供应商审核工作流
如何建立 ICT 供应商安全尽职调查证据包
把获准的软件供应商资料整理成可追溯的证据包,明确标注来源、适用范围、缺口、负责人和复审日期。
关于这篇指南
工作流程
在采购或续约前审核单个 ICT 或软件供应商的采购、安全与 IT 负责人
9 分钟阅读
01
让每个供应商主张都连接到获准文件、日期、修订和适用服务范围。
02
分别记录数据访问、业务韧性、安全证据、依赖关系和尚未回答的问题。
03
为证据包指定负责人和复审日期,不把旧问卷答案当成永久事实。
完整示例
建立 ICT 供应商尽职调查证据包
这是三个文件的虚构尽职调查练习:分开供应商声明与实际证据,找出缺口,再把未决事项交给采购和法务审核。
试做这个任务
只根据三个来源文件,列出实际存在的证据和所有重要缺口,并说明为什么采购或法务负责人必须暂缓决定。每个结论都用 [[filename]] 引用。
预期推理
供应商提供的是说明和问卷回答,不是独立或合同证据。删除证据、数据驻留、子处理者、保证报告和签署条款都缺失;不能推出认证或可接受风险结论。
为什么要保持这些内容关联
一份不完整的供应商资料可以手动核对。当问卷修订、合同、证据附件和人工审核决定需要保持可追溯,又不能虚构保证时,来源链接的尽职调查 wiki 才有帮助。
审核边界
逐项核对声明是否有附件证据,特别看删除记录、驻留数据、子处理者与合同;不要把声明当认证,采购与法务仍需判断。
在 Wenlan 中查看这个示例
Wenlan v0.18.3 界面,呈现隔离测试后读回的数据。来源是虚构教学数据,参考答案为这次练习人工编写;画面没有展示 AI 自动生成或审批完成。
引用的来源变更后,Wenlan 将页面标记为过期,正文仍保留原文。这里的「updating…」表示等待重建,不代表已完成修正。请先检查变更的来源,再重建并审核新答案。
来源文件
打开文件即可阅读完整的人工编写 Markdown。
三种语言视图使用相同的人工编写英文来源数据集。
01supplier-profile.mdMicaGrid Systems — fictional supplier profile
# MicaGrid Systems — fictional supplier profile MicaGrid Systems is a fictional hosting supplier for this teaching exercise. Its profile says it can host application workloads in an EU region and describes encryption in transit and at rest. The profile is a supplier-authored description. It includes no signed contract, independent assurance report, certificate, data-flow diagram, or evidence that the described options are enabled for a particular customer.
02security-questionnaire.mdMicaGrid Systems — questionnaire response
# MicaGrid Systems — questionnaire response Status: fictional response, evidence review pending. The supplier states that customer data can be deleted within 30 calendar days after a written request. It has not attached a deletion test, retention configuration, or service-specific record. Data residency details and the current subprocessor list are unanswered. These statements are questionnaire answers, not legal or compliance certification.
03procurement-review.mdProcurement review checklist
# Procurement review checklist The reviewer has a supplier profile and a questionnaire but no signed data-processing terms, independent assurance report, deletion evidence, residency confirmation, or subprocessor list. Keep the supplier decision on hold until the responsible procurement and legal owners review the missing evidence and contract terms. Do not infer certification, regulatory approval, or acceptable risk from the supplier's statements. A human owner must record any final decision.
参考答案
Reference answer: a supplier statement is not a certification
The packet contains supplier descriptions and a questionnaire statement about deletion within 30 days, but no independent or contract evidence. Residency and subprocessors are unanswered, and procurement and legal owners must review the gaps before deciding; no certification or compliance conclusion is warranted.
MicaGrid Systems — due-diligence reference
Evidence present
The fictional supplier profile describes EU-region hosting and encryption in transit and at rest, but it is a supplier-authored description with no attached contract, assurance report, certificate, data-flow diagram, or customer-specific enablement evidence. supplier-profile.md
The questionnaire states that data can be deleted within 30 calendar days after a written request, but provides no deletion test, retention configuration, or service-specific record. Residency and the current subprocessor list are unanswered. security-questionnaire.md
Decision boundary
This is an evidence gap, not a legal or compliance certification. The missing terms, assurance report, deletion evidence, residency confirmation, and subprocessor list keep the decision on hold. Procurement and legal owners must review the evidence and contract before recording any final decision. procurement-review.md
变更后的来源: security-questionnaire.md
这项变更后的预期更新
The reference's statement that the supplier says data can be deleted within 30 calendar days becomes stale. Revision 2 removes that fixed period and makes timing dependent on the service and written agreement, so deletion timing is now unknown. The missing evidence, no-certification boundary, hold status, and human procurement/legal review remain unchanged.
# MicaGrid Systems — questionnaire response, revision 2 Status: fictional response, evidence review pending. The supplier cannot state a fixed deletion period. Deletion timing depends on the service and written agreement, and no deletion test, retention configuration, or service-specific record is attached. Data residency details and the current subprocessor list remain unanswered. These statements are questionnaire answers, not legal or compliance certification.
01
先说结论:一次审核只处理一个供应商和服务范围
先固定供应商、产品或服务、采购或续约决策、数据访问范围、审核人员与获准来源。证据包至少要记录来源文件、修订、适用范围、韧性与安全证据、依赖服务、缺口、待确认事项、负责人和复审日期。
无法由来源支持或已经过期的主张要明确标为未验证。最终采购判断仍由组织内的采购、安全、法务和隐私负责人按照现有制度作出。
02
把问卷、政策和架构资料拆成可检查的证据
供应商审核经常把现行安全政策、旧问卷、架构图、认证声明和邮件补充混在一张表里。没有日期和适用范围,再流畅的摘要也无法说明某项控制是否适用于正在采购的服务。
- 建立来源登记:保存文件名、版本、日期、提供者、适用服务和允许使用范围。
- 逐项记录主张:连接到准确段落,区分供应商陈述、审核解读、残余风险、矛盾和缺件。
- 标注数据与系统访问:记录数据类型、权限、存储位置、保留方式和分包商或关键依赖。
- 设置复审:来源或服务范围变化时,先把依赖该证据的结论标为过期,再交给具名负责人确认。
有边界的供应商证据工作流
wenlan status
wenlan sources add ~/Reviews/approved-supplier-docs
# 在 Wenlan plugin client 中:
/distill <供应商与审核范围>
/pages <供应商证据包>
/lint
/curate03
一份可复审的供应商证据包应包含什么
把每项内容标为当前有效、过期、互相矛盾、缺乏支持或待补件,并保留证据负责人、审核人、依赖服务和下次复审日期。问卷答案只能算供应商提供的一项主张,不能直接等同控制已经有效落实。
即使不使用 Wenlan,这份来源登记、缺口清单和复审字段仍可作为采购会议中的独立工作成果。
04
Wenlan 的能力与安全边界
Wenlan 能把获准的 Markdown、文本、可提取文本的 PDF、文件夹与只读 Obsidian 来源整理成有来源的 Pages,并显示引用、修订、过期状态、lint 和人工审核。
Wenlan 不会验证认证真伪、不提供法律或隐私意见、不发现供应商、不爬取网站、不做实时监控或漏洞扫描、不自动评分,也不批准或拒绝采购。敏感资料仍须留在组织批准的访问控制中。
让一次供应商审核可追溯
选定一个供应商与服务范围,连接获准证据,并在决策会议前保留所有过期或缺乏支持的主张。
常见问题