Stop chasing vendors for spreadsheets. Start making decisions.
Praeferre sends your questionnaires, chases your suppliers, reads their answers and their policies, and tells you exactly where they fall outside your risk appetite — so your DPO or compliance team spends their time validating decisions, not hunting for evidence. No vendor limits. No manual re-keying. No more six-week onboarding delays.
Your risk doesn't stop at your own perimeter
Nearly half of breaches in 2026 involve a third party, and regulators know it. New legislation is making supplier due diligence a legal duty, not just good practice — and the organisations that treat vendor assurance as a box-ticking exercise are the ones left explaining themselves after the fact.
Cyber Security & Resilience Bill
Introduced November 2025, the Bill makes supply chain risk management a statutory duty for essential and digital service providers — with new powers to designate "critical suppliers" who must meet the same obligations as the organisations that rely on them.
Cyber Assessment Framework 4.0
CAF 4.0's Principle A4 now expects organisations to evidence — not just claim — how supplier access, platforms and software are assessed, monitored and incorporated into security operations. Spreadsheets no longer count as evidence.
NIS2 & DORA
Both regimes push due diligence obligations down the supply chain, requiring in-scope organisations to demonstrate ongoing — not one-off — assurance over the vendors and sub-processors they depend on.
The supply chain is where the biggest incidents start
These aren't hypothetical risks — they're recent, real, and each one started with a vendor relationship nobody was watching closely enough.
A ransomware attack on the outsourcing provider exposed data affecting multiple clients — a single supplier compromise that cascaded across an entire customer base.
Cited in Parliament as the costliest cyber incident in UK history, with the financial damage shared between JLR directly and its supply chain.
A single vulnerability in one widely-used third-party file transfer tool was exploited at scale, affecting organisations worldwide who had never assessed that dependency directly.
Sources: Clifford Chance, on supply chain incidents referenced in the Cyber Security & Resilience Bill · Hansard, UK Parliament debate, June 2026.
Average time a manual vendor security review takes per supplier — time your compliance team could spend on judgement calls instead of data entry.
Of total assessment cycle time consumed purely by chasing evidence and reconciling vendor responses — before any actual risk evaluation begins.
Of organisations monitor supplier security beyond the initial onboarding check — the rest lose visibility the moment the contract is signed.
Sources: Gartner, via Atlas Systems, 2026 · Safe Security, 2026 · World Economic Forum Global Cybersecurity Outlook, 2026.
From questionnaire to decision, without the manual middle
Praeferre handles everything between "we need to assess this vendor" and "here's what our compliance team needs to sign off on."
Send
Questionnaires go out automatically, matched to the vendor's risk tier and the frameworks that apply — no drafting, no chasing emails.
Collect
Responses, policies and supporting documents come back into one place — reminders sent automatically until every vendor is complete.
Analyse
Praeferre's models read thousands of pages in minutes, comparing every answer and policy clause against your own predefined standards.
Decide
Anything outside your risk thresholds is flagged for your DPO or compliance team — with a recommendation ready, and a DPIA one click away.
Offload the chasing, not the accountability
The single biggest time sink in vendor risk management isn't the analysis — it's the chasing. Praeferre sends the right questionnaire to the right vendor automatically, follows up without anyone having to remember to, and brings every response back into one place the moment it lands, ready for review.
- Questionnaires scoped automatically to vendor risk tier and applicable frameworks
- Automatic reminders — no analyst has to chase a single email
- Unlimited vendors held on the platform, at every stage, at once
Thousands of pages, read in minutes — not delegated to a Friday afternoon
Vendor policies, sub-processor lists, certifications, DPAs — every one of them matters, and none of them get read properly under deadline pressure. Praeferre's models read them all, extract what's relevant, and surface insight and recommendations your team can act on immediately, or send straight back to the vendor.
- Full document review — not sampling, not summaries of summaries
- Recommendations generated per document, ready to send to the vendor directly
- Every finding traceable back to the exact clause it came from
Praeferre flags it. Your team decides.
You define what "acceptable" means for your organisation — not a generic industry benchmark. When a vendor's answers or policies fall outside that line, it's routed straight to your DPO or compliance team with the context they need, and a DPIA can be raised in a single click when deeper assessment is warranted.
- Risk thresholds configured by you, not fixed by Praeferre
- One-click DPIA escalation with the evidence already attached
- Full decision trail — who reviewed it, what was decided, and why
Built for more than the annual review
Vendor risk isn't a once-a-year event, and neither is Praeferre.
Pre-onboarding due diligence
Run a full risk assessment before a new vendor ever touches your data — so procurement decisions are made with evidence, not a signed SOC 2 cover page taken on faith.
Scheduled reassessment
Set your own cadence per vendor tier — critical suppliers reviewed quarterly, lower-risk vendors annually — without anyone needing to remember to trigger it.
Direct vendor feedback
Send the gaps Praeferre finds straight back to the vendor with clear recommendations — turning a compliance check into a working relationship that improves posture over time.
Regulator-ready evidence
Every assessment, decision and DPIA is logged — so when the Cyber Security & Resilience Bill or your next audit asks for proof of supply chain due diligence, it's already there.
M&A and integration due diligence
Assess an acquired company's entire vendor estate in days rather than months — critical when integration timelines are already tight.
Fourth-party visibility
Understand the sub-processors your critical vendors rely on — the dependency MOVEit-style incidents exploit, and the one most programmes still can't see.
Don't have a DPO to validate the findings? We are one.
Praeferre flags what's outside your risk threshold — but someone still needs to make the judgement call. If you don't have an in-house DPO or compliance function, our DPO as a Service team reviews the findings, makes the call, and stands behind the decision as your named Data Protection Officer.
Explore DPO as a ServiceTime is the real cost of manual vendor risk
Rough numbers for a compliance team running 50 active vendor relationships on a manual, spreadsheet-based process today.
Figures reflect published industry benchmarks (Gartner, ComplyScore, Safe Security, 2026) for manual versus automated vendor risk programmes, not a Praeferre-specific guarantee. Your results depend on vendor count, questionnaire complexity and current process maturity.
Bring us your vendor list. We'll show you what's hiding in it.
A short discovery call is enough to see what a live assessment would surface across your current supplier base — no limit on how many you bring.