Home · Solutions · Other solutions

Solution · Other solutions

Four hundred vendors hold your data, and the spreadsheet that governs them has one owner

Every vendor with your data has a current security review

Every vendor with data or system access carries a current review, a named owner and an expiry date, the chasing runs on a schedule, and analysts confirm every value that enters the register.

Quick winMicrosoft TeamsHuman in the loopAI where it earns its place
420vendors hold patient, employee or financial data of this illustrative healthcare group, or connect to its systems, and a spreadsheet is meant to know which.

Executive summary

Challenge

Vendor reviews live in a spreadsheet, certificates in mailboxes, and expiry is discovered by the auditor.

What changes

Two things are missing today, and neither is a tool: a system of record that other systems write to, and a mechanism that notices when a date passes.

Business value

Every vendor with data access has a current review, a named owner and an expiry date, because rows are created by events rather than by memory.

Systems involved

the register in Microsoft Lists or Dataverse; SharePoint evidence library; Power BI

Business problem

Vendor security

Vendor security review is a process everyone agrees matters and nobody owns end to end. Procurement onboards the vendor, IT grants the access, security sends the questionnaire, legal signs the data processing agreement, and the register that should tie them together is a spreadsheet kept in spare time.

Questionnaires go out as documents attached to mail and come back weeks later, partly completed, with certificates nobody checks for scope or expiry. Reading a SOC 2 report to extract the handful of facts that matter takes an analyst about an hour, and the result is retyped into the register by hand.

Reviews are annual in policy and occasional in practice, because nothing reminds anyone. Nothing connects the register to the events that create vendors either, so a supplier can be onboarded, given a guest account and paid for a year before security learns the name.

The problem persists because the work is diffuse and unglamorous, and because the consequence, an audit finding or a breach through a vendor, arrives long after the omission. The cost is zero until it is very large.

How it works today

  1. PersonProcurement onboards a vendor and IT grants access; security hears about it later, sometimes from the invoice
  2. PersonAn analyst mails the questionnaire as a Word document to a contact address
  3. WaitingThe vendor replies after two reminders and several weeks, partly completed
  4. PersonThe analyst reads the questionnaire, the certificate and any SOC 2 report and retypes the key points
  5. Risk of errorCertificate scope and expiry are noted, or not, depending on who reviewed and how busy that week was
  6. SystemA next review date is typed into the spreadsheet, where nothing will act on it
  7. WaitingThe date passes unnoticed, and the vendor's access continues regardless of review status
  8. Risk of errorAn auditor asks for evidence, and analysts search mailboxes for documents that left with a colleague
PersonWaitingRisk of errorSystem

Why the current process costs more than it appears

Behind every exception is an hour nobody logged.

  • Analyst hours per review are modest; the exposure is not. A vendor with expired controls and live access to patient or payroll data is a breach waiting for a date, and regulators treat supply-chain failures as the company's own.
  • Audit preparation becomes a project every year because the evidence is scattered across mailboxes, drives and personal folders rather than held in one place.
  • Cyber-insurance questionnaires ask about the third-party programme and price the answer, so a weak register is paid for annually whether or not anything goes wrong.
  • Key-person dependency is severe. When the analyst with the spreadsheet leaves, the programme restarts, and the vendors nobody remembers are the ones nobody reviews.
  • Duplication hides gaps: one vendor is reviewed twice by two departments while another is never reviewed, because no list says who holds what.

Cost of inaction

Twelve months of reviews run from memory≈ €43,848
Three annual cycles before the register can be trusted≈ €131,544
At 560 vendors after the next two acquisitions (per year)≈ €58,464

The vendor count rises with every new service, cloud tool and outsourced function, and each addition is a row nobody maintains. The share of expired reviews grows quietly, and the vendor with the weakest controls is the one nobody has looked at since onboarding. Insurers price the programme into the premium, and regulators asking for supply-chain evidence increasingly treat a spreadsheet as a finding rather than an answer.

Then somebody asks the simple question: show me the current security review for the payroll provider. Today that takes a day of searching, and produces a questionnaire from three years ago, a certificate that expired in the spring and a mail promising the new one. The analysts who hold this together by hand burn out on chasing and leave, which resets the programme to whatever the next person can reconstruct.

Illustrative scenario

A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.

Organisation

A private healthcare group with 3,400 employees running clinics and diagnostic laboratories in two countries, subject to GDPR and, as an essential entity, to NIS2, with Microsoft 365, Teams, SharePoint and Microsoft Entra ID in place and Power BI already used by finance.

