Supplier Management
🤝 Supplier & Third-Party Management in Brainframe
"One place for every vendor — contracts, assessments, risks, and the assets they touch."
Brainframe treats each supplier as a governed hub document: link NDAs, DPAs, certificates, reviews, and risks in one register, connect the vendor to your core and digital assets, and track onboarding through process kanban and integrated tasks.
Supplier management in Brainframe works much like asset management — but the focus is third-party and supply-chain risk, not procurement workflows or accounts payable. You are not replacing your ERP or ticketing system. You are building a GRC-grade vendor register where every subcontractor, SaaS provider, MSP, or critical supplier has one central record, with all compliance evidence linked around it.
For CISOs and compliance professionals, this answers: Who are we dependent on? What did we agree with them? What is the impact if they fail or breach? And which of our business assets does this vendor support?
1️⃣ Why Supplier Management Exists
Outsourcing and cloud services mean your security perimeter extends to vendors you do not control directly. Regulations and standards expect you to govern that exposure:
Framework theme | What Brainframe supports |
|---|---|
ISO/IEC 27001:2022 — A.5.19 Information security in supplier relationships | Central supplier register with linked policies and agreements |
A.5.20 Addressing security within supplier agreements | Contracts, NDAs, DPAs, and security commitment documents linked to the supplier |
A.5.21 Managing information security in the ICT supply chain | Dependencies between suppliers and digital/physical assets |
A.5.22 Monitoring, review and change management of supplier services | Supplier reviews, offboarding records, process kanban stages |
A.5.23 Information security for use of cloud services | Cloud/SaaS vendors linked to supporting digital assets |
GDPR Art. 28 Processor relationships | Data processing agreements and DPIAs linked to the vendor |
SOC 2 / NIS2 Third-party risk | Risk documents, certificates, and control evidence per vendor |
Brainframe is designed so vendor evidence feeds risk assessment and audit — not so it replaces contract negotiation or vendor billing systems.
💡 Think vendor risk register, not procurement portal. Brainframe tells you whether the vendor is governed and what breaks if they do — not how much you pay them this quarter.
2️⃣ One Supplier, One Central Hub
The core idea mirrors asset management: one governed document per vendor (or vendor class), with everything else linked to it.
Traditional approach | Brainframe approach |
|---|---|
DPA in SharePoint, SOC report in email, review in spreadsheet | All documents linked to the Supplier record |
"Which systems does Vendor X touch?" — answered in meetings | Supporting assets column and Dependencies graph |
Vendor risk in a separate tool | Legal, business, and security risks linked on Governance and in the register |
Onboarding status in someone's inbox | Process kanban stage on the supplier row + tasks linked to the vendor |
A single Supplier document becomes the index page for that third party. Auditors open one record and see agreements, assessments, linked assets, risks, tasks, and review history — without hunting across folders.
📌 Like assets, you typically model one Brainframe supplier per governed vendor relationship — not one record per invoice, support ticket, or individual contact at the vendor (those belong in linked documents or your operational tools).
3️⃣ The Suppliers Register
Open the left sidebar → Resources → Suppliers.
The register opens as a table view with a document-type dropdown covering the supplier lifecycle:
Document type | Typical use |
|---|---|
Supplier | Main vendor / subcontractor record — the central hub |
Supplier review | Periodic due-diligence and performance reviews |
Supplier technical and organisational security measures | Documented security commitments, questionnaires, SOC summaries |
Supplier offboarding | Exit checklist when terminating a vendor relationship |
Use the dropdown to focus on one type or Show all to see the full vendor population in one list.
The supplier management table is richer than a standard document list. Key columns include:
Column | What it shows |
|---|---|
Status | Current process kanban stage when a supplier is linked to a workflow (e.g. Onboarding → Due diligence → Approved → Review due) |
RACI | Responsible, Accountable, Consulted, Informed — people or roles for vendor ownership |
Task | Linked tasks (including integration tasks from JIRA, Asana, Monday, Azure DevOps) |
Supporting assets | Core business, digital, and physical assets this vendor supports or accesses |
Documents | Linked supporting documents grouped by type (NDAs, contracts, DPAs, etc.) |
Business requirement | Free-text ISMS / business requirements specific to this vendor |
Related risks | Linked risk documents with latest risk readings where configured |
💡 Columns such as Documents and Supporting assets are built from linked records. When you edit a supplier, you configure which document types appear in each automatic filter — so your register shows exactly the evidence categories your programme cares about.
4️⃣ Creating and Documenting Suppliers
✨ Create new (with template)
- Open Resources → Suppliers.
- Select Supplier (or another supplier document type) in the dropdown.
- Click Create new.
- Complete the template — supplier document types include structured sections to capture vendor scope, services provided, data handled, criticality, and compliance context.
Templates keep vendor documentation consistent across the organisation, which matters for ISO audits and GDPR processor registers.
