Supplier Management

Manage supplier relationships with security assessments and approval workflows

Why Do I Need Supplier Management?

Your business security is only as strong as your weakest supplier. Managing suppliers properly helps you:

  • Prevent Data Breaches: Ensure suppliers protect your data as carefully as you do
  • Meet Compliance: Many regulations require you to assess and monitor supplier security
  • Reduce Risk: Identify and address security weaknesses before they cause problems
  • Protect Reputation: Avoid being blamed for supplier security failures
  • Make Better Decisions: Choose suppliers based on security strength, not just price

What is Supplier Management?

Supplier management is the process of evaluating, approving, and monitoring the companies you work with to ensure they meet your security and business requirements.

Real-World Example

You're hiring a cloud storage company to store customer files. Before signing the contract, you need to check:

  • Do they encrypt data properly?
  • Are their systems regularly updated?
  • Do they have good backup procedures?
  • What happens if they get hacked?

Supplier management helps you evaluate these factors systematically.

Key Features

Supplier Registration

Centralized database of all suppliers with contact information and business details.

Multi-Phase Approval

Structured approval workflow ensuring proper review before supplier engagement.

Security Assessment

Comprehensive security questionnaires and risk evaluation tools.

Ongoing Monitoring

Regular re-assessments and performance tracking throughout the relationship.

3-Phase Approval Process

Phase 1: Initial Registration & Due Diligence

Purpose: Collect supplier information and verify credibility

Company details, contact information, business description, financial stability check, and initial documentation. Any user with the Supplier Due Diligence role can complete this phase.

Phase 2: Security Assessment & 8-Factor Criticality

Purpose: Evaluate cybersecurity capabilities and business criticality

Detailed security questionnaire, 8-factor criticality scoring (data sensitivity, regulatory impact, dependency level, etc.), and risk assessment. Creates a criticality score that feeds into the heatmap.

Phase 3: Final Approval

Purpose: Executive decision and formal onboarding

Leadership review of all assessment data, approval decision, and formal supplier activation. Requires approval authority beyond the Supplier Due Diligence role.

Jira Integration

Create Jira tickets directly from supplier records to track due diligence tasks, remediation items, or contract reviews. Tickets link back to the supplier record in amara.

Security Assessment

What We Evaluate
  • Data Protection: How they handle your sensitive information
  • Access Controls: Who can access what in their systems
  • Network Security: Firewalls, encryption, monitoring systems
  • Incident Response: How they handle security breaches
  • Business Continuity: Backup systems and disaster recovery
  • Compliance: Certifications and regulatory adherence
  • Employee Training: Staff security awareness programs
  • Third-Party Risk: How they manage their own suppliers

Supplier Criticality Heat Map

AMARA provides an interactive visualization to help you understand supplier risk at a glance. The heat map shows the relationship between dependency criticality and overall supplier criticality.

Supplier Criticality Matrix - Dependency vs Overall Criticality
Dependency Criticality
Overall Criticality
Color Legend:
Extreme High Medium Low Pending

Click any bubble to view detailed supplier information. Larger bubbles represent higher-impact suppliers.

Figure 1: Interactive supplier criticality heat map showing dependency vs overall criticality assessment. This visualization helps you quickly identify which suppliers pose the highest risk to your organization.

How to Read the Heat Map

X-Axis (Dependency Criticality):

  • 1 - Low: Easy to replace, minimal dependency
  • 2 - Medium: Takes effort to replace
  • 3 - High: Few alternatives available
  • 4 - Critical: No viable alternatives

Y-Axis (Overall Criticality):

  • 1 - Low: Minimal impact on operations
  • 2 - Medium: Moderate impact
  • 3 - High: Significant impact
  • 4 - Critical: Severe impact threatening business

Category Distribution

AMARA automatically organizes suppliers by category, helping you understand your supplier portfolio at a glance.

Category Distribution
2
Consultancy
1
Hardware
2
Services
1
Software

Figure 2: Category distribution chart showing supplier breakdown by type. This helps you understand your supplier portfolio composition and identify potential concentration risks.

Understanding Category Distribution

Why This Matters:

  • Portfolio Balance: Identify if you're over-dependent on one category of suppliers
  • Risk Assessment: Different categories carry different risk profiles
  • Budget Planning: Understand spending distribution across supplier types
  • Strategic Planning: Make informed decisions about supplier diversification

Getting Started

Quick Start Guide
  1. Identify Current Suppliers: List all companies you currently work with
  2. Prioritize by Risk: Focus first on suppliers who handle sensitive data or critical services
  3. Start Registration: Begin with your most important suppliers
  4. Conduct Assessments: Use security questionnaires to evaluate current suppliers
  5. Address Gaps: Work with suppliers to resolve any security concerns
  6. Set Review Schedule: Plan regular re-assessments (typically annually)
Common Risk Areas
  • Cloud storage providers with weak encryption
  • Software vendors with poor update practices
  • Service providers lacking incident response plans
  • Suppliers without proper employee background checks
Best Practices
  • Include security requirements in all contracts
  • Request proof of insurance and certifications
  • Establish clear communication channels
  • Plan for supplier termination procedures
Integration with Other Modules

Supplier Management integrates with Risk Management to automatically create risk entries for supplier-related threats. Security gaps identified during supplier assessments can be tracked as remediation items, ensuring comprehensive supplier risk management across your organization.