Supplier risk management, due diligence, data protection agreements (DPAs), subcontracting and ongoing monitoring — in line with DORA’s ICT supplier rules and ISO 27036.
Shared controls: a supplier assessment covers ISO 27001, DORA and the GDPR (Article 28) — all in one go.
What’s included
One third party control. Every framework that needs it.
Everything you need for third party management — inventory, due diligence, contracts and monitoring — all within the same platform as the rest of your governance.
Vendor inventory & tiering
Supplier register and classification by criticality.
Due diligence & onboarding
Due diligence and structured supplier onboarding.
Security assessments
Security assessments and supplier questionnaires.
DPAs & privacy
DPA, data transfer mechanisms and privacy due diligence.
DORA ICT suppliers
Register of ICT suppliers and concentration risk (DORA).
Continuous monitoring
Continuous monitoring of value chain risk.
Outsourcing governance
Governance of subcontracting and outsourced services.
Third-party audits
Third-party audits and follow-up on findings.
Designed for multi-framework use
One third party control. For all frameworks that needs it.
Assess a supplier once and iComply will flag them against all the standards and laws that require it — without any duplication of effort.