The supplier register, with the check nobody builds in¶
Commission Implementing Regulation (EU) 2024/2690 and ISO/IEC 27001:2022 A.5.19 to A.5.23. A supplier register that does the work rather than recording it after the fact: someone fills in a request form, the workbook scores it across five axes, names a tier, tells them what that tier demands, and refuses to let the request through until every gate is clear. It comes with a twelve-step walkthrough and a worked example running through every screenshot on this page.
The part most registers leave out is the last one. Almost every third-party assessment I have seen asks what data the vendor touches, where it runs and who can reach it — and never asks who owns the company. That is a compliance obligation with no size threshold, no sector limit and close to strict liability, and it takes about two minutes per vendor.
Artefacts¶
| Artefact | Type | Format |
|---|---|---|
| Supplier and third-party risk register | Twelve-tab workbook: intake, tiering, questionnaire, findings, exit, calendar, screening | .xlsx |
| Twelve-step walkthrough | Slide deck, screenshots of a live worked example | .pptx |
Download and adapt
Both files are hosted here on the domain, no third-party requests. Fill in the tinted cells only — the scoring, the tier, the questionnaire scope and the stop signals all compute themselves. The document IDs inside (P1-13, REG-17 to REG-21, PRC-02 to PRC-06) are placeholders for documents you already have under some other name; the Read me tab maps each one.
What the register actually does¶
Three things, in this order.
It makes the requester do the thinking, without making them learn the standard. The intake form asks plain questions — what data goes there, who can reach our systems, how fast could we replace them — and turns the answers into a score. Nobody types a tier.
It refuses to be a filing cabinet. Twenty-one stop signals sit between the request and the approval. Each one names its own legal basis, so a "no" can go into an email without anyone looking anything up.
It keeps the evidence where an auditor will look for it. Every assessment lands in a register row with a date, an owner and a result, and every unanswered question becomes a finding with a deadline rather than a silent tick.
The twelve steps¶
1 · Fill in the request¶

One request per third party. The tinted cells are the only ones anyone touches. If a question cannot be answered with confidence, the instruction is to pick the less favourable option — over-classifying costs a questionnaire, under-classifying costs the audit.
2 · Answer the data question honestly¶

This is the single most consequential answer in the form. Special categories under Article 9 GDPR score three points and push the request to Critical on their own, regardless of anything else. "Passing through" and "storing permanently" are both transfers. "Unknown" about training use is a finding with a deadline, not a tick.
3 · Identify the legal entity behind the product¶

You cannot screen what you have not named. "Microsoft 365" is not a company. The register court and number pin the entity down; the ultimate parent and the country of ultimate control matter just as much as the name, because a clean-looking German GmbH can still be controlled from somewhere that changes the answer.
4 · Run the screening and record it¶

Six fields, and every one of them is evidence. The date matters more than the result — the lists change constantly, so a check without a date proves nothing a year later. Name the person who ran it and store the screenshot: a check with no checker is not evidence.
5 · Look the company up¶
Free, official, no registration. Roughly two minutes per vendor.
| Where | What it is |
|---|---|
| EU consolidated list of financial sanctions | The binding one for an EU undertaking. Start and finish here. |
| EU Sanctions Map | Which regime applies to which country, and what each one restricts. |
| EU Sanctions Helpdesk | Run by DG FISMA, built for SMEs, and it offers cost-free personalised due-diligence support. If you have no compliance function, this is the most useful link on this page. |
| OFAC Sanctions List Search | Where there is a US nexus — which, for most software and hardware estates, there is. |
| US Consolidated Screening List | Several US agency lists in one search. |
Search three things, never one
The company, the ultimate parent, and the controlling persons. A company that is not itself listed is still caught where a listed person holds more than 50 % of it or otherwise controls it. Screening only the name on the invoice is the failure mode this control exists to prevent.
6 · Read the result¶

Five axes, zero to three points each. In the worked example the score is ten, which on its own would mean High — and then the override fires, because special-category data is involved, and the tier becomes Critical. Overrides only ever raise a tier. They never lower one.
That asymmetry is deliberate. A score is an average of five things, and averages hide exactly the risk you most need to see.
7 · See what the tier requires¶

The tier is not a label. It decides the questionnaire scope, the evidence you must collect, the clauses that go in the contract, who may approve, and how often the whole thing is redone. At Critical: the full questionnaire, a certificate or equivalent report, a penetration test summary, a processor contract, a sub-processor list, a documented and tested exit plan, and annual reassessment.
8 · Clear every stop signal¶

An empty row means the signal does not apply. A filled row means something has to be settled before anyone approves anything. In the worked example one has fired: personal data is involved and there is no processor contract, so until one exists, no data flows.
A stop signal is not advice. It is a gate.
9 · A sanctions hit stops everything¶

