Skip to content
    ← all services · governance & compliance

    Procurement & Third-Party Governance.

    Sourcing policy, supplier due diligence and third-party risk across privacy, security, AI and sector requirements.

    get started →

    APPLICABLE FRAMEWORKS · DORA · NIS2 · GDPR · EU AI Act
    § 01the assessment

    Sourcing policy, supplier due diligence and third-party risk across privacy, security, AI and sector requirements.

    Suppliers now carry a large share of an organisation's regulatory exposure: data processors, cloud and ICT providers, AI vendors and outsourced services.

    We bring procurement and third-party risk onto one process, from sourcing policy and due diligence through contracting and ongoing monitoring, drawing on partners who have run procurement functions themselves.

    key benefits
    One due diligence process instead of several
    Supplier risk visible across privacy, security and AI
    Contract terms that match the risk
    Evidence ready for regulators and auditors
    § 02what we can do

    The work, itemised.

    01Sourcing and procurement policy
    02Supplier tiering and due diligence questionnaires
    03Third-party risk assessment across privacy, security and AI
    04Contract requirements and clauses
    05Ongoing monitoring and exit planning
    § 03instructing us

    Ready to discuss procurement & third-party governance?

    Get in touch with our team to learn how we can support your organisation.

    contact us →