Documentation
Supplier Management
Manage supplier relationships with security assessments and approval workflows
Why Do I Need Supplier Management?
Your business security is only as strong as your weakest supplier. Managing suppliers properly helps you:
- Prevent Data Breaches: Ensure suppliers protect your data as carefully as you do
- Meet Compliance: Many regulations require you to assess and monitor supplier security
- Reduce Risk: Identify and address security weaknesses before they cause problems
- Protect Reputation: Avoid being blamed for supplier security failures
- Make Better Decisions: Choose suppliers based on security strength, not just price
What You'll Learn
What is Supplier Management?
Supplier management is the process of evaluating, approving, and monitoring the companies you work with to ensure they meet your security and business requirements.
Real-World Example
You're hiring a cloud storage company to store customer files. Before signing the contract, you need to check:
- Do they encrypt data properly?
- Are their systems regularly updated?
- Do they have good backup procedures?
- What happens if they get hacked?
Supplier management helps you evaluate these factors systematically.
Key Features
Supplier Registration
Centralized database of all suppliers with contact information and business details.
Multi-Phase Approval
Structured approval workflow ensuring proper review before supplier engagement.
Security Assessment
Comprehensive security questionnaires and risk evaluation tools.
Ongoing Monitoring
Regular re-assessments and performance tracking throughout the relationship.
3-Phase Approval Process
Phase 1: Initial Registration & Due Diligence
Purpose: Collect supplier information and verify credibility
Company details, contact information, business description, financial stability check, and initial documentation. Any user with the Supplier Due Diligence role can complete this phase.
Phase 2: Security Assessment & 8-Factor Criticality
Purpose: Evaluate cybersecurity capabilities and business criticality
Detailed security questionnaire, 8-factor criticality scoring (data sensitivity, regulatory impact, dependency level, etc.), and risk assessment. Creates a criticality score that feeds into the heatmap.
Phase 3: Final Approval
Purpose: Executive decision and formal onboarding
Leadership review of all assessment data, approval decision, and formal supplier activation. Requires approval authority beyond the Supplier Due Diligence role.
Jira Integration
Create Jira tickets directly from supplier records to track due diligence tasks, remediation items, or contract reviews. Tickets link back to the supplier record in amara.
Security Assessment
What We Evaluate
- Data Protection: How they handle your sensitive information
- Access Controls: Who can access what in their systems
- Network Security: Firewalls, encryption, monitoring systems
- Incident Response: How they handle security breaches
- Business Continuity: Backup systems and disaster recovery
- Compliance: Certifications and regulatory adherence
- Employee Training: Staff security awareness programs
- Third-Party Risk: How they manage their own suppliers
Supplier Criticality Heat Map
AMARA provides an interactive visualization to help you understand supplier risk at a glance. The heat map shows the relationship between dependency criticality and overall supplier criticality.
Supplier Criticality Matrix - Dependency vs Overall Criticality
Color Legend:
Click any bubble to view detailed supplier information. Larger bubbles represent higher-impact suppliers.
Figure 1: Interactive supplier criticality heat map showing dependency vs overall criticality assessment. This visualization helps you quickly identify which suppliers pose the highest risk to your organization.
How to Read the Heat Map
X-Axis (Dependency Criticality):
- 1 - Low: Easy to replace, minimal dependency
- 2 - Medium: Takes effort to replace
- 3 - High: Few alternatives available
- 4 - Critical: No viable alternatives
Y-Axis (Overall Criticality):
- 1 - Low: Minimal impact on operations
- 2 - Medium: Moderate impact
- 3 - High: Significant impact
- 4 - Critical: Severe impact threatening business
Category Distribution
AMARA automatically organizes suppliers by category, helping you understand your supplier portfolio at a glance.
Category Distribution
Figure 2: Category distribution chart showing supplier breakdown by type. This helps you understand your supplier portfolio composition and identify potential concentration risks.
Understanding Category Distribution
Why This Matters:
- Portfolio Balance: Identify if you're over-dependent on one category of suppliers
- Risk Assessment: Different categories carry different risk profiles
- Budget Planning: Understand spending distribution across supplier types
- Strategic Planning: Make informed decisions about supplier diversification
Getting Started
Quick Start Guide
- Identify Current Suppliers: List all companies you currently work with
- Prioritize by Risk: Focus first on suppliers who handle sensitive data or critical services
- Start Registration: Begin with your most important suppliers
- Conduct Assessments: Use security questionnaires to evaluate current suppliers
- Address Gaps: Work with suppliers to resolve any security concerns
- Set Review Schedule: Plan regular re-assessments (typically annually)
Common Risk Areas
- Cloud storage providers with weak encryption
- Software vendors with poor update practices
- Service providers lacking incident response plans
- Suppliers without proper employee background checks
Best Practices
- Include security requirements in all contracts
- Request proof of insurance and certifications
- Establish clear communication channels
- Plan for supplier termination procedures
Integration with Other Modules
Supplier Management integrates with Risk Management to automatically create risk entries for supplier-related threats. Security gaps identified during supplier assessments can be tracked as remediation items, ensuring comprehensive supplier risk management across your organization.