✨ Asset wizard (digital / physical supplier types)
On supplier-related document types configured as assets, the Create asset wizard (✨ button next to Create new) offers the same AI-assisted flow as for digital and physical assets: describe the vendor, link controls, assess risks, build a mitigation plan, and create the document with governance links persisted.
Use this when onboarding a critical vendor where you want structured risk and control mapping from day one.
5️⃣ Linking Evidence to a Supplier
Open a supplier → Edit (from the register) or manage links from the document's Dependencies and Governance tabs.
📄 Supporting documents (central evidence locker)
Link documents that prove and govern the vendor relationship. Workspaces commonly include:
Evidence category | Examples of linked document types |
|---|---|
Confidentiality | Non-disclosure agreements (NDA) |
Data protection | Data processing agreements (DPA), DPA reviews |
Privacy assessments | Data protection impact assessments (DPIA) |
Commercial terms | Contracts, statements of work, terms & conditions |
Assurance | Certificates (ISO 27001, SOC 2, PCI), penetration-test summaries |
Security posture | Supplier technical and organisational security measures |
Reviews | Supplier review records, audit reports |
General files | PDFs, uploaded documents, policies addressed to the vendor |
Auto filter supporting documents — When editing a supplier, choose which document types appear in the Documents column and automatic filters. Default configurations often include NDAs, contracts, DPAs, DPIA, and general documents — your administrator can extend this to vulnerabilities, legal risks, or any custom type.
You can upload files directly when linking supporting documents, so signed PDFs land in the vendor folder and attach to the supplier in one step.
🏗 Supporting assets (what the vendor touches)
Link core business, digital, and physical assets that depend on or are exposed through this vendor:
- A SaaS HR platform → linked to Payroll process (core business) and HR application (digital)
- A managed SOC provider → linked to Security monitoring service and SIEM platform
- A hosting provider → linked to Customer portal and Production database
Auto filter supporting assets — Configure which asset types surface in the Supporting assets column (typically digital, physical, and core business types).
This is how you answer audit questions like "Show all vendors with access to personal data systems" — filter the register or open a supplier and read its asset links.
⚠️ Related risks
Link legal risks, business risks, risk scenarios, and other risk document types configured for your workspace. The Related risks column shows linked risks with latest risk readings (severity scores) when available.
Typical vendor risks:
- Sub-processor breach exposing customer data
- Vendor service outage impacting critical business process
- Non-compliance with contractual security clauses
- Fourth-party (supply chain) exposure
✅ Tasks and integrations
Link tasks from Brainframe's integrated task management — including tickets synced from JIRA, Asana, Monday, or Azure DevOps. Tasks appear in the supplier row so remediation, onboarding steps, and audit actions stay tied to the vendor.
6️⃣ Metadata — Owner, Criticality, and RACI
Supplier records support the same metadata properties as assets, configured per document type under Workspace Settings → Document types:
Property | Purpose |
|---|---|
Owner | Internal owner of the vendor relationship (e.g. procurement lead, business sponsor) |
Criticality | High / Medium / Low — how essential or sensitive this vendor is |
RACI | Responsible (does the work), Accountable (owns the outcome), Consulted, Informed |
Service category | SaaS, MSP, subcontractor, data processor, etc. |
Review due date | Next scheduled vendor review |
Data classification | Highest classification of data shared with the vendor |
Owner and Criticality appear as table columns and filters — e.g. "All High-criticality suppliers without a review in the last 12 months."
RACI is edited on the supplier and displayed directly in the register, giving auditors a clear accountability line for each vendor.
7️⃣ Governance — Maximum Impact on the Supplier
Supplier document types use governance classification "This is an asset" (the same governance model as business and technology assets). This unlocks the Governance tab on each supplier document.
What you configure
Area | Description |
|---|---|
Risk type | Risk methodology (matrix) applied to this vendor |
Maximum impact (Max impacts) | For each consequence dimension — financial, reputational, operational, legal, personal/safety, and others defined in your risk type — set the worst credible outcome if this vendor breaches, fails, or mishandles data |
Linked risks | Risk documents that apply to this vendor |
Linked controls | Controls that govern the relationship (vendor assessment, contract clauses, monitoring, access reviews) |
Mitigation overview | How well linked controls cover identified vendor risks |
AI identify | Suggest additional controls, risks, or related records (when Confidential AI is enabled) |
Why max impact matters for vendors
A payroll SaaS provider and a marketing flyer printer have different breach profiles. Configuring max impacts on the supplier document means:
- Risk assessments use realistic consequence bounds for vendor scenarios
- Board and management reporting can rank vendors by inherent business harm
- DPIA and processor risk analysis align with the same impact dimensions as your enterprise risk framework
📌 Example: A cloud HR processor might have High legal/personal impact (employee PII) and Medium operational impact (payroll delay tolerance). A stationery supplier might be Low across all dimensions. Both get one supplier record — with different governance profiles.
8️⃣ Process Kanban — Following Suppliers as a Workflow
Suppliers can be linked to a process kanban board (process checklist) so vendor lifecycle stages are visible in the register.