Volume

About 420 vendors hold patient, employee or financial data or connect to internal systems: laboratory software, imaging, payroll, cloud hosting, device maintenance, agencies. Reviewed annually, that is roughly 35 reviews a month.

Current process

Five security staff and eight in procurement share responsibility, tracked in an Excel register. Questionnaires are Word documents, certificates and SOC 2 reports arrive by mail, and there is no GRC platform.

Bottleneck

About 3.2 hours per review, most of it chasing, reading, extracting and typing rather than judging, plus roughly 120 hours a year to assemble evidence for audit and insurance.

Solution

The register becomes a system with a robot behind it: rows created by the events that create vendors, tiered questionnaires chased on schedule, evidence in one library, values proposed from the documents and confirmed by an analyst, expiries escalated in Teams.

Potential outcome

In the modelled case coverage becomes a number with a trend, chasing stops depending on memory, and audit evidence is an export. Nothing here is a measured client result; the register you keep will move these numbers.

Proposed solution

Two things are missing today, and neither is a tool: a system of record that other systems write to, and a mechanism that notices when a date passes. We supply both, on the tenant you already run.

The register lives in Microsoft Lists, or in Dataverse where volume justifies it: one row per vendor with data classification, access type, risk tier, named owner, review status, due date and certificate expiry. Rows are created by the events that create vendors, an onboarding record, a signed agreement, a guest account in Microsoft Entra ID, so the list stops depending on somebody remembering to add a line.

Questionnaires are Microsoft Forms, tiered by risk so a marketing agency does not answer the questions asked of a hosting provider. A robot sends them, chases at defined intervals through the Outlook 365 connector, collects responses and documents into a SharePoint evidence library, and accepts an existing SOC 2 report or ISO 27001 certificate for the sections it covers. UiPath GenAI Activities then read those documents and propose register values: certificate validity and scope, subprocessors, encryption, breach-notification terms. Each proposal arrives with the passage it came from, as a UiPath Action Center validation task in Microsoft Teams, and an analyst confirms or corrects it. Nothing enters the register unvalidated.

The robot then does the part people are worst at: tracking due dates and expiries, reminding the named owner in Teams, escalating overdue high-tier vendors to the CISO, and flagging lapsed vendors to the access-review process, so review status and access stop being unrelated facts. Power BI shows coverage, overdue reviews, expiring certificates and tiers, with an export an auditor can take away. Supplier onboarding and sanctions screening are separate solutions here; this page covers the assurance that follows.

Native capabilities used

Microsoft Lists or Dataverse with rules and version history; Microsoft Forms; SharePoint evidence library with sensitivity and retention labels; UiPath Action Center validation tasks in Microsoft Teams; UiPath GenAI Activities under the UiPath AI Trust Layer; UiPath Orchestrator triggers, queues and audit; Microsoft Entra ID access reviews

What we build

The register model and its risk-tier rules; the questionnaire tiers and their mapping to evidence types; the dispatch, chasing and collection robots; the extraction and validation task design; due-date, expiry, reminder and escalation logic; the access-review flag; the Power BI coverage view and auditor export

Custom integration

Register creation from the procurement onboarding source or ERP vendor master and from signed agreements; guest-account events from Microsoft Entra ID; record creation in a GRC platform where one arrives later

How the automated process works

  1. AutomationA vendor with data or system access appears in onboarding, in a signed agreement or as a guest account, and a register row is created
  2. SystemThe risk tier follows by rule from data classification and access type, and the questionnaire tier follows from the risk tier
  3. AutomationThe robot sends the questionnaire and chases at defined intervals, accepting existing SOC 2 or ISO evidence for the sections it covers
  4. AutomationResponses and documents land in the evidence library, and extraction proposes register values with the source passage attached
  5. PersonAn analyst validates every proposed value in an Action Center task in Teams, correcting what extraction got wrong
  6. PersonWhere findings arise, the owner and security decide on remediation, acceptance or exit
  7. AutomationThe review closes with a next due date and a tracked certificate expiry, and reminders run from those dates
  8. AutomationCoverage, overdue reviews and expiring certificates are reported in Power BI, with an evidence export for auditors
AutomationSystemPerson

Human-in-the-loop model

Automation handles

  • Register rows from onboarding, contracts and guest accounts, with the risk tier assigned by rule
  • Questionnaire dispatch, chasing on schedule, and evidence collection into one library
  • Proposed register values extracted from reports and answers, each with its source passage
  • Due dates, expiries, reminders, escalations, access-review flags and coverage reporting

