Noru

Vendors · TPRM

Third-party risk, starting from the vendors you didn't know you had.

A vendor register built from the grants in your identity provider and the apps your teams actually sign in to — each one a record with its documents gathered, its questionnaire answered with sourced suggestions, and its sub-processor line published to your trust center.

The way this usually goes

Your vendor list lives in three spreadsheets, none of which agree on who owns what — and none of which list the apps your identity provider has already granted access.

Questionnaires go out by email and come back as PDFs nobody maps to controls.

The sub-processor list on your website was typed in by hand, and nobody is sure it still matches the DPAs.

The vendor lifecycle

From an OAuth grant to a sub-processor line.

A vendor program that starts from a spreadsheet starts from what somebody remembered. Noru's starts from the systems that already know: the grants in your identity provider, the apps your code host authorises, the people who sign in through SSO. From there each vendor gets a record, its documents are fetched rather than chased, and what you learn is disclosed where a customer or a supervisor will look for it.

01 · Discover

Found before they are declared

OAuth grants and service principals in your identity provider, the applications your code host authorises, the people who sign in through SSO — each one a vendor, whether or not anyone registered it.

02 · Register

One record, owned

Every vendor gets an id, a category, an owner and a status, and two records for the same supplier merge into one without losing either side.

03 · Gather

Documents fetched, not chased

Noru researches the vendor's privacy policy, terms, DPA, SLA, trust page and certifications and attaches what it finds, marked as gathered so you can tell it from an upload.

04 · Assess

Answers suggested, sourced

Versioned questionnaire templates mapped to frameworks; the vendor answers through a tokenised link, and AI suggests answers with a confidence and the documents they came from.

05 · Publish

Disclosed where it matters

Sub-processors flow to your trust center from the vendor record, and ICT third parties into the DORA register of information.

A new grant, a new sign-in or a re-scan reconciles back to the record it belongs to

One record per vendor

Risk and privacy facts on the same page.

Category, owner and status; inherent and residual risk; processing role, sub-processor flag, data categories, locations, transfers and the DPA's state — on one record, with the evidence tab, the assessments and the people who sign in through it beside them. The score is an assessment, made by an analyst or by Noru's AI with those signals in view, and the record shows the signals so the score can be argued with.

  • Two records for one supplier merge without losing either, and unmerge if you were wrong
  • Data locations and transfer safeguards recorded as fields, so the Article 30 register and the trust center read them
  • Every change on the record lands in the vendor's activity log
Vendors/NORU-VND-118 · Helios CRM
Live
Privacy/Connected apps
3 need review

Shadow processors

The vendors your identity provider already knows about.

Your identity provider holds a list of every application that has been granted access to your data — delegated by a user or consented by an admin, with the exact scopes. Most of those applications are processors nobody registered. Noru reads the grants, derives a severity from the scopes, notices when one goes dormant, and lets you link each one to a vendor record or add the vendor it belongs to.

  • Grant type, consent and scopes read from Microsoft Entra ID and Google Workspace
  • Severity derived from the scopes; dormant and revoked tracked as states, never deleted
  • Unregistered apps become a decision, not a surprise in the audit

Questionnaires that produce evidence

Answers suggested, sourced, accepted by you.

Templates are versioned and mapped to the frameworks they serve, and the vendor answers through a tokenised link with no account to create. Before they do, Noru reads the documents it gathered and suggests an answer with a confidence, its reasoning and the documents it drew on — and declines when the evidence is weak. What you accept becomes evidence on the controls the question maps to.

  • Suggestions cite the vendor's own documents, and say when they are unsure
  • Accepted answers land as evidence against ISO 27001 and SOC 2 controls
  • Progress and reminders per assignment, without a portal login for the vendor
Vendors/Assessments · Helios CRM

DORA ICT third parties

The register of information, from the vendor register.

For a financial entity, the vendor register is also the register of information DORA asks for. The DORA frameworks in Noru's library — for the entity, for ICT third-party providers and for the critical ones — map onto the same vendor records, so the addendum, the SLA and the contract facts sit on the record that already holds the DPA.

  • DORADORA
  • DORA (ICT TPP)DORA (ICT TPP)
  • DORA (Critical ICT TPP)DORA (Critical ICT TPP)

The evidence tab

What each vendor record fills up with

Noru researches the vendor's public documents and attaches what it finds, marked as gathered. What no crawler can reach — the signed addendum, the audit report under NDA — is uploaded, and marked as that.

  • Privacy policyAI-gathered
  • Terms of serviceAI-gathered
  • Data processing agreementAI-gathered
  • Service level agreementAI-gathered
  • Trust pageAI-gathered
  • CertificationsAI-gathered
  • DORA addendumManual upload
  • SOC 2 reportManual upload

It feeds the rest

Sub-processor list, risk register, audit package: one source.

A vendor record is read by three other things. The trust center publishes the sub-processors from it, with purpose, location and DPA state. The risk register takes the vendor's inherent and residual scores as one of its inputs. And an audit package for ISO 27001 or DORA pulls the vendor evidence in with everything else — so the list a customer sees, the risk the board sees and the file the auditor sees are one record, not three.

  • Sub-processor disclosure on the trust center, read from the vendor record
  • Vendor scores inform the central risk register rather than living in a separate one
  • Vendor evidence bundled into audit packages with the rest of the program
Trust center/Subprocessors
Live

Who it's for

One system, every stakeholder

Security & CISO

Every application holding a grant over your data surfaced from the identity provider, scored and owned — not discovered when a customer asks.

Compliance

Questionnaire answers accepted by you become evidence on the ISO 27001 and SOC 2 controls they map to.

Procurement

A security layer that complements your purchasing process instead of replacing it.

Sales & legal

Sub-processor disclosures and DPA states read from the vendor record and published to the trust center, ready the moment customers ask.

Book a demo

See it on your own data.

A walkthrough against your own identity provider and vendor list, with your questions answered by practitioners.

  • 45 minutes, tailored to the frameworks and use cases you care about
  • Answers from practitioners, not a sales script
  • Leave with a concrete rollout plan — or a clear no-fit

We respond within one business day. No mailing lists, no spam.

FAQ

Frequently asked questions

What security, compliance and procurement teams ask before they send the first questionnaire.

Talk to us

How do vendors fill in questionnaires?

Vendors receive an email invite and complete the questionnaire inline — no account or portal login required. You see completion progress, can nudge stalled responses, and answers map back to your control framework automatically.

Can we bring our own questionnaire templates?

Yes. You can use Noru's mapped templates as a starting point or build custom ones. Either way, responses link to controls and evidence the same way.

How does vendor risk scoring work?

Each vendor carries inherent and residual likelihood and impact, scored by an analyst or by Noru's AI assessment with the record's signals in view: the data categories and locations it processes, the DPA state, the people who sign in through it and the grants it holds. Those signals sit on the record next to the score so it can be argued with, and the score feeds the central risk register as one of its inputs.

How does Noru find vendors we never registered?

From your identity provider. Microsoft Entra ID and Google Workspace hold every OAuth grant and service principal that has been given access to your data, with the scopes and whether an admin or a user consented. Noru syncs them, derives a severity from the scopes, tracks active, dormant and revoked as states, and lets you link each grant to a vendor record or add the vendor it belongs to.