Third-Party Risk Register
Every noodle supplier, tracked, so none goes stale. Vendors, criticality tier, status, review dates with overdue flags, open findings — and a one-click hand-off to the questionnaire generator.
Add vendor
Import
Paste a CSV (a header row with at least a name / vendor column; the other columns are matched by name: service type, tier, status, frameworks, dates, findings, notes) or a JSON export from this tool. Rows are added to the register; a vendor with the same name is updated, and blank cells never erase existing values.
| Frameworks |
|---|
No vendors yet. Add one, or import your existing list as CSV.
Criticality follows the DORA logic for critical or important functions (Art. 3(22)): a vendor whose failure would materially impair operations is critical on that alone; two or more of the four criteria make it critical, one makes it important. The tier drives how deep the questionnaire goes. This is the operational register; for the regulatory Register of Information (DORA Art. 28(3), ITS templates) use the DORA Register of Information builder. The policy this register implements can be drafted with the Policy Document Generator (Third-Party / Supplier Security Policy). Informational only — not legal advice.