The vendor and sub-processor register
ISO 27001 Annex A.5.19 and GDPR Article 28 both expect a register of the third parties you rely on. Each vendor records its kind (SaaS, hosting, payment and more), country, the data it can access (none, personal or special-category), a link to its DPA and its certificates such as ISO 27001 or SOC 2, notes, a next review date and a contract-expiry date.
- Two charts show vendors by data access and by review status: overdue, due within 30 days, scheduled or without a date.
- Filter on review overdue, contract expiring within 30 days, no DPA or full data access; sort by name, next review or contract expiry.
- Vendor reviews that are due arrive in the same daily digest as expiring evidence.
The asset inventory
One inventory for hardware, applications, databases and other assets, each with an owner, a criticality and a classification. Assets link to processing activities, risks, processes and controls, so you can see what depends on what.
Import, export and the trust page
- Download the vendor and asset registers as Excel and CSV from Basic upwards.
- On Enterprise, import existing registers from Excel or CSV with column mapping and a preview.
- Choose which vendors appear as sub-processors on your public trust page.
- Auditors read both registers in their own portal; vendor events go out as webhooks on Enterprise.