People decide

  • Every value that enters the register, confirmed in a validation task before it is stored
  • The risk tier where the rule is arguable, and what a finding means in practice
  • Remediation, risk acceptance and vendor exit, with the acceptance recorded and dated
  • Policy: review frequency, tier definitions and what the questionnaire asks

Before and after

BeforeAfter
Who chases the vendoran analyst, when they remembera robot, on a schedule, with escalation
Extracting facts from a SOC 2 reportabout an hour per vendora validation task with the passage shown
Certificate expiryfound by the auditor, or by chancetracked, with a reminder weeks ahead
Access and review statusunrelated facts in two systemsa lapsed review flags the accounts
Evidence for an audita search through mailboxes and drivesan export from the evidence library

Systems and integrations

Every entry can be checked in vendor documentation. The evidence class is stated next to each one.

Inputs

  • procurement onboarding records or the ERP vendor master
  • signed agreements
  • guest accounts in Microsoft Entra ID
  • questionnaire responses
  • certificates and audit reports

Automation layer

  • UiPath Orchestrator
  • UiPath Robots
  • UiPath GenAI Activities
  • UiPath Action Center
  • UiPath Integration Service

Target systems

  • the register in Microsoft Lists or Dataverse
  • SharePoint evidence library
  • Power BI
  • a GRC platform where one exists

Human touchpoints: validation tasks in Microsoft Teams; owner reminders and CISO escalations; the findings decision with the vendor owner

procurement onboarding recordsUiPath OrchestratorUiPath Robotsthe register in Microsoft Listsvalidation tasks in Microsoft Teams

Technologies used

Microsoft Lists (or Dataverse)

the register: one row per vendor with tier, owner, status, review and certificate dates

A
Microsoft Forms

tiered questionnaires sent to vendors, responses collected automatically

A
UiPath Robots + Orchestrator

dispatch, scheduled chasing, evidence collection, date tracking, escalation

A
UiPath GenAI Activities under the UiPath AI Trust Layer

propose register values from reports and answers, with model allow-list, EU routing and logging

A
UiPath Action Center in Microsoft Teams

analyst validation of every proposed value before it reaches the register

A
UiPath Integration Service (Microsoft Outlook 365, OneDrive & SharePoint connectors)

vendor mail, responses and the evidence library

A
Microsoft Entra ID

guest accounts create a review row; a lapsed review flags the vendor's accounts for access review

A
Power BI

coverage, overdue reviews and expiring certificates by tier, with the auditor export

A
Averified product capability (vendor documentation)

Illustrative economic model

The arithmetic is open, so it can be argued with.

Illustrative model
35 vendor reviews a month × 96 minutes of mechanical work= 56 h / month
56 h × €58 fully loaded security analyst cost= €3,248 / month
× 12 months≈ €38,976 / year
Annual analyst capacity released (illustrative)≈ €38,976

The unit here is a review, and the half of it that is mechanical. A review takes 3.2 hours today, which is 192 minutes; chasing, collecting, reading, extracting and typing account for about half, so the calculator carries 96 minutes per review and leaves the rest with analysts, where judgement belongs. The €58 hourly cost is an assumed fully loaded security-analyst rate, and nothing here was measured at a client. Audit preparation is counted separately below, and the breach this programme exists to prevent is not counted at all.

Run the numbers on your data

hours released per month
of annual capacity released

An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.

Business benefits

  • Every vendor with data access has a current review, a named owner and an expiry date, because rows are created by events rather than by memory
  • Chasing runs on a schedule rather than on attention, so response times fall and analysts stop being the reminder system
  • Reading a SOC 2 report becomes a short validation with the source passage shown, not an hour of extraction per vendor
  • Certificate expiries and overdue reviews surface weeks ahead in Teams instead of at the audit
  • Access and review status are finally connected, so a lapsed review reaches the people who can suspend the account
  • Audit and insurance evidence is an export from one library rather than a project every spring

The management view

  • Coverage as a number with a trend: vendors in scope, current, overdue, expiring, by risk tier, without anyone assembling it
  • Named owners reminded automatically, which makes accountability visible without a meeting
  • Exceptions and risk acceptances recorded with who accepted them, on what basis and until when
  • A programme that survives staff changes, because it is a system with history rather than a file with an owner

Board-level KPIs

in-scope vendors with a current reviewoverdue reviews by risk tiervendor response timeanalyst hours per reviewcertificates expiring in the next 90 days

Security and governance

Security is designed with the process, not after it.

