Stakeholder/Vendor Management
One current register of the suppliers and partners you depend on - each risk-assessed, re-assessing itself on schedule, and wired straight into your risk register.
Keep one current register of every supplier, partner and stakeholder, each scored against a consistent risk questionnaire that re-assesses on its own schedule, with concerning findings raised for review.
Connect supplier decisions to evidence, risk and the products affected
Keep suppliers, partners and other stakeholders in one register, with the classification, contacts, contract references and review cadence that decide how much attention each one needs.
Assessments, supporting documents and review dates live on the record, and a questionnaire result that suggests a problem feeds a risk workflow a person reviews. The register is where a supplier decision can be explained later, not just recorded.
What it looks like

Keep supplier and stakeholder details in one register. A supplier appears here as soon as it is recorded; being listed is not an assessment.
Use cases
Answer the due-diligence question
When a customer or auditor asks how you vet your suppliers, the answer is a live register and a full assessment history - evidence, not a reassurance.
Score every supplier the same way
One weighted questionnaire applied consistently gives every vendor an explainable 0–100 risk score and band, so scoring no longer depends on who filled the form in.
Reviews that chase themselves
Re-assessment dates set from each vendor’s risk arrive as tasks in your ComplyTrain list - the high-risk suppliers come round sooner, and nobody has to remember.
Find the answer in the contract
Contracts and certificates are held against the vendor they belong to, indexed and searchable in plain language - ask when a certificate expires or what a vendor committed to on breach notification, with the source quoted.
Everything third-party risk needs, in one place
Explainable risk scoring
A consistent, weighted questionnaire produces a live 0–100 score and risk band you can show an auditor line by line.
Reviews that schedule themselves
Each vendor’s re-assessment date sets itself from its risk and arrives as a task in your ComplyTrain list - the register stays current on its own.
Findings become managed risks
Concerning assessment answers are raised as risks in your risk register, linked to the vendor and waiting for a person to review.

Supplier profile
Record how much attention each supplier needs
A supplier profile carries its classification, its contacts, the contract it sits under and how often it should be reviewed. That is what decides the depth of diligence: a critical single-source supplier and a stationery vendor should not receive the same questionnaire or the same review cadence.
Supporting documents attach to the record, and the products or work that depend on a supplier are linked, so the question "what does this affect?" has an answer before it becomes urgent.
- Classification, contacts and contract reference on the record
- Review cadence set by how critical the relationship is
- Supporting documents held with the supplier, not in an inbox

Due diligence
Use a structured questionnaire, and review what it produces
Assessments are configurable questionnaires mapped to the kind of entity being reviewed, so the questions asked of a supplier are the ones that matter for that relationship. Answers drive scoring rules, and a result that suggests a problem raises it into the risk workflow for a person to consider.
The questionnaire above has not been answered yet. The score it displays is the calculation on an empty form rather than a finding about the supplier, and a low number on an unanswered assessment is not assurance. An assessment means something once it is completed and reviewed.
- Questionnaires configured per entity type, not one form for everybody
- Scoring rules that route a concern into a reviewed risk, not an automatic verdict
- Review dates tracked, so diligence is repeated rather than done once
