Advisory service · Security, Compliance & Risk

Compliance across the vendor chain — demonstrable and workable

ICT vendors bring risks to continuity, privacy and security. We assess your vendor chain against ISO 27001, GDPR and DORA — and get the file audit-ready.

Your compliance is only as strong as your weakest vendor

Regulators and auditors have long stopped looking only at your own organisation: ISO 27001, the GDPR and DORA all require demonstrable control of risk across the entire chain. That means knowing, per vendor, what data sits where, what's been agreed, and whether it's being followed.

What you get

  • Risk scan per vendor — continuity, privacy and security risks mapped and prioritised by impact.
  • Compliance check — compliance with ISO 27001, GDPR, DORA and NIS2 across the vendor chain assessed, with concrete improvement points.
  • Audit-ready file — a file per vendor or contract that convinces management, customers and regulators alike.

Workable, not a paper tiger

Compliance that only exists on paper won't survive an audit. We set requirements up so they land in your existing contract and vendor processes: measurable in SLAs, assigned to owners, and repeatable at every renewal. Ongoing monitoring is available through VendorManager.nl.

Frequently asked questions

Who does DORA apply to?

DORA applies to financial institutions and their critical ICT service providers. As a supplier to a bank or insurer, you're also drawn in through contracts.

Does this replace ISO 27001 certification?

No — it focuses on the vendor side of your information security: the controls, contracts and files that a certifying body or regulator wants to see about your chain.

What if a vendor doesn't cooperate with the assessment?

That's a finding in itself: the contract determines which audit rights and information duties you have. Where those are missing, we flag them as an improvement point for the next renewal.

Test your sourcing model

Schedule a no-obligation call with Bob Goosen, or start with the free Sourcing Quickscan.

Schedule a call