Know the risk
    inside every vendor.

    Whisperly sends structured assessments, scores responses automatically, and flags gaps before you sign.

    98% of organizations have
    vendor relationships
    with breached third parties.

    When a vendor is breached, your data goes with them. Most organisations find out too late, after the regulator, not before.

    Vendor Risk Register
    Nexaflow AIlast assessed: 2022
    PayEngine Ltdnever assessed
    Meridian HRlast assessed: 2023
    DataSync Pronever assessed
    Slack · #security
    DPO team: Anyone know what data PayEngine processes for us?
    No replies · sent 3 weeks ago
    GDPR fine issued
    €2.4M
    Failure to ensure third-party processor compliance under Article 28
    Automated Vendor Assessments.
    Lower Vendor Risk.

    Send structured assessments, score responses automatically, flag gaps, and build an audit-ready vendor register, without chasing anyone manually.

    Book a Demo

    From vendor list to
    risk register in minutes.

    Whisperly doesn't stop at one framework. It runs your entire vendor assessment lifecycle, questionnaire to approval, across every framework your vendors touch.

    1
    Add vendor
    Import your vendor list or add individually

    Connect your procurement system, or add vendors one by one. Whisperly creates a record for each with fields pre-populated from public sources.

    2
    Send assessment
    One click sends the questionnaire to the vendor

    Whisperly sends a structured AI governance questionnaire to the vendor contact. Automatic reminders chase responses. You never write another email.

    3
    Score & flag
    Responses are scored and gaps flagged automatically

    The moment a vendor responds, Whisperly scores every answer against your criteria, assigns a risk tier, and highlights the gaps that need attention, no manual analysis.

    4
    Approve or remediate
    Your team reviews and decides

    Approve vendors that meet your standard. Require remediation for those that do not. Every decision is logged in the audit trail, ready for regulators on request.

    It's all here. And more.

    From questionnaire to approval, Whisperly runs the entire vendor assessment lifecycle, across every framework your vendors touch.

    Vendor Register

    Maintain a live inventory of every vendor and the AI they bring in. Each is scored, tiered, and flagged automatically as their posture changes.

    AI Vendor Register
    8 vendors
    Nexaflow AI
    Document processing
    42
    Failed
    Salesforce Einstein
    CRM AI
    88
    Approved
    Meridian HR Suite
    Recruitment AI
    61
    Review
    Automated Assessments

    Send structured questionnaires in one click. Whisperly tracks responses, chases vendors, and escalates on your deadlines, no email chasing.

    Assessments
    3 in progress
    Nexaflow AI
    Reminder sent
    OpenAI Enterprise
    Complete
    DataSync Pro
    2 reminders
    Risk Scoring & Gaps

    Every response scored against your criteria. Gaps are highlighted, risk tiers assigned, and evidence stored, no manual analysis.

    Risk Score · Nexaflow AI
    Updated 2 min ago
    42
    High risk · Review failed
    2 critical gaps flagged
    Data handling88
    Model transparency34
    Security controls71
    Customisable questionnaires
    Tailor questions to your sector, risk appetite, and the frameworks each vendor is subject to.
    Multi-framework templates
    EU AI Act, ISO 42001, NIST AI RMF, SOC 2, ISO 27001, GDPR, DORA, and dozens more framework templates included out of the box.
    Automated reminders
    Set response deadlines and let Whisperly chase vendors and escalate automatically.
    Periodic reassessment
    Schedule reassessments and trigger them automatically when their posture changes.
    Full audit trail
    Every assessment, response, decision, and message logged with timestamps, export as PDF anytime.
    Connected to AI Governance
    Vendor AI surfaces alongside your internal systems in one unified register, no silos.
    Banking & Financial Services

    Vendor risk in banking has never been more demanding.

    DORA mandates it. The EBA expects it. Whisperly gets you there in minutes, not months.

    DORA Regulation
    Build your ICT third-party register.

