FiorLab is a procurement automation platform for EU regulated buyers. Six-dimension supplier scoring, live registry verification across CRO Ireland, Companies House, Handelsregister, VIES and GLEIF, IAF CertSearch, OCR document verification, and audit-ready evidence — end-to-end. Manual procurement compliance under DORA and the EBA outsourcing guidelines is a supervisory finding waiting to happen. Automated procurement compliance is the defensible baseline.
The manual-spreadsheet baseline for procurement compliance is regulator-defective. It has been defective for two full regulatory cycles. It became indefensible on 17 January 2025 when DORA took effect across all 27 EU member states, and it became structurally punitive on 30 June 2026 when the BaFin MaRisk 9th amendment locked in a central outsourcing management function for German banks. The next enforcement wave — the EBA non-ICT third-party risk framework, in final drafting through Q3 2026 — will apply the same evidence bar to the entire remaining EBA-supervised population. There is no defensible manual path through this workload. Procurement automation is not a productivity story any more. It is the audit story.
The number that tends to focus attention is 44% of supply-chain disruptions come from suppliers a buyer classified as "low risk". That is not a data-quality problem. It is a monitoring-cadence problem. A supplier that scored well at onboarding degrades quietly — a certificate expires, a directorship changes, a filing is late, a sanctions match appears. Manual procurement compliance catches none of it until the incident. Procurement automation catches it in the ongoing-monitoring pipeline before the incident.
The DORA penalty ceiling is €10M per incident, or 2% of global turnover, whichever is higher. Article 30 makes the contractual coverage explicit. Article 28(4) makes the supervisory-review evidence bar explicit. The EBA outsourcing guidelines apply the same logic to non-ICT third parties with national variants at CBI Ireland, BaFin Germany, DNB Netherlands, ACPR France, and CSSF Luxembourg. NIS2 Article 21 layers supply-chain risk management on essential and important entities. CSRD ESRS S2 demands supplier due diligence disclosures. GxP under EU GMP Annex 11 requires computerised-system supplier qualification. Every one of these frameworks demands evidence per supplier, per dimension, per date, with the source cited. None of it survives manual procurement compliance at scale.
The procurement automation category exists because a spreadsheet cannot produce Article 28(4) evidence and a source-to-pay suite cannot produce EBA outsourcing evidence. What the regulator wants is an evidence chain — registry record, certification body lookup, OCR-verified document, timestamp, decay model. Automated procurement compliance delivers that chain by default. Manual procurement compliance delivers a screenshot.
Procurement automation at FiorLab is a single deterministic pipeline. Every supplier flows through the same six-dimension scoring engine: financial stability (Altman Z-Score, Piotroski F-Score, working capital, profitability, leverage ratios), regulatory compliance (registry status, certifications, sanctions, jurisdictional posture), ESG / sustainability (environmental, social, governance disclosures mapped to CSRD / ESRS datapoints), delivery performance (SLA history, on-time rate, breach log), quality management (ISO 9001 / 13485 / IATF 16949 / AS9100 verified against IAF CertSearch), and innovation capability (R&D intensity, patents, market posture). Each dimension outputs a raw score, a verification-level tag, and an evidence pointer.
The score is then adjusted by a 5-tier verification multiplier. Registry-verified evidence carries a 1.0x multiplier — the gold standard, verified against the source registry or accredited certification body. Verified evidence (OCR-extracted with cross-reference integrity check) carries 0.95x. Partially verified carries 0.88x. Unverified carries 0.80x. Self-declared tick-boxes carry 0.65x. The multiplier structurally penalises the manual-baseline behaviour of trusting supplier attestation, and structurally rewards the automated procurement compliance behaviour of verifying against the source.
The registry layer is where automated procurement compliance earns its keep. FiorLab cross-checks every supplier against CRO Ireland (services.cro.ie), UK Companies House, the German Handelsregister, VIES (EU VAT validation against the source national authority), and GLEIF (Legal Entity Identifier global lookup). Certifications are cross-checked against IAF CertSearch — the global accredited-body database for ISO 9001, 14001, 27001, 45001, 22000, 50001, 13485, 27701, IATF 16949, and AS9100. Documents are OCR-verified with a 5-tier staleness decay model: fresh under 30 days at full weight, aging 30–180 days at 0.92x, stale 180–365 days at 0.85x, very stale 365–730 days at 0.70x, expired beyond 730 days demoted. Certifications are re-verified weekly against the accreditation body via the cron pipeline. Company registry data is re-verified on a 30-day cadence. All of it end-to-end automated procurement compliance, no analyst intervention required.
The end-to-end procurement compliance workload broken down. Every workflow below is fully automated in the platform — the analyst supervises, the platform executes.
Registration, self-attestation form, evidence collection, questionnaire routing, and initial risk classification. The buyer sends the supplier a single link. The supplier completes the form. The platform ingests, cross-checks against the five EU registries, runs the six-dimension score, and files the assessment. Manual onboarding weeks compress to automated minutes.
