Strategy & Ambition
Legal & Compliance
IT Infrastructure X-Ray
Risk & Opportunities
Improvements
Policies & Procedures
Measures & Controls
Operations
Leadership & Management
Compliance
Progress Overview
Audit View
Logging and Monitoring Information
External Audit ISO 27001
MS365 Integration Supporting Documentation
Suppliers Overview

Your organization must systematically assess and manage security risks related to suppliers and other third parties, such as partners, to safeguard information and assets from potential threats. This includes establishing controls and processes to ensure the information and data shared with or accessed by suppliers is protected against unauthorized access, disclosure, alteration, or loss.
To maintain effective supplier relationships, implement the following security measures and expectations:
- Maintain a structured approach to managing security risks associated with suppliers, ensuring appropriate protection of shared or accessible information.
- Establish and enforce security requirements in contractual agreements with suppliers to mitigate risks related to access, processing, and storage of information.
- Monitor and control changes to supplier services to maintain security requirements and ensure continuous compliance.
- Implement a formal policy for supplier management to define the onboarding process, risk assessment and oversight mechanisms.
- Continuously assess supplier performance against agreed security requirements and take corrective action when necessary.
When implementing security, privacy and quality controls and processes to address risks associated with suppliers, you should consider the following key aspects:
- Ensure that each supplier has a contractual agreement defining specific information security requirements and obligations, tailored to the type of services provided. If personal data is shared or accessed by the supplier, an appropriate data processing agreement should be also put in place.
- Keep a current and up to date overview of all suppliers in the Supplier Overview.
- Implement the Supplier Management Procedure, which can be accessed in the Compleye Online Templates Section to establish and document consistent and structured processes.
- Check whether the supplier holds ISO 27001 certification or any other relevant certifications, such as SOC 2, to ensure they meet the required security and compliance standards for managing information security risks.
- Implement proper controls to manage changes in supplier relationships, ensuring ongoing security compliance. This should be overseen during compliance meetings, where the onboarding and offboarding of suppliers are discussed and managed.
- Where applicable, regularly review, audit, and assess suppliers to verify adherence to contractual security requirements. This can be achieved by implementing relevant Operational Planning and Control (OPCs), where the monitoring of supplier relationships is scheduled at planned intervals.
- Perform systematic risk assessments to evaluate potential security, privacy and quality threats posed by suppliers, ensuring alignment with your risk management framework.
Supplier Overview Management:
To streamline supplier risk management, you should maintain a structured Supplier Overview, which includes key details for monitoring and compliance.
This section captures essential supplier details, including:
- Supplier name, service description, jurisdiction, and contact details.
- Supplier assigned owner.
- Supplier profile classification for grouping and easy retrieval.
- Contract execution details, including type, start date, and signed agreements, ensuring centralized records for audit purposes.
- IT access rights, with an option to flag suppliers with software access for integration with Access Management.
- Export functionality to generate supplier reports for internal use and audits.
Supplier Compliance Management
The ‘Compliance Tab’ helps organizations determine whether suppliers meet necessary security and privacy standards. Key considerations include:
Consider the following key points when completing the ‘Supplier Compliance Tab’:
- Compliance-related information can be gathered from supplier websites, contractual agreements, publicly available sources, or directly from suppliers in security statements or other relevant documents.
- It is recommended to assess whether a supplier complies with GDPR requirements and document this in the ‘GDPR Policy in Place’ checkbox. To verify compliance, you can request or locate the supplier’s publicly available Privacy Statement and check if it addresses key GDPR obligations. Be sure to upload the Supplier Privacy Statement to the ‘Supplier Compliance Tab’.
- Determine if the supplier is ISO 27001 certified and record this information in the ‘Supplier Compliance Tab’. The certification status is crucial, as it may influence the risk assessment, particularly if the supplier is classified as high risk.
- If the supplier holds other certifications, such as SOC 1, SOC 2, SOC 3, or SOC for Cybersecurity, document and record these certifications in the ‘Supplier Compliance Tab’ If available, upload the relevant certification documents as evidence.
- Depending on the scope of services and the contractual relationship, various agreements may be executed to formalize the relationship with the supplier. These may include, but are not limited to:
- Non-Disclosure Agreements (NDAs) or other Confidentiality Agreements
- Terms and Conditions or other general user agreements
- Data Processing Agreements (DPAs) for personal data processing activities
- Service Level Agreements (SLAs) outlining expected service levels
- Any other relevant contractual agreements related to the provision of agreed services
Ensure that all signed agreements and certifications are uploaded to the ‘Supplier Compliance Tab’ to facilitate audits and support risk assessments.
Supplier Risk Profiling
To classify and manage supplier risk levels, organizations should:
- Define clear risk criteria for evaluating supplier risks.
