Vendors

A register of every third party you rely on, with a risk rating and a review date for each, so your supply-chain due diligence is on record when an auditor asks.

Keep suppliers, cloud providers, contractors and service partners here, with the risk each one carries. Most frameworks expect it: ISO 27001 (an international information-security standard), NIS2 (a European cybersecurity law) and DORA (a European law for financial-sector operational resilience) all ask you to manage third-party risk (the risk that a supplier's failure or breach becomes yours).

This chapter is the screen-by-screen reference. To see the whole journey worked as a story — from "we want to use this supplier" to a rated, monitored vendor — see the full walkthrough in Scenario: onboard and risk-rate a vendor.

Who uses it

What's on this screen

Open /vendors from the Risks group in the left sidebar. Two buttons sit above everything else at the top right — the outlined Import and the dark blue Smart Triage (AI) — then the heading Vendor Management with the subtitle Track and assess third-party vendors, and a dark blue Add Vendor button on the right.

Under the heading is the filter bar: a Search vendors… box with a Search button beside it, an All Statuses dropdown and an All Criticalities dropdown. Then the register table, with a tick box in the header row and on each row for the bulk actions. Left to right the columns are the select box, Name (a link that opens the vendor), Criticality, Data Classification, Rating, Last Assessment, Next Review, Status, Owner and Actions. In a narrow window the table scrolls sideways, with a soft shadow at the edge to show there is more.

In the capture, ratings run from 92/100 in green down to 3/100 in red, and vendors never assessed show a dash under Rating and Not scheduled under Next Review. If your register is empty, the table shows an empty state and you begin at step 3. A Portfolio Report card, a Concentration Risk panel, saved AI briefings and the action items raised from them sit below the table, off the bottom of the screenshot.

  1. Select Import to bring in a list from a spreadsheet. The Import vendors dialog opens.
  2. Select Smart Triage (AI) to ask which vendors need reassessing first. A modal opens with a Run Smart Triage button.
  3. Select Add Vendor to create one by hand. The Add New Vendor dialog opens over the register.
  4. Type a name into Search vendors… and select Search. The table redraws with only the matching vendors; the two dropdowns narrow it further.
  5. Select a vendor's Name. Its detail page opens at /vendors/{id}.
  6. Use the three icons in a row's Actions cell to act without leaving the list: the lightbulb runs an AI investigation, the document icon sends a questionnaire, the box icon archives the vendor. Each opens its own dialog.
The vendor register — /vendors.
The vendor register — /vendors.

Adding a vendor

Three fields are required; the company details underneath are optional.

  1. Enter the Vendor Name. It is the only field that blocks you if left blank.
  2. Choose a Criticality. It starts on Low; the list runs Low, Medium, High, Critical.
  3. Choose a Data Classification. It starts on None; the list runs None, Internal, Confidential, Restricted.
  4. Enter the VAT / registration no. if you have it: the financial screening searches on the registration number. Fill in the rest of Company details as you can — External reference, Category, Address, City, Postal code, Country, Phone and more below the fold.
  5. Select Add Vendor in the footer to save, or Cancel to discard. On save the dialog closes and the register refreshes with the new vendor in it.
Adding a vendor — /vendors.
Adding a vendor — /vendors.

Criticality is how badly a failure would hurt you; Data Classification is what data the vendor can touch. Criticality also sets the default review interval and leads the Smart Triage ordering, so set it honestly.

Importing a list of vendors

  1. Select Import, then Download template in the dialog. An .xlsx template downloads with the columns Aegis expects.
  2. Fill it in, choose your file, and select Validate. A summary appears — valid rows, error rows, and a line per bad row saying what is wrong. Nothing is written yet.
  3. Fix the errors, re-validate, then select Import. Only clean rows are created, and a confirmation says how many vendors were added.
Import always creates new vendors

The importer never matches rows against vendors you already hold, and never updates them. Import the same spreadsheet twice and you get two copies of every row.

Working a vendor from its detail page

Under the breadcrumb sit the vendor name, its status chip, the date it was last updated and a row of action buttons. Then the financial screening card, a Compliance Rollup and Supply Chain Graph side by side, and the Managed Relationships list. Below the fold: the current rating, assessment history, linked evidence and risks, services, security standards, data flows, and side panels of details and dates.

  1. Select AI Analysis to score the vendor from the record Aegis already holds. The button shows Analyzing… while it runs, with a note that it can take a few minutes.
  2. Select Schedule review to set when this vendor comes round again. A dialog asks for a Review interval (days); leave it empty and the interval follows the criticality. On Schedule the date is set that many days out and appears in the register's Next Review column.
  3. Select Raise non-conformity on the right for something that has gone wrong with this supplier, rather than a risk you are still watching.
  4. Read the AI Analysis panel beneath the buttons — in the capture, badges for Score 70/100, Medium risk, Suggested: 3 and Medium confidence, with 55% beside the last. Its sections open to show the security findings, compliance gaps, data-handling risks, DPA analysis and recommendations behind that score. None of it is applied until you act.
  5. Check Financial & KYC Screening for the credit rating and sanctions/PEP (politically exposed person) results. It needs the GraydonCreditsafe integration switched on; until then it reads Creditsafe integration is not configured — contact your operator, as in the capture.
  6. Read Compliance Rollup for the picture across this vendor's supply chain — an Overall Risk badge and counts of Dependencies, Critical Dependencies and High Risk Dependencies — with the Supply Chain Graph beside it drawing the same thing. In the capture no dependency has been recorded, so the badge reads Low, all three counts are 0, and the graph holds the single vendor node.
A vendor's detail page — /vendors/{id}.
A vendor's detail page — /vendors/{id}.

Four more buttons sit in that row. Deep Investigation runs the external background check described below; Deactivate sets the vendor to Inactive (it reads Activate for one already inactive); Recompute risk score re-derives the rating and reports the new score and tier; Download report saves a per-vendor report.

The current rating, explained

An assessment is one scored evaluation at a point in time; the rating is the score currently held. Each assessment updates the rating and the history stays, so you can see whether a vendor is improving or slipping. With no rating, the register shows a dash and the page reads Not Assessed.

Score Label
80–100 Excellent
60–79 Good
40–59 Fair
Below 40 Poor

Requesting an assessment

  1. Select the document icon in the vendor's Actions cell. The questionnaire dialog opens, headed with the vendor's name.
  2. Choose a template — the list holds whatever you have published in Questionnaires.
  3. Enter the Recipient email and, if you want, a custom message, then send. The vendor receives a link, and their answers come back as a scored assessment.

Archiving a vendor

  1. Select the box icon in the vendor's Actions cell.
  2. Read the confirmation dialog, which lists what archiving does, and confirm. The Status changes to Inactive.
  3. To bring it back, filter to Inactive, tick the row and use the bulk Change Status action — or Activate on its detail page.

Bulk actions and export

Ticking rows reveals an action bar showing only what your role allows. Change Status sets the selection to Active or Inactive (Contributor and above). Delete asks for confirmation and removes them permanently (Manager and Admin only). Export downloads the selection as vendors-export-{timestamp}.csv.

The AI assist

All three gather, score and suggest. None changes a vendor's status, rating or owner on its own: a person reviews the output and decides. Investigation works best for well-known software and cloud providers; for a small local supplier it may return very little, so record your own due-diligence files as evidence. AI actions are recorded against your organisation's AI usage.

Tips and limits

Where this connects

Due-diligence files — questionnaire results, audit reports, certifications — belong in Evidence and link back to the vendor. Findings are raised in Risks, questionnaires built in Questionnaires, claimed certifications tracked in Security standards. For a worked example, see the vendor scenario.