The register is a view of your data, not a second job
Six supervisory frameworks run on one engine. Each is a definition over the suppliers, contracts and incidents your team already maintains, so the register is current the day you open it and the export is reproducible.
Frameworks are data, not code
A register is a field definition plus a deriver that reads your live data. That is why six of them exist rather than one, and why the seventh is a definition rather than a release.
Derive
The engine reads your vendors, contracts and incidents and fills every field it can answer from live data.
Fill the gaps
What cannot be derived is edited inline, on the register itself, with the edit attributed.
Review
A blocking banner names what is still missing before the register can be considered complete.
Submit and keep
Export the pack and keep the submission history, so the next cycle starts from the last one.
One engine, six jurisdictions
Register of Information across contractual arrangements, with concentration analysis and structured submission output.
Article 21 supply-chain measures tracked against your suppliers, with Article 23 reporting readiness derived from live incidents.
Important business services mapped to the suppliers underneath them, with impact tolerance recorded per service.
Interagency third-party guidance evidenced across the relationship lifecycle, assembled into an examiner-ready pack.
Outsourcing register under Notice 644 with the incident notification clock and board attestation captured alongside it.
Critical operations and their service providers, tolerance levels, and the notification trail regulators ask to see.
See your own register, populated.
Bring a supplier list and we will show you what the register derives and what it still needs from you.
