Konfirmity
Layer 3 of 7 — Supply Chain

// supply chain

Vendors you have judged, not vendors you have listed

L3 needs nothing connected to start working. From the day your vendor register exists, the layer counts the vendors that are not compliant.

// what it watches

What this layer watches

Supply Chain has no “Set Up” state. It is measurable from your first day, without connecting anything, because the data it judges is data you already hold.

  • Every third party in your register, excluding fourth parties reached through them
  • The compliance status each vendor currently holds
  • SaaS tools in use across the business, including the ones nobody registered — browse the 104 connectors
  • Review cadence, and which vendors are overdue one

// what turns it red

What turns it red

Each row is a live measurement on your own environment, not a checklist item. The third column is the part a compliance-first tool cannot offer.

What is measuredWhat it saysWhere clicking it takes you
Third parties in your register whose compliance status is Not compliantN Vendors Are Not CompliantThe vendor register, filtered to exactly those vendors
Vendors that never returned a completed security questionnaireN Vendors Are Not CompliantThe vendor record and its questionnaire state
Vendors whose evidence has expired, or whose review is overdueN Vendors Are Not CompliantThe vendor record and its review history
Fourth parties reached through a vendor, tracked but deliberately excluded from this countNot counted hereThe vendor record, showing its downstream relationships
SaaS tools discovered in use that nobody put in the registerN Vendors Are Not CompliantThe vendor register, with the discovered tool flagged

This table is not the whole check

Vendor criticality, data classification, contractual terms and the questionnaire corpus behind each status all shape whether a vendor passes. This table shows what turns the layer red, not everything we ask a vendor.

See how deep we go

// getting to green

What it takes to go green

  1. Your vendor register is the input. No integration is required for this layer to be measurable.
  2. Each vendor carries a compliance status backed by what you collected from them, not by a box someone ticked.
  3. Vendors that fall out of compliance turn the layer red without waiting for the next review cycle.
  4. The layer clears when no third-party vendor sits at Not compliant.

// the evidence

The evidence this produces

None of this is collected for the auditor's benefit. It is the by-product of work that had to happen anyway, which is why it holds up when someone checks.

  • Third-party risk evidence for every framework requiring supplier management, worked through vendor management
  • A current, dated vendor register rather than a spreadsheet of unknown age
  • The questionnaire and document trail behind each vendor's status

// questions this answers

Supply chain coverage, answered directly

Do I need an integration for vendor coverage to work?

No. L3 has no Set Up state. Your vendor register is the only input, so the layer is measurable from your first day without connecting anything.

What counts as a non-compliant vendor?

A third party in your register whose compliance status is Not compliant, based on what you actually collected from them. Fourth parties reached through another vendor are excluded from the count.

How quickly does the layer react when a vendor lapses?

Immediately. A vendor that falls out of compliance turns the layer red without waiting for the next scheduled review cycle.

Want to see this one live?

Book 30 minutes and we will walk through “Vendors you have judged, not vendors you have listed” in the actual platform, using your environment as the example.

Book a demo