Vendors · TPRM
Third-party risk, starting from the vendors you didn't know you had.
A vendor register built from the grants in your identity provider and the apps your teams actually sign in to — each one a record with its documents gathered, its questionnaire answered with sourced suggestions, and its sub-processor line published to your trust center.
The way this usually goes
Your vendor list lives in three spreadsheets, none of which agree on who owns what — and none of which list the apps your identity provider has already granted access.
Questionnaires go out by email and come back as PDFs nobody maps to controls.
The sub-processor list on your website was typed in by hand, and nobody is sure it still matches the DPAs.
The vendor lifecycle
From an OAuth grant to a sub-processor line.
A vendor program that starts from a spreadsheet starts from what somebody remembered. Noru's starts from the systems that already know: the grants in your identity provider, the apps your code host authorises, the people who sign in through SSO. From there each vendor gets a record, its documents are fetched rather than chased, and what you learn is disclosed where a customer or a supervisor will look for it.
01 · Discover
Found before they are declared
OAuth grants and service principals in your identity provider, the applications your code host authorises, the people who sign in through SSO — each one a vendor, whether or not anyone registered it.
02 · Register
One record, owned
Every vendor gets an id, a category, an owner and a status, and two records for the same supplier merge into one without losing either side.
03 · Gather
Documents fetched, not chased
Noru researches the vendor's privacy policy, terms, DPA, SLA, trust page and certifications and attaches what it finds, marked as gathered so you can tell it from an upload.
04 · Assess
Answers suggested, sourced
Versioned questionnaire templates mapped to frameworks; the vendor answers through a tokenised link, and AI suggests answers with a confidence and the documents they came from.
05 · Publish
Disclosed where it matters
Sub-processors flow to your trust center from the vendor record, and ICT third parties into the DORA register of information.
One record per vendor
Risk and privacy facts on the same page.
Category, owner and status; inherent and residual risk; processing role, sub-processor flag, data categories, locations, transfers and the DPA's state — on one record, with the evidence tab, the assessments and the people who sign in through it beside them. The score is an assessment, made by an analyst or by Noru's AI with those signals in view, and the record shows the signals so the score can be argued with.
- Two records for one supplier merge without losing either, and unmerge if you were wrong
- Data locations and transfer safeguards recorded as fields, so the Article 30 register and the trust center read them
- Every change on the record lands in the vendor's activity log
Shadow processors
The vendors your identity provider already knows about.
Your identity provider holds a list of every application that has been granted access to your data — delegated by a user or consented by an admin, with the exact scopes. Most of those applications are processors nobody registered. Noru reads the grants, derives a severity from the scopes, notices when one goes dormant, and lets you link each one to a vendor record or add the vendor it belongs to.
- Grant type, consent and scopes read from Microsoft Entra ID and Google Workspace
- Severity derived from the scopes; dormant and revoked tracked as states, never deleted
- Unregistered apps become a decision, not a surprise in the audit
Questionnaires that produce evidence
Answers suggested, sourced, accepted by you.
Templates are versioned and mapped to the frameworks they serve, and the vendor answers through a tokenised link with no account to create. Before they do, Noru reads the documents it gathered and suggests an answer with a confidence, its reasoning and the documents it drew on — and declines when the evidence is weak. What you accept becomes evidence on the controls the question maps to.
- Suggestions cite the vendor's own documents, and say when they are unsure
- Accepted answers land as evidence against ISO 27001 and SOC 2 controls
- Progress and reminders per assignment, without a portal login for the vendor
DORA ICT third parties
The register of information, from the vendor register.
For a financial entity, the vendor register is also the register of information DORA asks for. The DORA frameworks in Noru's library — for the entity, for ICT third-party providers and for the critical ones — map onto the same vendor records, so the addendum, the SLA and the contract facts sit on the record that already holds the DPA.
DORA
DORA (ICT TPP)
DORA (Critical ICT TPP)
The evidence tab
What each vendor record fills up with
Noru researches the vendor's public documents and attaches what it finds, marked as gathered. What no crawler can reach — the signed addendum, the audit report under NDA — is uploaded, and marked as that.
- Privacy policyAI-gathered
- Terms of serviceAI-gathered
- Data processing agreementAI-gathered
- Service level agreementAI-gathered
- Trust pageAI-gathered
- CertificationsAI-gathered
- DORA addendumManual upload
- SOC 2 reportManual upload
It feeds the rest
Sub-processor list, risk register, audit package: one source.
A vendor record is read by three other things. The trust center publishes the sub-processors from it, with purpose, location and DPA state. The risk register takes the vendor's inherent and residual scores as one of its inputs. And an audit package for ISO 27001 or DORA pulls the vendor evidence in with everything else — so the list a customer sees, the risk the board sees and the file the auditor sees are one record, not three.
- Sub-processor disclosure on the trust center, read from the vendor record
- Vendor scores inform the central risk register rather than living in a separate one
- Vendor evidence bundled into audit packages with the rest of the program
Who it's for
One system, every stakeholder
Security & CISO
Every application holding a grant over your data surfaced from the identity provider, scored and owned — not discovered when a customer asks.
Compliance
Questionnaire answers accepted by you become evidence on the ISO 27001 and SOC 2 controls they map to.
Procurement
A security layer that complements your purchasing process instead of replacing it.
Sales & legal
Sub-processor disclosures and DPA states read from the vendor record and published to the trust center, ready the moment customers ask.
What's included
Platform modules working together
This solution runs on the same system of record as everything else — add modules later without re-platforming.
Vendor Risk
See every vendor's posture
A vendor register with risk scoring, security questionnaires and evidence collected from responses.
Risk Register
Know your risk before anyone asks
A live register linked to security findings, controls and treatments — not a yearly workshop artifact.
Evidence Vault
Never chase a screenshot again
Evidence collected continuously from your systems, versioned, tagged and linked to controls automatically.
Trust Center
Publish proof, not promises
A public trust page on your own domain showing your security posture, policies and subprocessors — always current.
Works with
- more
Book a demo
See it on your own data.
A walkthrough against your own identity provider and vendor list, with your questions answered by practitioners.
- 45 minutes, tailored to the frameworks and use cases you care about
- Answers from practitioners, not a sales script
- Leave with a concrete rollout plan — or a clear no-fit
FAQ
Frequently asked questions
What security, compliance and procurement teams ask before they send the first questionnaire.
Talk to usHow do vendors fill in questionnaires?
Vendors receive an email invite and complete the questionnaire inline — no account or portal login required. You see completion progress, can nudge stalled responses, and answers map back to your control framework automatically.
Can we bring our own questionnaire templates?
Yes. You can use Noru's mapped templates as a starting point or build custom ones. Either way, responses link to controls and evidence the same way.
How does vendor risk scoring work?
Each vendor carries inherent and residual likelihood and impact, scored by an analyst or by Noru's AI assessment with the record's signals in view: the data categories and locations it processes, the DPA state, the people who sign in through it and the grants it holds. Those signals sit on the record next to the score so it can be argued with, and the score feeds the central risk register as one of its inputs.
How does Noru find vendors we never registered?
From your identity provider. Microsoft Entra ID and Google Workspace hold every OAuth grant and service principal that has been given access to your data, with the scopes and whether an admin or a user consented. Noru syncs them, derives a severity from the scopes, tracks active, dormant and revoked as states, and lets you link each grant to a vendor record or add the vendor it belongs to.
