directly when linking supporting documents, so signed PDFs land in the vendor folder and attach to the supplier in one step.

### 🏗 Supporting assets (what the vendor touches)

Link **core business**, **digital**, and **physical** assets that depend on or are exposed through this vendor:

* A SaaS HR platform → linked to **Payroll process** (core business) and **HR application** (digital)
* A managed SOC provider → linked to **Security monitoring service** and **SIEM platform**
* A hosting provider → linked to **Customer portal** and **Production database**

**Auto filter supporting assets** — Configure which asset types surface in the **Supporting assets** column (typically digital, physical, and core business types).

This is how you answer audit questions like *"Show all vendors with access to personal data systems"* — filter the register or open a supplier and read its asset links.

### ⚠️ Related risks

Link **legal risks**, **business risks**, **risk scenarios**, and other risk document types configured for your workspace. The **Related risks** column shows linked risks with **latest risk readings** (severity scores) when available.

Typical vendor risks:

* Sub-processor breach exposing customer data
* Vendor service outage impacting critical business process
* Non-compliance with contractual security clauses
* Fourth-party (supply chain) exposure

### ✅ Tasks and integrations

Link **tasks** from Brainframe's integrated task management — including tickets synced from **JIRA**, **Asana**, **Monday**, or **Azure DevOps**. Tasks appear in the supplier row so remediation, onboarding steps, and audit actions stay tied to the vendor.

---

## 6️⃣ Metadata — Owner, Criticality, and RACI

Supplier records support the same **metadata properties** as assets, configured per document type under **Workspace Settings → Document types**:

| Property | Purpose |
| ---- |
| **Owner** | Internal owner of the vendor relationship (e.g. procurement lead, business sponsor) |
| **Criticality** | High / Medium / Low — how essential or sensitive this vendor is |
| **RACI** | **Responsible** (does the work), **Accountable** (owns the outcome), **Consulted**, **Informed** |
| **Service category** | SaaS, MSP, subcontractor, data processor, etc. |
| **Review due date** | Next scheduled vendor review |
| **Data classification** | Highest classification of data shared with the vendor |

**Owner** and **Criticality** appear as **table columns and filters** — e.g. *"All High-criticality suppliers without a review in the last 12 months."*

**RACI** is edited on the supplier and displayed directly in the register, giving auditors a clear accountability line for each vendor.

---

## 7️⃣ Governance — Maximum Impact on the Supplier

Supplier document types use governance classification **"This is an asset"** (the same governance model as business and technology assets). This unlocks the **Governance** tab on each supplier document.

### What you configure

| Area | Description |
| ---- |
| **Risk type** | Risk methodology (matrix) applied to this vendor |
| **Maximum impact (Max impacts)** | For each consequence dimension — **financial, reputational, operational, legal, personal/safety**, and others defined in your risk type — set the **worst credible outcome** if this vendor breaches, fails, or mishandles data |
| **Linked risks** | Risk documents that apply to this vendor |
| **Linked controls** | Controls that govern the relationship (vendor assessment, contract clauses, monitoring, access reviews) |
| **Mitigation overview** | How well linked controls cover identified vendor risks |
| **AI identify** | Suggest additional controls, risks, or related records (when Confidential AI is enabled) |

### Why max impact matters for vendors

A payroll SaaS provider and a marketing flyer printer have different breach profiles. Configuring **max impacts** on the supplier document means:

* Risk assessments use **realistic consequence bounds** for vendor scenarios
* Board and management reporting can rank vendors by **inherent business harm**
* DPIA and processor risk analysis align with the **same impact dimensions** as your enterprise risk framework

> 📌 Example: A cloud HR processor might have **High** legal/personal impact (employee PII) and **Medium** operational impact (payroll delay tolerance). A stationery supplier might be **Low** across all dimensions. Both get one supplier record — with different governance profiles.

---

## 8️⃣ Process Kanban — Following Suppliers as a Workflow

Suppliers can be linked to a **process kanban board** (process checklist) so vendor lifecycle stages are visible in the register.

### How it works

| Step | Action |
| ---- |
| **1. Link process** | In the **Status** column, select **Link process** and choose a kanban board (e.g. "Vendor onboarding", "Annual vendor review") |
| **2. Track stage** | Move the supplier through stages — *Requested → Due diligence → Legal review → Approved → Active → Review due → Offboarding* |
| **3. Link tasks** | Attach tasks to the supplier for each stage; assign owners and due dates |
| **4. Monitor** | The **Status** column shows the current stage with colour-coded kanban state |

Document types can have a **default process** configured so new suppliers automatically join the right workflow.

This connects **third-party risk management** to Brainframe's **integrated task system** — onboarding questionnaires, security reviews, and contract sign-offs become trackable work items on the vendor record, not orphaned emails.