    DORA requires every EU financial institution to maintain a complete, up-to-date register of all ICT third-party service providers. Whisperly creates and maintains it automatically.

    DORA Register · 47 vendors
    Nexaflow AI · ProcessingCritical
    Salesforce Einstein · CRMImportant
    Bloomberg Terminal · DataStandard
    Function Criticality
    Assess whether a vendor supports a critical function.

    Under DORA and local outsourcing rules, the depth of due diligence depends on whether a provider supports a critical or important function. Whisperly determines criticality for every vendor and scales the assessment accordingly.

    Criticality Assessment
    CloudCore Hosting · Core bankingCritical
    Nexaflow AI · Loan decisioningCritical
    Salesforce · CRMImportant
    Bloomberg Terminal · Market dataNon-critical
    Continuous Monitoring
    Re-assess automatically when vendors change.

    When a vendor adds a new AI tool, changes their subprocessors, or their certification expires, Whisperly detects it and triggers a re-assessment without any manual intervention.

    Auto-triggered
    Nexaflow added GPT-4 integration
    ISO 27001 cert expires in 30 days
    Re-assessment sent automatically
    Regulatory Reporting
    Walk into every inspection with evidence ready.

    Export DORA-compliant reports, EBA outsourcing registers, and full audit trails at any time. Whisperly keeps the evidence; you keep the focus on running your business.

    Book a Demo
    Export ready
    DORA ICT Register✓ Ready
    EBA Outsourcing Register✓ Ready
    Full Audit Trail✓ Ready

    Three solutions. One platform.
    No gaps between them.

    Vendor assessment doesn't exist in isolation. Neither should your tools.

    Vendor Assessment

    Assessments, risk scoring and monitoring

    The programme you're on. Structured questionnaires, automatic risk scoring, and continuous reassessment for every third party you rely on.

    AI Governance

    EU AI Act compliance, AI system inventory

    Vendor AI you approve flows straight into your AI system register, classified, tracked, and kept current for the EU AI Act.

    Data Privacy

    RoPA, DPIA, DSAR and breach management

    Every vendor that processes personal data is linked to your RoPA and the right DPIAs, no orphaned sub-processors, no manual reconciliation.

    Whisperly connects all three, because they are inseparable.
    When a vendor brings an AI tool that processes EU personal data, Whisperly flags it across your vendor register, your RoPA, and your AI Act inventory simultaneously.
    Book a Demo

    Common questions about vendor assessment.

    Any third party your organisation relies on. Common categories include SaaS and cloud providers, payment and banking partners, data sub-processors, outsourced service providers, and AI vendors. Each is assessed against the questionnaire and risk criteria that fit the relationship, you are never limited to AI vendors.

    Sending an assessment takes under a minute. Vendor response times vary, typically 3 to 10 business days. Whisperly chases automatically and scores the response the moment it arrives. The full cycle from send to decision averages 8 days with Whisperly, compared to 4 to 6 weeks manually.

    Whisperly flags the gaps and provides a remediation checklist the vendor can act on. You can put the vendor into a remediation workflow where they are required to provide additional evidence before approval is granted. All of this is tracked in the audit trail.

    Yes. Whisperly ships with templates aligned to major frameworks, SOC 2, ISO 27001, GDPR, DORA, and the EU AI Act, but you can fully customise questions, scoring weights, and risk thresholds. Enterprise customers can import their existing procurement or security questionnaires and Whisperly scores them automatically.

    Yes. For regulated financial institutions, Whisperly supports third-party and ICT risk assessments aligned to DORA, outsourcing guidelines, and operational-resilience requirements. You can evaluate a vendor’s financial stability, concentration risk, sub-outsourcing chain, and exit strategy alongside data and security controls, all in one workflow.

    No per-seat costs.
    No implementation fees.

    See why teams are moving vendor risk to Whisperly.

    Book a Demo

    Stay ahead of compliance changes

    Practical compliance tips, delivered to your inbox every two weeks.