Skip to content

The supplier register, with the check nobody builds in

Commission Implementing Regulation (EU) 2024/2690 and ISO/IEC 27001:2022 A.5.19 to A.5.23. A supplier register that does the work rather than recording it after the fact: someone fills in a request form, the workbook scores it across five axes, names a tier, tells them what that tier demands, and refuses to let the request through until every gate is clear. It comes with a twelve-step walkthrough and a worked example running through every screenshot on this page.

The part most registers leave out is the last one. Almost every third-party assessment I have seen asks what data the vendor touches, where it runs and who can reach it — and never asks who owns the company. That is a compliance obligation with no size threshold, no sector limit and close to strict liability, and it takes about two minutes per vendor.

Artefacts

Artefact Type Format
Supplier and third-party risk register Twelve-tab workbook: intake, tiering, questionnaire, findings, exit, calendar, screening .xlsx
Twelve-step walkthrough Slide deck, screenshots of a live worked example .pptx

Download and adapt

Both files are hosted here on the domain, no third-party requests. Fill in the tinted cells only — the scoring, the tier, the questionnaire scope and the stop signals all compute themselves. The document IDs inside (P1-13, REG-17 to REG-21, PRC-02 to PRC-06) are placeholders for documents you already have under some other name; the Read me tab maps each one.

What the register actually does

Three things, in this order.

It makes the requester do the thinking, without making them learn the standard. The intake form asks plain questions — what data goes there, who can reach our systems, how fast could we replace them — and turns the answers into a score. Nobody types a tier.

It refuses to be a filing cabinet. Twenty-one stop signals sit between the request and the approval. Each one names its own legal basis, so a "no" can go into an email without anyone looking anything up.

It keeps the evidence where an auditor will look for it. Every assessment lands in a register row with a date, an owner and a result, and every unanswered question becomes a finding with a deadline rather than a silent tick.

The twelve steps

1 · Fill in the request

The request form, section one: request number, date, requester, provider, product, website, the reason for the request and the date it is needed, with guidance text in the right-hand column

One request per third party. The tinted cells are the only ones anyone touches. If a question cannot be answered with confidence, the instruction is to pick the less favourable option — over-classifying costs a questionnaire, under-classifying costs the audit.

2 · Answer the data question honestly

The request form, section three: what data the third party sees, whether it is stored permanently, whether the provider can read it in the clear, and whether it is used for training

This is the single most consequential answer in the form. Special categories under Article 9 GDPR score three points and push the request to Critical on their own, regardless of anything else. "Passing through" and "storing permanently" are both transfers. "Unknown" about training use is a finding with a deadline, not a tick.

Section ten, first half: registered company name, register court and number, ultimate parent company and country of ultimate control, filled in for a fictional cloud backup provider

You cannot screen what you have not named. "Microsoft 365" is not a company. The register court and number pin the entity down; the ultimate parent and the country of ultimate control matter just as much as the name, because a clean-looking German GmbH can still be controlled from somewhere that changes the answer.

4 · Run the screening and record it

Section ten, second half: ownership disclosed, screening result, date of screening, lists checked, screened by, and where the evidence is stored

Six fields, and every one of them is evidence. The date matters more than the result — the lists change constantly, so a check without a date proves nothing a year later. Name the person who ran it and store the screenshot: a check with no checker is not evidence.

5 · Look the company up

Free, official, no registration. Roughly two minutes per vendor.

Where What it is
EU consolidated list of financial sanctions The binding one for an EU undertaking. Start and finish here.
EU Sanctions Map Which regime applies to which country, and what each one restricts.
EU Sanctions Helpdesk Run by DG FISMA, built for SMEs, and it offers cost-free personalised due-diligence support. If you have no compliance function, this is the most useful link on this page.
OFAC Sanctions List Search Where there is a US nexus — which, for most software and hardware estates, there is.
US Consolidated Screening List Several US agency lists in one search.

Search three things, never one

The company, the ultimate parent, and the controlling persons. A company that is not itself listed is still caught where a listed person holds more than 50 % of it or otherwise controls it. Screening only the name on the invoice is the failure mode this control exists to prevent.

6 · Read the result

The computed result block: the five axes scored three, one, two, three and one, a total of ten, a base tier of three, the override "D1=3 special categories, at least Critical", and a final tier of Critical shown in pink

Five axes, zero to three points each. In the worked example the score is ten, which on its own would mean High — and then the override fires, because special-category data is involved, and the tier becomes Critical. Overrides only ever raise a tier. They never lower one.

That asymmetry is deliberate. A score is an average of five things, and averages hide exactly the risk you most need to see.

7 · See what the tier requires

The tier requirements block: questionnaire scope, evidence required, audit right in the contract, incident notification duty, exit plan, reassessment cycle and approver, all computed from the tier

The tier is not a label. It decides the questionnaire scope, the evidence you must collect, the clauses that go in the contract, who may approve, and how often the whole thing is redone. At Critical: the full questionnaire, a certificate or equivalent report, a penetration test summary, a processor contract, a sub-processor list, a documented and tested exit plan, and annual reassessment.