Live cross-check against CRO Ireland, UK Companies House, German Handelsregister, VIES, and GLEIF in a single call. Company status (active / dissolved / in liquidation / in examinership), VAT validity, LEI, directorships, filing history. Every hit is timestamped and staleness-decayed. Registry data is the anchor for every downstream score.
The six-dimension score re-runs on every document upload, every certificate re-verification, every registry re-check. The buyer does not schedule "quarterly reviews" any more — the platform surfaces the deltas as they happen. Automated procurement compliance replaces the manual cadence with an event-driven one.
Built-in RFP module for the sourcing stage. Buyer creates the RFP, invites suppliers, receives responses, and scores each response against the same six-dimension model. RFP-stage scoring flows directly into the supplier record post-award, closing the gap between "how we chose them" and "how we monitor them" that manual procurement compliance leaves open.
Auto-flag DORA Article 30 clauses — sub-outsourcing consent, audit rights, exit assistance, service-level definitions, incident notification cadence. The contract module surfaces gaps against the Article 30 checklist so the buyer can request contractual amendments before signature, not at supervisory review.
Six anomaly types across three severities — sudden financial degradation, certification expiry, registry status change, sanctions match, sub-outsourcing disclosure gap, monitoring-cadence miss. Alerts fire to the procurement, compliance, and risk queues with the evidence trail attached. The automated procurement compliance layer that turns a monitoring obligation into a monitoring workflow.
Comparison rows are based on publicly available product documentation, official websites, and analyst coverage as of 22 July 2026. To request a correction, email hello@fiorlab.com.
| FiorLab | SAP Ariba | Coupa | GEP SMART | |
|---|---|---|---|---|
| EU regulatory framework mapping (native) | DORA, EBA (5 NCAs), GxP, MiFID II, CSRD, NIS2 | Add-on modules | Add-on modules | Add-on modules |
| Published price | Free + from €329/mo | Contact sales | Contact sales | Contact sales |
| Free tier | Up to 5 suppliers, full engine | No | No | No |
| Time to first automated assessment | Under 5 minutes | Weeks (professional services) | Weeks (professional services) | Weeks (professional services) |
| Live EU registry integrations | 5 (CRO, CH, HR, VIES, GLEIF) + IAF CertSearch | D&B / partner data | D&B / partner data | Partner data |
| 6-dimension automated scoring | Deterministic rules-based | Configurable via Ariba Supplier Risk | Configurable via Coupa Risk Aware | Configurable |
| DORA Article 28 native | Purpose-built | Framework template | Framework template | Framework template |
| Target segment | Mid-market EU (200–2,000 FTE) | Enterprise / Fortune 500 | Enterprise / Fortune 500 | Enterprise / Fortune 500 |
FiorLab does not replace SAP Ariba, Coupa, or GEP SMART for sourcing, contract execution, catalog management, purchase orders, invoicing, or payments. FiorLab is the procurement automation layer for the compliance-and-risk workflow — supplier scoring, registry verification, framework mapping, and audit-ready evidence. Ariba, Coupa, and GEP buyers frequently run FiorLab alongside their source-to-pay stack because the source-to-pay suites do not produce DORA Article 28 evidence and do not verify certifications against IAF CertSearch. Where a buyer does not already own a source-to-pay suite, FiorLab does not attempt to be one.
FiorLab is built for buyer teams under active regulatory obligation, at mid-market headcount, in EU-regulated verticals. If you are the person whose name is on the DORA register or the CBI outsourcing return, this is your platform.
Buyer-side procurement leads at 200–2,000 FTE companies running 20–200 active suppliers under regulatory scope. Automated procurement compliance removes the spreadsheet backlog and the ad-hoc analyst chase for evidence.
The person responsible for producing evidence at a CBI, BaFin, DNB, ACPR, CSSF, or DORA supervisory review. The audit-ready PDF is designed to be handed directly to the regulator; the evidence chain is designed to survive scrutiny.
Enterprise, operational, and third-party risk leads. The six-dimension score plus anomaly-detection pipeline delivers ongoing-monitoring evidence under DORA Article 28(4) and the EBA outsourcing guidelines without adding analyst headcount.
Financial services (banks, insurers, funds, payments, fintech under DORA / EBA / MiFID II / CBI / BaFin / DNB / ACPR / CSSF). Life sciences (pharma, medtech under EU GMP Annex 11 / GxP). Manufacturing (under CSRD ESRS S2 / German LkSG / EU CSDDD). Construction (under LkSG and CSDDD). Energy (critical infrastructure under NIS2 Article 21).
Standard pricing applies. DORA enforcement, EBA Outsourcing Guidelines, and national NCAs (CBI, BaFin, DNB, ACPR, CSSF) are already operative. We do not subsidise procrastination.
Explore the platform
Growing procurement teams
Regulated industries
Large organisations
All paid plans include a 14-day money-back guarantee. Cancel monthly at any time.
Procurement automation is the end-to-end replacement of manual procurement compliance workflows — supplier onboarding, evidence collection, risk scoring, contract review, ongoing monitoring — with software that ingests data from live sources, applies deterministic rules, and outputs auditor-defensible evidence. In a regulated EU context, procurement automation means every score the platform produces is traceable to a public registry record, an accredited certification body lookup, or an OCR-verified document with a timestamp. Under DORA Article 28 and the EBA outsourcing guidelines, that traceability is the difference between a defensible file and a supervisory finding.
