Vendor reviews that do not live in email

Supplier reviews usually begin in email and are forgotten until a customer asks. Keep the supplier, owner, risk level, evidence and next review date in one record.

Who this is for: For teams that need a repeatable way to review suppliers without building a procurement function.

Separate critical suppliers from ordinary tools

Record what the supplier does, which data it touches, who owns the relationship and how often it should be reviewed.

  • Supplier owner
  • Risk level
  • Next review date

Make reassessment visible

Supplier reviews should not depend on memory. Due dates and open items show what needs attention.

Reuse the work

Vendor notes and documents can support GDPR records, customer questionnaires and ISO 27001 supplier controls.

Common questions

Do we still need an auditor?

Yes. We help you prepare the work: scope, owners, policies, risks and evidence. An auditor still decides what is acceptable for certification, and legal interpretation stays with qualified advisers.

Which integrations are available today?

The current evidence sources are GitHub, Google Workspace and AWS. Jira can be used for remediation work. Other systems should be treated as manual evidence unless they are scoped separately.

What can AI help with?

AI can prepare drafts, summarise notes and suggest first-pass wording. Scope, evidence approval, legal interpretation and customer-facing statements still need owner review.

Which standards should we lead with?

ISO 27001 and GDPR are the strongest starting points. SOC 2, NIS2 and DORA can be handled as preparation or mapping work once the exact scope is agreed.