8 · Clear every stop signal

The stop signals block, showing an explanatory note and one fired signal: personal data with no processor contract in place, with its legal basis cited

An empty row means the signal does not apply. A filled row means something has to be settled before anyone approves anything. In the worked example one has fired: personal data is involved and there is no processor contract, so until one exists, no data flows.

A stop signal is not advice. It is a gate.

9 · A sanctions hit stops everything

A fired sanctions stop signal in pink: match or suspected match, nothing is approved and nothing flows, escalate to the managing directors, citing Article 2 of Regulation (EU) No 269/2014

This is the one signal with no workaround and no proportionality argument.

The prohibition it enforces is the Bereitstellungsverbot — Article 2 of Regulation (EU) No 269/2014 and the parallel provisions in the other sanctions regimes. No funds and no economic resources may be made available, directly or indirectly, to a listed person or entity. It binds every natural and legal person in the EU. There is no size threshold and no sector carve-out.

Two things about it are worth being precise on, because they are commonly muddled:

This is not the anti-money-laundering regime. An ordinary IT company is not an obliged entity under the German Money Laundering Act or its equivalents elsewhere. No KYC duty, no compliance officer, no suspicious activity reporting. That part genuinely does not apply.

There is no statute that says "you must screen". The prohibition is absolute; the screening duty is derived from it, with the organisational-supervision duty — in Germany § 130 OWiG — as the hook that makes not having a process sanctionable in itself. That derivation is standard practice among German practitioners, but it is not uncontested in the literature, and I am not a lawyer. Have your own counsel frame it in their own words before you rely on the wording in this workbook.

10 · Decide, and record the conditions

The decision block: decision, decided by, date of decision, conditions and rationale, and the supplier ID assigned in the register

Only whoever the tier names may approve. "Approved with conditions" is a real answer — but it only means something if it says what is missing, by when, and who is fetching it, and if each condition also becomes a row on the Findings sheet. Otherwise it is a promise, not a control.

Refusals stay in the request log. They are the evidence that selection criteria were actually applied, which is what Annex No. 5.1.2 asks for.

11 · Hand it over into the register

The handover sheet showing the completed request laid out in the exact column order the register expects, with the supplier ID, name, contact and service details populated

The handover sheet lays the request out in exactly the column order the register expects. Copy as values — pasting formulas overwrites the computed columns. Assign the supplier ID yourself; it is the key every other sheet joins on.

Without a complete register the Annex No. 5.2 duty is not met, and that duty applies to every direct supplier, including the ones you tiered as Low. Tiering decides how deeply you assess. It does not decide whether you list them.

The last columns of the register: legal entity and register number, country of ultimate control, screening date and screening result, with a placeholder row above a completed one

These four columns are what make the screening auditable months later. Re-screening rides on the reassessment cycle that already exists — there is no second calendar to maintain.

12 · Send the questionnaire the tier calls for

The questionnaire sheet: numbered questions with area, question text, the tier from which each applies, the evidence required and the source for each one

The "applies from tier" column decides who gets which question, and it is cumulative — a question marked Medium also goes to High and Critical. Tier Low gets no questionnaire at all, only the register entry. Every question names its source, so the supplier can see it was not invented on the way to the meeting.

"We do not have that" is a valid answer. It becomes a finding, not an argument.

Questionnaire rows F23 and F24: one asking for the full legal entity and ultimate parent, one asking the supplier to declare whether it, its parent or a controlling person is on an EU, UN or US sanctions list

The last two questions are the ones people forget to ask. F23 wants the legal entity and the group structure; F24 asks the supplier to declare its own sanctions status. The declaration supplements your own check — it never replaces it, because a company willing to lie on a form is exactly the case the control exists for.

What the five axes are

Axis What it measures 3 points means
D1 Data What the third party sees, stores or transmits Special categories under Article 9 GDPR
D2 Access What technical access it holds to your systems Standing privileged access to production
D3 Dependency How fast you could replace it No workable alternative
D4 Process Which of your processes depends on it A process with very high protection needs and an MTPD of 24 hours or less
D5 Onward transfer Sub-processors and where processing happens Third country with no adequacy decision, or a chain that was never disclosed

Twelve to fifteen points is Critical, eight to eleven High, four to seven Medium, zero to three Low — before the overrides, which set a floor and never a ceiling.

D4 is the axis that assumes something. It expects you to already know which of your processes are critical and what their maximum tolerable period of disruption is. If you do not, that is a business impact analysis, and it is a different piece of work — see protection needs and how criticality is inherited.

Primary sources

Germany-specific rows in the workbook are marked as such. They are BSIG § 30(2) and § 203(3) and (4) StGB.