Vendor Risk Management
Matproof’s vendor risk module manages the full lifecycle of third-party relationships — from onboarding and risk assessment through ongoing monitoring and contract review. It produces evidence for GDPR Article 28, DORA Article 28-30, ISO 27001 A.5.19–A.5.23, and SOC 2 CC9.2 simultaneously.What it covers
Adding vendors
Manual entry
- Go to Vendor Risk → Vendors → Add vendor
- Enter name, primary contact email, country of registration, contract value
- Classify by category (ICT, professional services, goods, marketing, financial)
- Save — Matproof creates the vendor record and starts a sanctions screen
Bulk import via CSV
Go to Vendor Risk → Vendors → Import and upload a CSV with the columns Matproof expects:Sync from procurement (optional)
If you run procurement in Coupa, SAP Ariba, or a similar system, Matproof can pull the vendor list via integration. Contact support to enable.Classifying vendors
Each vendor needs three classifications. Set them when you add the vendor or in bulk afterwards.
Matproof’s classification helper asks a few questions about the vendor and recommends a criticality level. You confirm or override.
GDPR Article 28 register
The Article 28 register tracks every processor that handles personal data on your behalf. Required by GDPR for every controller. For each entry Matproof tracks:- Vendor name and primary contact
- Categories of personal data processed (employee data, customer data, special categories, etc.)
- Purpose of processing
- Data transfer mechanism (SCCs / adequacy decision / DPF / not applicable)
- DPA status — signed / pending / not required (with the actual DPA file attached)
- Sub-processor list provided by the vendor
- Last review date
DORA ICT Third-Party Risk
For ICT vendors, Matproof tracks the additional information DORA Article 28–30 requires:- Criticality classification per the EBA guidelines
- Contractual requirements checklist per Article 30 (mandatory clauses: data location, audit rights, exit strategy, sub-contracting limits, etc.)
- Exit strategy — documented plan for migrating off the vendor
- Concentration risk — alerts when too many critical functions depend on one provider, one region, or one parent group
- Sub-processor tracking — vendor’s own sub-processor list, refreshed at each review cycle
- Register of information — the Article 28 ROI export format that DORA-supervised entities submit to their NCA
Vendor questionnaires
Send security and risk questionnaires to your vendors via the Questionnaire AI module. Matproof ships templates aligned to common standards:- DORA ICT third-party assessment — covers Article 30 mandatory clauses
- ISO 27001 vendor security questionnaire — Annex A.5.19–A.5.23 alignment
- GDPR Article 28 data processor assessment — DPA-readiness check
- SIG Lite — Shared Assessments standard
- CAIQ — Cloud Security Alliance standard
Sanctions screening
Matproof screens every vendor on import and monthly afterwards against:- EU Consolidated Sanctions List
- UN Security Council Sanctions
- OFAC Specially Designated Nationals (SDN)
- UK Financial Sanctions
Review cycles
Each vendor has a review frequency tied to its criticality:
Matproof emails the vendor’s owner 30 days before a review is due. The review workflow re-runs the questionnaire, refreshes sanctions screening, and re-confirms criticality.
Questionnaire AI
Send and respond to vendor questionnaires
DORA framework
What DORA Article 28-30 requires of you
Findings
Track vendor gaps in the unified findings view
GDPR
Article 28 obligations