- Assign a risk profile for each supplier from the security, quality, and business continuity perspectives. This should involve evaluating potential risks in these areas to ensure that each supplier’s impact on the organization’s operations, security and privacy posture, as well as service quality is properly assessed and managed.
- Maintain consistent and transparent risk assessments using predefined standards.
- Record whether suppliers have access to IT infrastructure, applications, or sensitive data, particularly personal data. This can be achieved by marking the relevant information in the Risk Profile tab of the Supplier Overview and using the ‘Add New Field’ functionality to customize and record the necessary details.
Low | Medium | High | |
Information security | Supplier has no access to information and data, including personal data and/or source code | Supplier only has access to metadata on information and data, including personal data and/or source code | The supplier has access to the end-user data (including personal data) and/or to the IT infrastructure |
Business Continuity | In the event of a supply interruption switching to a comparable service is relatively easy/ | A supply interruption causes short-term problems within important business processes | A supply interruption causes mid-term to long term problems within important business processes |
Quality | Supplier has no direct effect or influence on the quality or performance of products delivered or services provided by the organization. | Supplier has certain effect or influence the quality or performance of product delivered or services provided by the organization. | Supplier has a significant effect or influence the quality or performance of product delivered or services provided by the organization. |
The accepted risk criteria are incorporated into the Supplier Management Procedure. Based on the evaluation and information gathered in the General and Compliance sections, determine the most appropriate risk profile for each supplier, taking into account the established risk criteria. Supplier risk profiling, necessary to determine the initial risk score, should be categorized into three levels: High, Medium, or Low.
| GENERAL | ||
| Field Name | Value | Example |
| Name | Free text field | Compleye |
| Owner | Select owner from a drop-down menu function. | [Name team member] |
| Status | Select status from a drop-down menu, options are Active or Inactive. | Active |
| Profile | Select a business profile from a drop-down menu, options are: Business Services Provider MarCom Office Tools Project Management Tools Third-Party Data Provider Documentation Storage Other | Business Services |
| Supplier Headquarters | Indicate suppliers’ headquarter in a free text format. | Amsterdam, The Netherlands |
| Jurisdiction of Supplier | Indicate supplier’s country of residence in a free text format. | Amsterdam |
| Type of Contract | Indicate contract type in a free text format. | Paid Subscription |
| Date of Contract | Select a date using an embedded calendar. | [date picker] |
| +Upload Document | [Upload the confirmation of Assignment] | |
| Run Time | Specify service run time in a free format text. | 1 year |
| Used Since | Select a date using an embedded calendar. | [date picker] |
| Closed Since | Select a date using an embedded calendar. | – |
| Main Contact | Indicate the main contact in a free text format. | Karolin Kruiskamp |
| Contact Details | Indicate contact details in a free text format. | info@compleye.io |
| Field Name | Value | Example / tips |
| Terms & conditions available | Select the checkbox to indicate an affirmative choice. If required, include additional information in a free text format. | [selection] |
| GDPR policy in place | Select the checkbox to indicate an affirmative choice. | [some suppliers have specific GDPR policies or statements available, most of them are available on the website of the supplier] |
| NDA/Confidentiality agreement signed | Select the checkbox to indicate an affirmative choice. If required, include additional information in a free text format. | [selection] |
| Data process agreement | Select the checkbox to indicate an affirmative choice. If required, include additional information in a free text format. | [if yes, add the DPA in the DPA overview under Section Legal & Compliance – GDPR] |
| Software license agreement | Select the checkbox to indicate an affirmative choice. If required, include additional information in a free text format. | [selection, if yes add the SLA to this section] |
| Certifications | Select the checkbox to indicate an affirmative choice. If required, include additional information in a free text format. | [check on the website what kind of certifications are more in place .. e.g. ISO9001, SOC-2, etc.] |
| Extra Info | Include any additional information, if available. | [what ever info you think might be valuable – and use this section also for notes if there are changes] |
| Upload Document | Upload relevant documents, if available. |
| Field Name | Value | Example |
| Risk Criteria | Include prescribed risk criteria in a free text format. | [Use the content in Wiki as an example, adjust if needed, and add to the Criteria info box in Procedure/Info section] |
| Information Security Risk | Select determined risk profile from a drop-down menu, options are Low, Medium, High. | Low |
| Business Continuity | Select determined risk profile from drop-down menu options are Low, Medium, High. | Medium |
| Upload Document | Upload relevant document, if available. | |
| Part of Outsourced ISO27001 | Select the checkbox to indicate an affirmative choice. | |
| Stakeholder in Access Management Overview | Checkbox combined with Descriptive Free Text. | |
| Access to Restricted Data Resources | Select the checkbox to indicate an affirmative choice. If required, include additional information in a free text format. | |
| Involved in Security Procedure | Select the checkbox to indicate an affirmative choice. If required, include additional information in a free text format. |

