Skip to main content
PLATFORM · SUPPLIER RISK

One supplier record. Every regulation that references it.

Vendor risk is typically assessed once at contract signing and rarely revisited — while NIS2 Art. 21(2)(d) and DORA's ICT third-party chapter both expect continuous oversight. A questionnaire in a drawer is not oversight.

TruSecure maintains one continuous supplier risk register that feeds every regulation referencing supplier or third-party risk simultaneously. One supplier, one record, every regime that cares about that supplier reading from the same page.

How it works

  1. Register

    Every supplier gets one record: the services it provides, the data it touches, the criticality of what depends on it.

  2. Assess

    Inherent risk is scored from what the supplier is to you — not from a generic questionnaire template — and reassessed on a cycle matched to criticality.

  3. Monitor

    Certification status, contract and SLA data, and assessment outcomes stay current through the year, connected where a TPRM system already exists.

  4. Feed every regime

    NIS2’s supply-chain clause, DORA’s third-party register, ISO 27001’s supplier controls — each reads the same record. Assess the supplier once; answer every framework.

What a supplier record looks like

Supplier record · cloud hosting providerSample data
Services
IaaS · backup
Criticality
high
Citations
NIS2 21(2)(d) · DORA Art. 28 · ISO A.5.19
Assessment
current
Next review
2026-12-01

Which regulations it maps to

Third-party obligations · by framework
FrameworkWhat it expectsCitation
NIS2Supply-chain security as a risk-management measureArt. 21(2)(d)
DORAA register of ICT third-party arrangements, maintainedArt. 28
ISO 27001Supplier relationship controls, defined and operatingA.5.19–5.22

Already running a TPRM or vendor-risk tool? TruSecure's supplier and TPRM connectors pull assessments, contract data and certification status from it — the register enriches what you have rather than replacing it.

When a supplier changes — a certificate lapses, a sub-processor is added, a disclosed incident lands — the register changes with it, and every regime reading that supplier sees the new state at once. There is no second register to update, and no quarter in which the answer quietly goes stale.

The monitoring loop

continuous · every 6 hours
  1. 01

    Connect

    Read-only connectors into AWS, Azure, GCP, on-premise.

    AWSAzureGCPon-prem
  2. 02

    Collect

    AI pulls compliance evidence every 6 hours — not at audit time.

    every 6 h
  3. 03

    Detect

    Gaps and control drift flagged the moment they appear.

    24/7
  4. 04

    Remediate

    Routine fixes closed automatically; the rest routed to you.

    auto
  5. 05

    Approve

    A named person decides. The approval is the record.

    logged
90% less manual evidence work100% audit-ready, every day

The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.