Digitisation moves paper forms into web forms and calls the job done. The workflow is unchanged; only the medium moved. Procurement automation removes the workflow. Instead of the procurement analyst chasing a supplier for a certificate, the platform pulls the certificate status from IAF CertSearch. Instead of a compliance officer typing a company number into three registry websites, the platform cross-checks CRO, Companies House, Handelsregister, VIES, and GLEIF in one call. Instead of a risk manager assembling a scorecard in Excel, the platform runs a deterministic six-dimension score and outputs an audit-ready PDF. Digitisation makes procurement faster on paper. Procurement automation makes procurement defensible in front of a regulator.
No EU regulation names procurement automation as a mandatory technology. Several regulations effectively require it. DORA (in force across all 27 EU member states) demands ongoing monitoring of ICT third parties, a Register of Information, contractual coverage under Article 30, and evidence at supervisory review — impossible at scale by spreadsheet. The EBA outsourcing guidelines, with national variants at CBI Ireland, BaFin MaRisk (9th amendment published 30 June 2026), DNB Netherlands, ACPR France, and CSSF Luxembourg, require a central outsourcing management function, pre-outsourcing risk assessment, and exit-strategy testing. NIS2 Article 21 requires supply-chain risk management for essential and important entities. CSRD ESRS S2 requires supplier due diligence across the value chain. GxP under EU GMP Annex 11 requires computerised-system supplier qualification. Each regulation produces a workflow load that manual procurement compliance cannot service defensibly.
No. SAP Ariba and Coupa are source-to-pay suites — sourcing, contracts, catalog, purchase orders, invoices, and payments. FiorLab is a procurement automation platform for the compliance and risk slice — supplier scoring, registry verification, framework mapping, and audit-ready evidence. Ariba and Coupa buyers frequently run FiorLab alongside their source-to-pay stack because their existing suite does not produce DORA Article 28 evidence, does not verify certificates against IAF CertSearch, and does not score suppliers on the six-dimension model. If you already own Ariba or Coupa, FiorLab is the compliance-and-risk layer that closes the regulatory gap. If you do not, FiorLab does not replace a source-to-pay suite and does not attempt to.
Supplier onboarding to first audit-ready assessment. Register the buyer account, add a supplier by legal name and jurisdiction, and the platform cross-checks CRO Ireland, UK Companies House, German Handelsregister, VIES, and GLEIF in a single call. Add a certification and IAF CertSearch confirms it against the accredited-body database. Upload financial statements and OCR extracts the working-capital, retained-earnings, and EBIT lines for the Altman Z-Score and Piotroski F-Score. The six-dimension score runs deterministically. The audit-ready PDF drops in under five minutes. Total time from registration to first assessment is measured in minutes, not weeks.
Yes. Procurement automation is more valuable at small procurement-team headcount, not less. A one-person compliance function cannot manually monitor 40 suppliers against DORA Article 28 ongoing-monitoring obligations without a platform. The FiorLab Starter plan is free up to 5 suppliers with the full six-dimension scoring engine, live registry verification, and audit-ready PDF output. Growth (up to 25 suppliers) is €399 per month (€329 per month billed annually). Professional (up to 100 suppliers) is €799 per month (€649 per month billed annually). Sub-5 procurement teams typically move to Growth after the first quarter and Professional at the second regulated onboarding wave.
CRO Ireland (services.cro.ie) for Irish company status, officers, and filing history. UK Companies House for UK company registry data. German Handelsregister via the FiorLab HRB provider. VIES for EU VAT-number validation against the source national authority. GLEIF for the Legal Entity Identifier global lookup. IAF CertSearch for ISO 9001, 14001, 27001, 45001, 22000, 50001, 13485, 27701, IATF 16949, and AS9100 verification against the accredited-body database. Every registry hit is timestamped, staleness-decayed, and cited in the assessment PDF. Registry-verified evidence scores at the 1.0x multiplier; self-declared evidence scores at 0.65x. Registry data is the backbone of automated procurement compliance under the EU framework.
Procurement automation at FiorLab is not DORA-only. The platform supports GxP assessments for life sciences buyers (EMA Annex 11, EU GMP computerised-system supplier qualification), a Standard assessment type for manufacturing, construction, energy, and general regulated procurement, a Hybrid assessment type where a buyer needs both financial-services and non-financial frameworks in one assessment (for example, a payments-adjacent tech vendor selling into a manufacturer), and framework-specific report templates. Buyers in construction under the German LkSG, in life sciences under EU GMP, in manufacturing under CSRD ESRS S2, and in energy under CSDDD get the same six-dimension scoring engine, the same live registry verification, and the same audit-ready PDF — mapped to the framework that applies to them.
DORA is enforced across all 27 EU states. EBA Outsourcing Guidelines apply. Up to 5 suppliers on the free Starter plan, full six-dimension scoring, live registry verification, and audit-ready PDF reports. EU-hosted, customer-owns-data. No credit card.
Start Your Assessment