Assessment templates
Start with built-in NIS2 supplier risk, ISO 27001, GDPR Article 28 full and lite, and concentration-risk questionnaires. Customise them or create your own.
Collect consistent evidence, record findings and keep follow-up visible in one lightweight system designed for recurring supplier oversight.
Start with built-in NIS2 supplier risk, ISO 27001, GDPR Article 28 full and lite, and concentration-risk questionnaires. Customise them or create your own.
Send suppliers a response link with no portal account required. Track status and due dates while keeping each completed assessment attached to its supplier.
A finding records a control gap or weak response, its severity, recommended action, status and contribution to risk. It turns assessment evidence into follow-up work.
Inherent risk is the exposure before controls are considered. Residual risk is what remains after controls and remediation. Supplira keeps both visible over time.
Set due dates, send automatic reminders and see overdue assessments so recurring oversight does not depend on personal spreadsheets and calendar notes.
Maintain account activity and assessment history to support internal review and demonstrate that supplier risk decisions were followed up.
Generate a management-ready report covering current posture, suppliers with the highest residual risk, finding themes, overdue work and recommended actions.
Classify business criticality, data access, system access and legal posture before sending a questionnaire, helping teams prioritise effort by exposure.
Use the dashboard to see programme status and, on applicable plans, export data for further review and reporting.