How it works
Step | Action |
|---|---|
1. Link process | In the Status column, select Link process and choose a kanban board (e.g. "Vendor onboarding", "Annual vendor review") |
2. Track stage | Move the supplier through stages — Requested → Due diligence → Legal review → Approved → Active → Review due → Offboarding |
3. Link tasks | Attach tasks to the supplier for each stage; assign owners and due dates |
4. Monitor | The Status column shows the current stage with colour-coded kanban state |
Document types can have a default process configured so new suppliers automatically join the right workflow.
This connects third-party risk management to Brainframe's integrated task system — onboarding questionnaires, security reviews, and contract sign-offs become trackable work items on the vendor record, not orphaned emails.
💡 Pair process kanban with Supplier review and Supplier offboarding document types for a complete lifecycle: onboard → operate → review → exit.
9️⃣ Dependencies and Visual Maps
Supplier relationships use the same dependency tools as assets.
On the supplier document
Dependencies panel:
Section | Meaning |
|---|---|
Parent documents | What this supplier depends on (e.g. a parent Contract framework, a Policy governing procurement) |
Child documents | What depends on this supplier (linked DPAs, reviews, vulnerabilities, sub-vendor records) |
Show dependencies in graph diagram — Interactive graph centred on the supplier; drill into linked documents and return without losing the view.
Suppliers table — Dependencies & Graph tabs
From Resources → Suppliers, switch the table from List to:
Tab | Use |
|---|---|
Dependencies | Tree of each supplier and linked children — see which assets and documents hang off each vendor |
Graph | Network diagram of suppliers and links in the current scope — useful for workshops and TPRM presentations |
Resources → Dependencies (helicopter view)
Configure a visual collection that includes Supplier plus core business, digital, and physical asset types. The helicopter graph shows vendor → asset → business service chains across the organisation — ideal for supply-chain and concentration-risk analysis.
🔟 ISO 27001 & GDPR Best Practices
Build the register (top-down)
- List critical and personal-data vendors first — processors, SaaS, MSPs, subcontractors with system access.
- Create one Supplier record per governed relationship (not per contract amendment — link amendments as child documents).
- Set Owner, Criticality, and RACI before deep due diligence.
- Link the process kanban for onboarding if your programme uses a standard workflow.
Attach evidence (bottom-up)
- Link NDA, contract, and DPA before production data flows.
- Store certificates and security questionnaires as linked documents or dedicated security-measures records.
- Complete a DPIA where required and link it to the supplier.
- Record supplier reviews on a schedule (annual for critical, less often for low-risk).
Connect risk and controls
- Set max impacts on the Governance tab using your risk type's consequence dimensions.
- Link controls — vendor assessment, contract security schedule, monitoring, sub-processor approval.
- Link or create risks for credible vendor failure modes.
- Use Related risks column in the register for management review dashboards.
Keep it lean
Do | Avoid |
|---|---|
One supplier record per governed vendor relationship | Duplicate records per project phase |
Link asset classes the vendor supports | Listing every endpoint the vendor could theoretically access |
Use Supplier review documents on a schedule | One-off spreadsheet reviews outside Brainframe |
Track offboarding with Supplier offboarding type | Leaving terminated vendors in "Active" status |
Evidence auditors expect
- "Show your supplier inventory." → Resources → Suppliers with Owner and Criticality
- "Show processor agreements." → Filter suppliers → Documents column → DPA types
- "How do you monitor vendors?" → Supplier review records + process kanban stages
- "What is the impact of vendor X failing?" → Supplier → Governance → Max impacts
- "Which systems does vendor X access?" → Supporting assets + Dependencies graph
1️⃣1️⃣ Day-to-Day Workflows
CISO / third-party risk lead
Task | Where |
|---|---|
Review critical vendors | Suppliers table → filter Criticality = High |
Check missing DPAs | Filter suppliers → inspect Documents column for DPA gaps |
Map vendor to business impact | Supplier → Governance → max impacts + linked core business assets |
Annual TPRM report | Export Dependencies helicopter graph including suppliers + assets |
Compliance / privacy officer
Task | Where |
|---|---|
Maintain GDPR processor register | Suppliers + linked DPA and DPIA documents |
Schedule vendor reviews | Supplier review documents + process kanban Review due stage |
Evidence for Art. 28 | Open supplier → Documents → DPA, security measures, sub-processor list |
Track legal/compliance risks | Related risks column or Governance → linked legal risks |
Procurement / business owner
Task | Where |
|---|---|
Onboard new vendor | Create new Supplier → link process kanban → add tasks per stage |
Document business need | Business requirement field on supplier row |
Assign accountability | RACI on supplier record |
Link what the vendor supports | Supporting assets → core business and digital assets |
Risk owner
Task | Where |
|---|---|
Assess vendor-related risk | Risk document → Governance → link Supplier as affected asset |
Understand vendor consequence ceiling | Supplier → Governance → Max impacts |
See control coverage | Supplier → Governance → linked controls + mitigation chart |
Updated on: 13/07/2026
Thank you!