Skip to content

Your vendor questionnaire never asks who owns the company

Every third-party assessment I have seen asks the same three things. What data does the vendor touch. Where does it run. Who can reach our systems.

All good questions. And then it stops, and never asks the one that carries close to strict liability.

The check with no threshold

EU sanctions law does not have a size threshold, a sector limit, or a materiality carve-out. It does not care that the vendor is a €400-a-month SaaS tool, or that you are forty people, or that the contract is a renewal you have had since 2019. Ownership and control screening applies, and the consequences of getting it wrong are not the kind you close with a corrective action.

It also takes about two minutes per vendor.

That combination — high consequence, no threshold, trivial effort — is exactly the sort of thing that should be automatic, and in most supplier registers it simply is not present. Not deprioritised. Absent. There is no column for it.

The reason is structural rather than negligent. Registers get built by security people, from security frameworks, and the sanctions obligation sits in a different body of law that nobody's control framework put in front of them. So it falls in the gap between legal and security, which is where obligations go to be nobody's job.

A register that does the work rather than recording it

That is the check the workbook I have published builds in, but the ownership screening is only the piece that was missing. The rest of it is an attempt to fix a second problem: most registers are filing cabinets. Somebody makes a decision in a meeting, and afterwards somebody else types it into a spreadsheet.

This one sits before the decision.

The requester does the thinking, without learning the standard. The intake form asks plain questions. What data goes there. Who can reach our systems. How fast could we replace them. The workbook turns the answers into a score across five axes and names a tier. Nobody types a tier, which means nobody negotiates one.

Twenty-one stop signals sit between the request and the approval. Each names its own legal basis, so a "no" can go straight into an email without anyone having to go and look up why. That detail matters more than it sounds: the reason bad vendors get approved is rarely that somebody decided to approve them, it is that saying no required forty minutes of research nobody had.

A sanctions hit stops everything. Not a flag, not a risk acceptance, not a conditional approval with a follow-up date. It is the one gate in the workbook that does not have a path through it.

Where the evidence lands

Every assessment ends in a register row with a date, an owner and a result. Every unanswered questionnaire question becomes a finding with a deadline, rather than a silent tick that nobody notices until an auditor samples it.

That is the difference between a register that produces evidence and one that produces a document. The first survives an audit sample. The second produces a conversation about what the tick meant in March.

It comes with a twelve-step walkthrough, screenshotted from a live worked example running end to end, and it maps to Commission Implementing Regulation (EU) 2024/2690 Annex 5.1 and 5.2, NIS2 Article 21(2)(d), and ISO/IEC 27001:2022 A.5.19 to A.5.23.

Fill in the tinted cells. The scoring, the tier, the questionnaire scope and the stop signals compute themselves.

The supplier register, with the check nobody builds in →

CIR (EU) 2024/2690 Annex 5.1 and 5.2 · NIS2 Art. 21(2)(d) · ISO/IEC 27001:2022 A.5.19 to A.5.23 · Reg. (EU) No 269/2014 Art. 2. Practitioner material, not legal advice. Sanctions screening is a legal determination; build the obligation in, and get the determination from someone qualified to make it.