LOADING…
Platform  /  Supplier Assurance  ·  Module
AI-driven third-party risk

8,000 suppliers.One source of truth.

Built for UK public sector, CNI and nuclear. Built sovereign. Built deep. Built to defend you from the breach you didn't see coming.

60% breaches via a third party £4.45m avg breach cost 205 questions · 21 domains
The challenge

Supplier risk is now your risk.

Your suppliers now hold your data, run your services and sit inside your network - which means their security is your security.

For a UK public-sector or critical-infrastructure organisation, the third-party estate is vast and uneven: thousands of suppliers, sub-processors and connected services, each a potential route in. The traditional answer - an annual questionnaire emailed to a handful of "key" vendors - assures a tiny fraction of that estate, on the day they answered, and says nothing about the months in between.

E2ERisk treats supplier assurance as a continuous operating model rather than a once-a-year form. Discovery, criticality tiering, a deep questionnaire, AI-assisted evidence review, outside-in scanning and remediation all run on one platform - so a stretched team can assure the whole estate, not just the suppliers they had time to chase, and prove it to an auditor at any moment.

205
Questions
21
Assurance domains
29
Step lifecycle covered
12
Frameworks mapped
The problem

Your suppliers are your attack surface.

You can spend £10m hardening the perimeter and still be breached through a vendor with a £49 SaaS account. The organisations that get owned rarely come through the front door any more - they come through a supplier that was trusted, integrated and then quietly forgotten.

The two columns below are the gap that matters: everything a security team believes it controls, set against everything that is actually exposed through the third-party estate sitting just outside it.

What you think you control
Endpoints, firewalls, EDR, SIEM
Hardened cloud config, patched servers
MFA on every internal account
Annual penetration test
A mature CAF programme
What is actually exposed
Your payroll provider's HR portal
A 4-person SaaS vendor run from a living room
An MSP holding domain-admin keys
A code-signing certificate stolen 14 months ago
A subcontractor four levels deep you can't even name
The pattern

The breach pattern is unmistakable.

The defining breaches of the decade do not look alike on the surface - different sectors, different malware, different scale - but the entry point is always the same: a trusted supplier, not the target's own perimeter.

Read the six below as one pattern rather than six incidents. In every case a single supplier became the route in, and point-in-time assurance never saw it coming.

Software supply chain

Poisoned updates

Implant in signed vendor updates

A trusted software vendor's signed updates carried an attacker's implant into thousands of organisations at once - government included. One supplier, mass compromise.

Managed services

Compromised MSP tooling

Ransomware via remote management

Attackers subverted one managed-service provider's tooling and pushed ransomware to every business it managed - thousands encrypted over a single weekend.

File transfer

Zero-day in shared SaaS

One product, thousands of victims

A zero-day in a widely used file-transfer product exposed the data of thousands of organisations and tens of millions of people - all through a single supplier.

Identity

Support-desk compromise

Stolen support-session tokens

Stolen credentials at an identity provider's support desk let attackers pivot into the customers that trusted it. The identity layer itself became the way in.

Healthcare

Clearing-house ransomware

One sub-processor, national impact

Ransomware through a single healthcare processor took pharmacy and claims systems offline for weeks and exposed data on a vast share of a nation's population.

Public services

Pathology provider down

Outage became patient harm

Ransomware against one NHS pathology supplier cancelled thousands of appointments and forced a national blood appeal. A supplier outage became direct patient harm.

Different sectors, different malware - the same root cause. A trusted supplier became the way in. Point-in-time assurance never sees it coming.

The maths nobody admits

4 analysts. 8,000 suppliers.

Most public-sector security teams are not under-funded - they are under-staffed by an order of magnitude. The figures below come from a real, anonymised UK central-government department in 2026, and they are not the exception. Four analysts, eight thousand suppliers, and a queue you could never clear by hand.

4
analysts in supplier assurance for a major UK department
8,000
tech suppliers needing assurance
14
properly assessed - 0.175% coverage
250yr
programme at current capacity

How E2ERisk multiplies four people into forty.

