Menu

Vendor monitoring

You hear about a vendor change before your client does

A vendor moves its contracting entity or adds a sub-processor, and every document naming it is quietly wrong. This is the part of the work that has no natural trigger, so it gets one.

Free · No sign-up · Up to ten websites

What is vendor monitoring?

Vendor monitoring is watching the pages a vendor publishes — its data processing agreement, its sub-processor list, its security documentation — and noticing when they change in a way that matters to a client's documentation.

It is the piece of portfolio work with no deadline attached. Nobody asks for it, so it happens when something has already gone wrong: a prospect reads a sub-processor list naming an entity that no longer exists, or an auditor asks when the register was last true and the honest answer is unknown.

What it has to cover

  • A change of contracting entity, which dates every agreement naming it
  • A sub-processor added or removed from the vendor's own list
  • A transfer mechanism replaced
  • A change of hosting region or data location
  • A material change to security commitments

What changes when it is not done by hand

Read by a person

No alert reaches you unreviewed

Every detected change is read and classified by a person before it appears in your workspace. You are not the filter for a feed of page diffs.

Per client

It tells you who is affected

A change shows exactly which of your clients use that vendor and which of their documents name the fact that changed.

Evidence

You can say when you last checked

Each vendor record carries the date it was verified, so the question of when the register was last true has an answer.

What you get

Every vendor fact comes from our own registry: 157 vendors with the date each entry was checked.

Daily checks across the registry

Vendor pages are fetched on a schedule, and differences are detected against the stored snapshot.

Human review before you see it

A change is classified by type and severity by a person, with a short note saying what changed.

Client impact, not just news

Each change lists the clients that use the vendor and the documents to regenerate for each.

Watchlist for vendors outside a client

Watch vendors you care about even when no client has them yet, and get the same alerts.

Documents marked out of date

The affected documents are flagged in each client's workspace rather than waiting to be noticed.

Nothing reaches your clients

Alerts stop with you. What the client hears, and when, is your call.

Get started in three steps

  1. 1

    Have clients with vendors

    Vendors collected in the interview, imported from documents or found by scanning the client's site resolve to registry records.

  2. 2

    Changes are detected and reviewed

    Vendor pages are checked daily; a person reviews each difference before it becomes an alert.

  3. 3

    Act on what matters

    Open the change, see which clients it affects, regenerate the documents that named the old fact.

Questions

Are the alerts generated automatically?
The detection is. The alert is not: a person reads every change and writes the note before it reaches your workspace.
Will my clients be emailed?
No. Nothing goes to your clients from us. You decide what to tell them.
What about a vendor you do not track?
You can add it to a watchlist. Until it has been verified it is shown as unverified rather than as a checked record.
How far back does the history go?
Each vendor record carries the date it was last verified, and changes are kept with the date they were detected and reviewed.
Does it score or rank vendors?
No. It reports what changed. Scoring vendors is not something this product does.

See what changed since your clients' policies were written

Enter up to ten client websites. Free, no sign-up, the first report in about a minute.