🔗 Third-party & supplier risk

Vendor risk teams carry a portfolio of suppliers — each a different criticality, data exposure and assurance age — and a fourth-party tail nobody has mapped. Buy-side APRA entities must also evidence CPS 230/234 obligations through those providers. Spreadsheet registers can't score honestly or show concentration, and they quietly grade unknowns green.

Book a demo → Try it on sample docs
Tier-A breadthVendor register · honest exposure scoring · CPS 230/234 flow-down

Frameworks on the engine serving this vertical

Read from the live catalogue at build time — a framework that is not live on the engine never renders here. Depth is badged per framework: consultant-grade only where we go deepest (ISM/IRAP, Essential Eight), Tier-A breadth everywhere else.

Licence-gated catalogues carry control IDs and CyberSentien's own labels only — the full standard text requires your licence and is never reproduced.

Depth today — stated honestly

Tier-A breadth: a tamper-evident vendor register with criticality tiering, honest exposure scoring, service concentration and fourth-party contagion, due-diligence questionnaires, a contract-clause matrix, CPS 230/234 flow-down conformance (prove-once) and a board / auditor portfolio report. Runs standalone or feeds the bank and consultant consoles — an unassessed supplier is surfaced as unassessed, never scored green.

The global angle

The SOCI Act is Australian, and there is no dedicated SOCI catalogue on the engine yet — this page says so rather than shading it green. The lanes serving the obligations mix Australian depth (Essential Eight, ISM) with internationally used instruments — NIST CSF 2.0, CIS Controls v8 — exactly as live on the catalogue.

See it on the real engine

Run the frameworks above against synthetic sample documents now, or tell us where you sit and we'll send a gated, revocable demo link.

Request the demo →Try it now →