Third Party Governance

Supplier risk management, due diligence, data protection agreements (DPAs), subcontracting and ongoing monitoring — in line with DORA’s ICT supplier rules and ISO 27036.

Standards & legislation covered

Shared controls: a supplier assessment covers ISO 27001, DORA and the GDPR (Article 28) — all in one go.

What’s included

One third party control. Every framework that needs it.

Everything you need for third party management — inventory, due diligence, contracts and monitoring — all within the same platform as the rest of your governance.

Vendor inventory & tiering​

Supplier register and classification by criticality.

Due diligence & onboarding​

Due diligence and structured supplier onboarding.

Security assessments​

Security assessments and supplier questionnaires.

DPAs & privacy​

DPA, data transfer mechanisms and privacy due diligence.

DORA ICT suppliers​

Register of ICT suppliers and concentration risk (DORA).

Continuous monitoring​

Continuous monitoring of value chain risk.

Outsourcing governance​

Governance of subcontracting and outsourced services.

Third-party audits​

Third-party audits and follow-up on findings.

Designed for multi-framework use

One third party control. For all frameworks that needs it.

Assess a supplier once and iComply will flag them against all the standards and laws that require it — without any duplication of effort.

Implementation

From scope to continuous assurance.
01

Scope & diagnosis
Define the scope and carry out a GAP analysis against the selected standards.

02

Map controls
Select controls; iComply automatically maps them to each relevant framework.

03

Collect evidence
Assign tasks, upload evidence once and reuse it across all requirements.

04

Audit & monitor
Carry out audits, track CAPA and monitor compliance on an ongoing basis.

Bring third-party governance onto a single platform.