01

Pre-contract auto-tier

Two-axis criticality routes Tier-3/4 suppliers to a 30-minute self-attestation. Analyst time freed for the suppliers that matter.

02

Self-serve supplier portal

Suppliers complete questionnaires themselves. No chase-ups, no emailed PDFs, no spreadsheet version control.

03

AI evidence extraction

Multi-provider AI reads policies, certs and pen-test reports and extracts answers. Analysts review and sign off - they don't retype.

The module

A complete operating system for third-party risk.

Supplier assurance is not one feature; it is discovery, tiering, assessment, evidence, monitoring and remediation working as one loop. Bolt those together from separate tools and the seams are exactly where risk hides.

Everything below runs on one platform, built for HMG, CNI and regulated industries - not a US Fortune-500 suite with a UK content pack bolted on.

SAQ v30 engine

205 questions, 21 domains, conditional logic, evidence tracking, follow-up branching.

AI evidence extraction

Multi-provider - Anthropic, Azure OpenAI (UK), Groq, Google. Reads policies, certs, audit reports.

Self-serve supplier portal

Suppliers complete, upload evidence and track progress. The end of email tag.

Criticality assessment

Auto-tier suppliers with two-axis scoring. Deep diligence where it actually matters.

Threat library

Which suppliers are exposed to which threat actors and CVEs - mapped to MITRE ATT&CK.

Risk register & deficiencies

Every gap becomes a tracked risk with owner, due date and treatment. Closure with audit trail.

Outside-in scanner

Ratings-grade passive scanning - domain hygiene, certs, leaked creds, dark-web exposure.

Sovereign deployment

Azure UK-South/West. Customer-tenant for OFFICIAL-SENSITIVE. Source escrow available.

SAQ v30

The deepest supplier questionnaire on the market.

Most tools ship a fifty-question form and call it assurance - until an auditor asks for the evidence behind a control nobody thought to ask about. We engineered the depth UK regulators actually expect: 205 questions across 21 domains, with conditional follow-ups and evidence tracked against every answer.

205
questions
21
domains
2,875
conditional follow-ups
51,842
pre-built answer options

Profile · criticality · applicability rules tailor every questionnaire - Tier-3/4 suppliers see ~30 questions; only Tier-1 / critical suppliers see the full depth.

Security Governance & RiskCompliance & LegalAccess Control & IdentityNetwork & InfrastructureOT / ICS SecurityVulnerability ManagementEndpoint ProtectionLogging & MonitoringCloud SecurityApplication SecurityAI GovernanceData ClassificationData Privacy & ComplianceData LifecycleCryptography & KeysBusiness Continuity & DRIncident ResponseHR SecurityPhysical SecuritySupply ChainSecurity Operations
Map once, report everywhere

One question. Every framework.

Most TPRM tools ship a generic questionnaire and leave the mapping to you. Ours ties every question to the frameworks it answers, so one response becomes evidence across all of them at once.

The example below is a single access-control question - and the ISO 27001, NIST, CAF, Cyber Essentials, GDPR and DSPT clauses it satisfies in that one answer.

Q · ACI008
"Do you enforce MFA for all privileged accounts and remote access to systems handling our data?"
This one question satisfies evidence for
ISO 27001:2022 A.5.15, A.5.17, A.8.5
NIST CSF 2.0 PR.AA-03, PR.AA-05
NCSC CAF B2.a, B2.b, B2.c
Cyber Essentials+ Access Control
GDPR Article 32 (technical measures)
DSPT Standard 8 (Secure Configuration)
The full lifecycle

The standard is 29 steps. They sell you 9.

NCSC, NIST SP 800-161r1, ISO/IEC 27036-2 and DORA all describe a full third-party lifecycle - roughly 29 distinct activities from onboarding through to offboarding. Most TPRM tools cover the easy third in the middle and leave the rest to spreadsheets.

