Supplier Due Diligence & Audit
Strengthen trust and reduce risk across your supplier ecosystem
Independent audits. Regulatory assurance. Clear risk visibility
Identify compliance and security risks in supplier relationships
Verify data protection and accountability standards under GDPR and the EU AI Act
Demonstrate resilience and maturity in procurement and partnerships
Turning supplier risk into a structured compliance advantage
Supplier risk is no longer a background issue. It is a direct compliance exposure.
Suppliers are often the weakest link in data protection and security frameworks. A single gap in oversight can lead to regulatory scrutiny, operational disruption, and loss of trust. Organisations remain accountable for how their suppliers handle data, security, and regulatory obligations. Without structured oversight, risks remain hidden until they surface through incidents or audits. This service provides a structured, independent view of supplier risk. It enables your organisation to identify weaknesses, validate controls, and make informed decisions backed by evidence.
Our Approach
Review
Examine vendor data protection, AI governance, and security practices against GDPR, ISO 27701, and the EU AI Act.
Align
Check vendor obligations against contractual and regulatory requirements, ensuring governance and accountability are in place.
Report
Deliver a structured audit report with findings, risks, and recommendations for remediation.
Resolve
Support follow-up actions and provide guidance to help vendors address findings and strengthen compliance posture.
The Result: Assured Oversight of Supplier Compliance
Verified Risk Controls
Documented evidence of supplier practices and vulnerabilities, benchmarked against regulatory requirements.
Procurement Confidence
Independent assurance that strengthens supplier selection, contracting, and renewal processes.
Demonstrated Accountability
Clear audit trails and governance records that meet regulator and partner expectations.
Frequently Asked Questions
-
Supplier due diligence becomes a legal obligation as soon as a supplier processes personal data on your behalf or impacts your ability to comply with GDPR.
Under Article 28, you must only use processors that provide “sufficient guarantees” to implement appropriate technical and organisational measures. Under Article 5(2) and Article 24, you remain accountable for all processing carried out under your responsibility, including by suppliers.
For high-risk processing, Article 35 requires a DPIA, which includes assessing risks linked to key processors. In practice, once a supplier handles personal data or supports critical processing, due diligence is no longer optional. It is part of your legal responsibility.
-
You remain accountable, even if the failure sits with your supplier.
Under the accountability principle and Recital 74, controllers are responsible for processing carried out on their behalf. Article 82 establishes that individuals can claim compensation for damage caused by GDPR breaches.
Where multiple parties are involved, joint and several liability applies. This means your organisation can be held fully liable, even if the failure originated with the processor.
You may recover costs contractually, but regulatory accountability cannot be outsourced.
-
Not on their own.
GDPR recognises certifications and codes of conduct (Articles 40–42) as supporting evidence, but they are voluntary and do not reduce your responsibility.
In practice:
Low-risk processing may justify lighter reliance
Medium to high-risk processing requires deeper validation
This includes reviewing real evidence such as configurations, logs, test results, and incident handling practices.
Self-assessment alone is rarely defensible in high-risk scenarios.
-
They are efficient, but incomplete.
Remote audits rely heavily on what the supplier chooses to disclose. They make it difficult to:
Verify actual practices versus documented policies
Detect cultural or operational gaps
Assess physical and environmental controls
On-site assessments provide stronger validation, especially for high-risk suppliers.
A defensible approach usually combines both, using on-site audits selectively where risk justifies them.
-
You cannot ignore the risk.
Under Article 28, you must only use processors that provide sufficient guarantees. If those guarantees are not met:
You should:
Define a clear remediation plan with timelines
Apply compensating controls where possible
Monitor progress closely
If risk remains high:
Restrict or suspend processing
Consider alternative suppliers
For high-risk scenarios, consult the supervisory authority under Article 36
Continuing without mitigation is difficult to justify under GDPR.
