Supply Chain Monitoring
Know which supplier puts you at risk — continuously, not just at the annual audit. Included from your first active supplier, no separate booking required.
A list isn't enough anymore — a continuously maintained register is.
"If my IT provider goes down, I don't know what's at stake for us — and I can't prove that I have my suppliers under control either." That is how managing directors and CISOs at mid-sized companies describe their situation the moment a customer questionnaire or a supervisor asks specifically about the supply chain. NIS2 Art. 21(2)(d) (§ 30(2) no. 4 BSIG), DORA Art. 28–29, and ISO 27001 A.5.19 all demand the same answer: suppliers and service providers must be assessed, managed, and demonstrably under control.
A spreadsheet of suppliers is quick to set up, but it goes stale the moment no one actively maintains it: no traceable justification for the criticality rating, no version history, no proof of who last reviewed it and when. At the next audit, that is exactly what counts — and an annual snapshot is worthless between two audits once the supplier base has already changed.
That's why supply chain monitoring in ReportAct isn't a separate booking — it's included with every active supplier: criticality is continuously reassessed, questionnaires run in the background, contracts are AI-reviewed against the mandatory controls — and every state is sealed, regardless of location or booked service.
Four building blocks that turn a list into a register of proof.
Supplier register with AI-assisted criticality
Every supplier is assigned a criticality tier with AI assistance — with a rationale you can review and correct if needed, never a black-box result. An approval workflow ensures a rating only becomes binding after sign-off.
Supplier questionnaires
Questionnaires go out directly to suppliers, and answers come together in the portal. Customer questionnaires that arrive at your own organization are answered from the same pool of data — one data foundation for both directions.
AI contract review against mandatory controls
Upload supplier contracts — the AI reviews clause by clause whether the required controls are covered, with source location, quote, and confidence score. No finding is adopted without your confirmation, and the result is sealed as evidence. Today for the 47 DORA contractual requirements (Art. 30); further catalogs are on the way.
Sealed evidence
Every state of the register is cryptographically sealed (RSA signature plus RFC 3161 timestamp) and independently verifiable — a single piece of evidence that counts for NIS2, DORA, and ISO 27001 at once.
How continuous monitoring works.
Capture the supplier
Added manually or synchronized through an integration — including an AI criticality suggestion.
Send questionnaire & review contract
Send a questionnaire, upload a contract — the AI reviews answers and clauses against the mandatory controls.
Seal the state
Every change to criticality, answers, or contract review is recorded as a new, sealed state.
A core building block for these regimes.
The basis for the ICT third-party register under Art. 28–29 and the 47 contractual requirements under Art. 30.
Regulation details →Supply chain security as one of the ten risk management measures under Art. 21(2).
Regulation details →Supplier relationships under A.5.19 — continuous assessment instead of an annual snapshot.
Regulation details →Your first sealed supplier register — today.
We'll show you how continuous monitoring works using your own supplier data.