We cover all six phases end to end, so nothing falls into the gap between assessment and the next audit - because there is no gap.

Onboarding
Intake
Register
Profile
Tier
Assessment
Diligence
Scope
Self-assess
Indep. review
AI review
Findings
Deficiency
Risk register
Rem. plan
Rem. track
Rem. verify
Risk Decide
Risk score
Decision
Acceptance
Clauses
Verified
Monitoring
Dashboard
Cert expiry
Threat intel
Incident
Reassess
Offboarding
Exit plan
Data destr.
Access revoke
Archive
Exit test

Same standards. 3.2× the coverage.

Honest comparison

Why generic US TPRM tools fail UK public sector.

A US-built TPRM suite can be excellent at what it was designed for and still be wrong for UK public sector: the frameworks, the data-residency rules and the classification handling are simply different. The comparison below is an honest, line-by-line read of where that gap shows.

CapabilityGeneric US TPRME2ERisk Supplier Assurance
UK CAF / NIS / GovAssureBolt-on content pack, partialNative, audit-ready
Question depth~50 generic questionsSAQ v30 - 205 Q, 21 domains
AI evidence extractionSingle proprietary modelMulti-provider, incl. Azure OpenAI UK
Data residencyUS SaaS, US dataUK-South / UK-West, customer-tenant
OFFICIAL-SENSITIVENot designed for itAir-gap-ready, customer-managed keys
Outside-in scoringSeparate, expensive add-onBuilt-in threat-centre scanner
Pricing$50-250k, supplier-count tiersModular, public-sector-friendly, G-Cloud
Sovereign by design

Deploy how you need. Up to SECRET.

Where your supplier data can live is rarely a detail in UK public sector - it is often the deciding factor. Managed SaaS is the fastest start, but OFFICIAL-SENSITIVE and classified work need the platform inside your own boundary.

The three patterns below are one product, not three: the same platform from managed SaaS, through customer-tenant, to a fully air-gapped classified deployment.

Managed SaaS · Fastest

OFFICIAL

UK Azure tenant
  • Hosted in our UK Azure tenant
  • UK-South + UK-West regions only
  • ISO 27001 / Cyber Essentials Plus
  • 30-day deploy, onboard suppliers same week
Customer-tenant · Sovereign

OFFICIAL-SENSITIVE

Your Azure subscription
  • Deployed into your own Azure subscription
  • Customer-managed encryption keys (CMK)
  • Your network policies, IAM and audit log
  • Enterprise self-hosted deployment pattern
On-prem / air-gapped · Max secure

SECRET-capable

Your data centre
  • Deploys to your own DC or classified cloud
  • Air-gapped - no outbound internet
  • Manual licence + threat-feed updates
  • Source escrow available for full audit

Generic US TPRM tools are SaaS-only. None deploy on-prem. None go classified.

Native to UK frameworks

Not bolted on. Built in.

Framework support that is bolted on as a content pack always shows the seams. Ours is built into the assessment model, so mapping and evidence fall out of the work you already do - against the regimes a UK organisation is genuinely held to. This is framework mapping and assurance evidence, not a certification claim.

NCSC CAF v4.0NCSC 12 Supply-Chain PrinciplesNIS / NIS2Cyber Essentials+ISO 27001:2022ISO 27036-2NIST SP 800-161r1NIST CSF 2.0GovAssureDORA Art. 28-30GDPR / UK DPA 2018DSPT
70%
Less analyst chase-up time
95%
Faster audit-pack assembly
3-5×
Throughput per analyst
60%
Faster supplier onboarding
Get started

Don't be the next headline.

Get supplier assurance you can prove, defend, and explain to a regulator at 6am on a Saturday.

30-min discovery

We map your current supplier portfolio against tiers in one session.

Sandbox in 48h

Hands-on access to SAQ v30, AI extraction and the supplier portal.

G-Cloud / DPS

Procurement-ready. We sit on the right frameworks and route accordingly.