// supply chain
Vendors you have judged, not vendors you have listed
L3 needs nothing connected to start working. From the day your vendor register exists, the layer counts the vendors that are not compliant.
// what it watches
What this layer watches
Supply Chain has no “Set Up” state. It is measurable from your first day, without connecting anything, because the data it judges is data you already hold.
- Every third party in your register, excluding fourth parties reached through them
- The compliance status each vendor currently holds
- SaaS tools in use across the business, including the ones nobody registered — browse the 104 connectors
- Review cadence, and which vendors are overdue one
// what turns it red
What turns it red
Each row is a live measurement on your own environment, not a checklist item. The third column is the part a compliance-first tool cannot offer.
| What is measured | What it says | Where clicking it takes you |
|---|---|---|
| Third parties in your register whose compliance status is Not compliant | N Vendors Are Not Compliant | The vendor register, filtered to exactly those vendors |
| Vendors that never returned a completed security questionnaire | N Vendors Are Not Compliant | The vendor record and its questionnaire state |
| Vendors whose evidence has expired, or whose review is overdue | N Vendors Are Not Compliant | The vendor record and its review history |
| Fourth parties reached through a vendor, tracked but deliberately excluded from this count | Not counted here | The vendor record, showing its downstream relationships |
| SaaS tools discovered in use that nobody put in the register | N Vendors Are Not Compliant | The vendor register, with the discovered tool flagged |
This table is not the whole check
Vendor criticality, data classification, contractual terms and the questionnaire corpus behind each status all shape whether a vendor passes. This table shows what turns the layer red, not everything we ask a vendor.
// getting to green
What it takes to go green
- Your vendor register is the input. No integration is required for this layer to be measurable.
- Each vendor carries a compliance status backed by what you collected from them, not by a box someone ticked.
- Vendors that fall out of compliance turn the layer red without waiting for the next review cycle.
- The layer clears when no third-party vendor sits at Not compliant.
// the evidence
The evidence this produces
None of this is collected for the auditor's benefit. It is the by-product of work that had to happen anyway, which is why it holds up when someone checks.
- Third-party risk evidence for every framework requiring supplier management, worked through vendor management
- A current, dated vendor register rather than a spreadsheet of unknown age
- The questionnaire and document trail behind each vendor's status
// questions this answers
Supply chain coverage, answered directly
Do I need an integration for vendor coverage to work?
No. L3 has no Set Up state. Your vendor register is the only input, so the layer is measurable from your first day without connecting anything.
What counts as a non-compliant vendor?
A third party in your register whose compliance status is Not compliant, based on what you actually collected from them. Fourth parties reached through another vendor are excluded from the count.
How quickly does the layer react when a vendor lapses?
Immediately. A vendor that falls out of compliance turns the layer red without waiting for the next scheduled review cycle.
// keep reading
Where this goes deeper
Want to see this one live?
Book 30 minutes and we will walk through “Vendors you have judged, not vendors you have listed” in the actual platform, using your environment as the example.