  • Vendor evidence often includes confidential audit reports, so the library has restricted permissions, sensitivity labels and a retention label matching your policy
  • Extraction runs under the UiPath AI Trust Layer with an allow-listed model and EU region routing, and a named analyst confirms every proposal before the register changes
  • The register keeps version history: who confirmed which value, when, and what it was before
  • Robots use service accounts limited to the vendor mailbox, the forms, the library and the register, with secrets held in a vault rather than in the workflow
  • Vendor contact details are the only personal data processed, inside the Microsoft 365 EU Data Boundary and the UiPath Automation Cloud EU region; exceptions and risk acceptances are recorded with approver, reason and expiry

Why now

01

Supply-chain security has moved from good practice into law for many sectors: Directive (EU) 2022/2555, the NIS2 Directive, requires essential and important entities to manage third-party risk and evidence it

02

Vendors now hold most of a company's data in their own clouds, and guest accounts in Microsoft Entra ID give them access no spreadsheet can see, which is why the register has to be created by events rather than by hand

03

Extraction under the AI Trust Layer with an analyst confirming every value makes reading vendor reports at scale practical, and Lists, Forms and Teams supply the register, questionnaire and reminders on a tenant you already pay for

Relevant executive roles

CISO

Coverage becomes a number with a trend, chasing is automated, and expiring controls surface before an auditor asks

General Counsel

Supply-chain due diligence under GDPR and NIS2 is evidenced per vendor, with data processing terms reconciled against what the vendor does

Procurement Director

Review status is visible before signature and renewal, and vendors are chased by a system rather than by procurement staff

CIO

Vendor access in Microsoft Entra ID is linked to review status, closing the gap between directory and register

Common questions and objections

We are buying a GRC platform.

The register can live there when it arrives. Chasing, evidence collection and extraction are the work a GRC tool still leaves to people, and the robots do that against whichever register you end up with.

Our vendors will not complete the questionnaire.

They already do, slowly. Scheduled chasing, a short tiered form and accepting their existing SOC 2 or ISO evidence instead of answers reduce the burden on both sides, and response time becomes a number you can manage.

Letting a model read a SOC 2 report is risky.

The model proposes a value and shows the passage it came from; an analyst confirms each one under their own identity. Nothing enters the register unvalidated, and the log shows who confirmed it.

When this is not the right solution

  • Fewer than a few dozen vendors with data access, where a maintained list and calendar reminders are proportionate
  • A GRC platform with a vendor-risk module already adopted and staffed, where the gap is process discipline rather than tooling
  • No vendor inventory at all, because reconciliation comes first and may be the whole of the first project

A question for the next management meeting

Between our vendor list, our contracts and the guest accounts in Microsoft Entra ID, which one does this company treat as the definitive record of who holds its data, and when was it last reconciled with the other two?

Implementation approach

Delivery runs in stages, so it can be stopped at any point.

We deliver

  • Inventory reconciliation first: the register against the ERP vendor master, the contract library and Entra ID guest accounts, which usually finds vendors with access no review covered
  • The register model, risk-tier rules and questionnaire tiers, agreed with security and procurement
  • Dispatch, chasing, collection, reminder and escalation automations, with the events that create rows
  • Extraction configuration and the validation task design, including what the analyst sees with each proposal
  • The Power BI coverage view and the evidence export an auditor can be given directly
  • Testing on a vendor sample, deployment, analyst training, support after go-live

We need from you

  • The current register, however incomplete, and the vendor security policy behind it
  • Questionnaire content and the evidence you already accept instead of answers
  • A security owner for validation and a procurement contact for the onboarding events
  • Licences where features need them: Power BI, and Entra ID Governance if access reviews are in scope

Stages

Reconciliation

Compare register, vendor master, contracts and guest accounts; agree the scope

Design

Tiers, questionnaires, due-date rules, escalation paths and the evidence taxonomy

Build

Register, dispatch and chasing, evidence library, extraction, validation tasks, reporting

Pilot

The highest-risk tier, typically thirty to fifty vendors, through a full cycle

Roll-out

Remaining tiers, onboarding triggers and the access-review link

Operation

Coverage monitoring, tuning of tiers and questionnaires, quarterly review with security

Quick win. Effort follows the state of the inventory more than anything technical: where the vendor list, the contracts and the directory disagree, reconciliation is the work.