USE CASE · SUPPLY CHAIN
A thousand suppliers. One defensible risk position.
Supply-chain attacks come in through the vendors you trust. Run third-party risk as a continuous program: inventory, proportionate assessment, shared remediation, and the regulatory deliverables that come with it.
Suppliers · Trust Grade
Assessment initiatives
Portal onboarding
Onboarding
Remediation plan · Q4
Active · shared
Annual reassessment
Validated
Shared frameworks · value chain
Value chain
Online payments
The inventory as a graph: one degraded Trust Grade, and every framework and business activity it touches is one hop away.
THE SITUATION
Your attack surface signed a contract with you.
-
Questionnaire fatigue, both sides
Your team chases answers; suppliers drown in forms. Response rates drop exactly where the risk is highest.
-
Concentration hides in a flat list
One cloud provider behind twelve critical services looks like a single vendor line, right up until it fails.
-
DORA does not wait for your program
The register of information is due whether your third-party program is ready or not.
-
Annual reassessment always arrives late
A supplier assessed in January can be breached in March. A yearly cycle guarantees you find out the following January.
CAPABILITIES
From vendor list to risk program.
-
An inventory that shows dependencies
Suppliers mapped as a graph: who provides, operates or hosts what, and where a single failure would spread.
-
Assessments that scale
A guided assessment flow on a versioned questionnaire library: proportionate questions, AI-suggested frameworks, one process from intake to validation.
-
Suppliers answer fast
A dedicated portal where vendors respond, with Ernest drafting answers from their own documents for a human to confirm. Days, not months.
-
Scores you can compare and defend
Automated scoring against NIST CSF, enriched with external ratings, comparable across your whole vendor base.
-
Remediation both sides sign
Joint action plans negotiated with the supplier in the platform: accepted, rejected or counter-proposed, then tracked as tickets on both sides.
-
DORA deliverables built in
Register of information, ICT concentration analysis (Art. 29) and TLPT engagement tracking (Art. 26-27), fed by the same living data.
REMEDIATION, SHARED
A finding your supplier never accepted is a finding that never closes.
Most programs end at the scorecard. Mindlapse continues into remediation: action plans are negotiated with the supplier, accepted explicitly, and tracked to completion on both sides, with re-assessment armed for when the work lands.
- 01
Inventory and tier
Import your vendor base, map dependencies, and tier by criticality so the effort follows the risk.
- 02
Assess in context
Proportionate questionnaires through the vendor portal, AI-drafted answers for speed, automated scoring for comparability.
- 03
Remediate and re-verify
Joint action plans with your suppliers, and re-assessments triggered by events, not by the calendar.
UNDER THE HOOD
The modules doing the work.
Third-Party Risk Management
The assessment machinery: questionnaires, AI-drafted answers, scoring, contradiction detection.
Learn more
DORA
What the regulation requires, and how its obligations map to verified controls.
Learn more
Risk Intelligence
Where supplier risk joins the enterprise register you steer.
Learn more
FAQ
Supply-chain risk, in practice
Do suppliers need a Mindlapse license?
No. They respond through a dedicated portal invitation, at no cost to them. And when a supplier runs Mindlapse too, answers and action plans synchronize between the two organizations.
How is this different from sending spreadsheets?
Proportionate questionnaires instead of one-size-fits-all, AI-drafted answers instead of blank forms, automated scoring instead of manual review, and a remediation loop instead of a filed PDF.
Does it produce the DORA register of information?
Yes. The register is built from the same living data, functions, systems and suppliers, rather than assembled once a year, and exported when you need it.
What triggers a re-assessment?
Events you configure: new findings, expiring attestations, changes of scope or criticality. Triggers fire targeted re-checks instead of another full annual campaign.
GLOSSARY
Terms to know
SUPPLY CHAIN, VERIFIED
Bring your supplier list. Leave with a program.
A live walkthrough on a real example: tiering, assessment, joint remediation and the DORA register.