This is the one signal with no workaround and no proportionality argument.
The prohibition it enforces is the Bereitstellungsverbot — Article 2 of Regulation (EU) No 269/2014 and the parallel provisions in the other sanctions regimes. No funds and no economic resources may be made available, directly or indirectly, to a listed person or entity. It binds every natural and legal person in the EU. There is no size threshold and no sector carve-out.
Two things about it are worth being precise on, because they are commonly muddled:
This is not the anti-money-laundering regime. An ordinary IT company is not an obliged entity under the German Money Laundering Act or its equivalents elsewhere. No KYC duty, no compliance officer, no suspicious activity reporting. That part genuinely does not apply.
There is no statute that says "you must screen". The prohibition is absolute; the screening duty is derived from it, with the organisational-supervision duty — in Germany § 130 OWiG — as the hook that makes not having a process sanctionable in itself. That derivation is standard practice among German practitioners, but it is not uncontested in the literature, and I am not a lawyer. Have your own counsel frame it in their own words before you rely on the wording in this workbook.
10 · Decide, and record the conditions¶

Only whoever the tier names may approve. "Approved with conditions" is a real answer — but it only means something if it says what is missing, by when, and who is fetching it, and if each condition also becomes a row on the Findings sheet. Otherwise it is a promise, not a control.
Refusals stay in the request log. They are the evidence that selection criteria were actually applied, which is what Annex No. 5.1.2 asks for.
11 · Hand it over into the register¶

The handover sheet lays the request out in exactly the column order the register expects. Copy as values — pasting formulas overwrites the computed columns. Assign the supplier ID yourself; it is the key every other sheet joins on.
Without a complete register the Annex No. 5.2 duty is not met, and that duty applies to every direct supplier, including the ones you tiered as Low. Tiering decides how deeply you assess. It does not decide whether you list them.

These four columns are what make the screening auditable months later. Re-screening rides on the reassessment cycle that already exists — there is no second calendar to maintain.
12 · Send the questionnaire the tier calls for¶

The "applies from tier" column decides who gets which question, and it is cumulative — a question marked Medium also goes to High and Critical. Tier Low gets no questionnaire at all, only the register entry. Every question names its source, so the supplier can see it was not invented on the way to the meeting.
"We do not have that" is a valid answer. It becomes a finding, not an argument.

The last two questions are the ones people forget to ask. F23 wants the legal entity and the group structure; F24 asks the supplier to declare its own sanctions status. The declaration supplements your own check — it never replaces it, because a company willing to lie on a form is exactly the case the control exists for.
What the five axes are¶
| Axis | What it measures | 3 points means |
|---|---|---|
| D1 Data | What the third party sees, stores or transmits | Special categories under Article 9 GDPR |
| D2 Access | What technical access it holds to your systems | Standing privileged access to production |
| D3 Dependency | How fast you could replace it | No workable alternative |
| D4 Process | Which of your processes depends on it | A process with very high protection needs and an MTPD of 24 hours or less |
| D5 Onward transfer | Sub-processors and where processing happens | Third country with no adequacy decision, or a chain that was never disclosed |
Twelve to fifteen points is Critical, eight to eleven High, four to seven Medium, zero to three Low — before the overrides, which set a floor and never a ceiling.
D4 is the axis that assumes something. It expects you to already know which of your processes are critical and what their maximum tolerable period of disruption is. If you do not, that is a business impact analysis, and it is a different piece of work — see protection needs and how criticality is inherited.
Related¶
- Third-party (ICT) risk assessment, start to finish — the same problem under DORA Chapter V, with the criticality decision driving the lifecycle
- Protection needs, and how criticality is inherited — where the D4 values come from
- NIS2 — the branch this artefact belongs to
- Your vendor questionnaire never asks who owns the company — the post that goes with this register
Primary sources¶
- Commission Implementing Regulation (EU) 2024/2690 — Annex Nos. 5.1.1 to 5.1.7 and 5.2, the supplier register and supply chain security requirements
- Directive (EU) 2022/2555 (NIS2) — Article 21(2)(d), supply chain security
- Regulation (EU) No 269/2014 — Article 2, the prohibition the screening exists to prevent breaching
- Regulation (EU) 2016/679 (GDPR) — Articles 9, 26, 28, 32, 33, 35 and 44 to 49
- ENISA technical implementation guidance on Regulation (EU) 2024/2690
- ISO/IEC 27001:2022 A.5.19 to A.5.23 — supplier relationships (not linkable; the standard is sold, not published)
Germany-specific rows in the workbook are marked as such. They are BSIG § 30(2) and § 203(3) and (4) StGB.