> 💡 Pair process kanban with **Supplier review** and **Supplier offboarding** document types for a complete lifecycle: onboard → operate → review → exit.

---

## 9️⃣ Dependencies and Visual Maps

Supplier relationships use the same dependency tools as assets.

### On the supplier document

**Dependencies** panel:

| Section | Meaning |
| ---- |
| **Parent documents** | What this supplier depends on (e.g. a parent **Contract** framework, a **Policy** governing procurement) |
| **Child documents** | What depends on this supplier (linked DPAs, reviews, vulnerabilities, sub-vendor records) |

**Show dependencies in graph diagram** — Interactive graph centred on the supplier; drill into linked documents and return without losing the view.

### Suppliers table — Dependencies & Graph tabs

From **Resources → Suppliers**, switch the table from **List** to:

| Tab | Use |
| ---- |
| **Dependencies** | Tree of each supplier and linked children — see which assets and documents hang off each vendor |
| **Graph** | Network diagram of suppliers and links in the current scope — useful for workshops and TPRM presentations |

### Resources → Dependencies (helicopter view)

Configure a **visual collection** that includes **Supplier** plus **core business**, **digital**, and **physical** asset types. The helicopter graph shows **vendor → asset → business service** chains across the organisation — ideal for supply-chain and concentration-risk analysis.

---

## 🔟 ISO 27001 & GDPR Best Practices

### Build the register (top-down)

1. List **critical and personal-data vendors** first — processors, SaaS, MSPs, subcontractors with system access.
2. Create one **Supplier** record per governed relationship (not per contract amendment — link amendments as child documents).
3. Set **Owner**, **Criticality**, and **RACI** before deep due diligence.
4. Link the **process kanban** for onboarding if your programme uses a standard workflow.

### Attach evidence (bottom-up)

1. Link **NDA**, **contract**, and **DPA** before production data flows.
2. Store **certificates** and **security questionnaires** as linked documents or dedicated security-measures records.
3. Complete a **DPIA** where required and link it to the supplier.
4. Record **supplier reviews** on a schedule (annual for critical, less often for low-risk).

### Connect risk and controls

1. Set **max impacts** on the Governance tab using your risk type's consequence dimensions.
2. Link **controls** — vendor assessment, contract security schedule, monitoring, sub-processor approval.
3. Link or create **risks** for credible vendor failure modes.
4. Use **Related risks** column in the register for management review dashboards.

### Keep it lean

| Do | Avoid |
| ---- |
| One supplier record per **governed vendor relationship** | Duplicate records per project phase |
| Link **asset classes** the vendor supports | Listing every endpoint the vendor could theoretically access |
| Use **Supplier review** documents on a schedule | One-off spreadsheet reviews outside Brainframe |
| Track offboarding with **Supplier offboarding** type | Leaving terminated vendors in "Active" status |

### Evidence auditors expect

* *"Show your supplier inventory."* → **Resources → Suppliers** with Owner and Criticality
* *"Show processor agreements."* → Filter suppliers → **Documents** column → DPA types
* *"How do you monitor vendors?"* → **Supplier review** records + process kanban stages
* *"What is the impact of vendor X failing?"* → Supplier → **Governance** → **Max impacts**
* *"Which systems does vendor X access?"* → **Supporting assets** + **Dependencies** graph

---

## 1️⃣1️⃣ Day-to-Day Workflows

### CISO / third-party risk lead

| Task | Where |
| ---- |
| Review critical vendors | **Suppliers** table → filter Criticality = High |
| Check missing DPAs | Filter suppliers → inspect **Documents** column for DPA gaps |
| Map vendor to business impact | Supplier → **Governance** → max impacts + linked core business assets |
| Annual TPRM report | Export **Dependencies** helicopter graph including suppliers + assets |

### Compliance / privacy officer

| Task | Where |
| ---- |
| Maintain GDPR processor register | **Suppliers** + linked **DPA** and **DPIA** documents |
| Schedule vendor reviews | **Supplier review** documents + process kanban **Review due** stage |
| Evidence for Art. 28 | Open supplier → **Documents** → DPA, security measures, sub-processor list |
| Track legal/compliance risks | **Related risks** column or Governance → linked legal risks |

### Procurement / business owner

| Task | Where |
| ---- |
| Onboard new vendor | **Create new** Supplier → link process kanban → add tasks per stage |
| Document business need | **Business requirement** field on supplier row |
| Assign accountability | **RACI** on supplier record |
| Link what the vendor supports | **Supporting assets** → core business and digital assets |

### Risk owner

| Task | Where |
| ---- |
| Assess vendor-related risk | Risk document → Governance → link **Supplier** as affected asset |
| Understand vendor consequence ceiling | Supplier → Governance → **Max impacts** |
| See control coverage | Supplier → Governance → linked controls + mitigation chart |
