FiorLab is vendor management software built for the regulator's evidence question. Six-dimension scoring, live registry verification against five EU sources plus IAF CertSearch, a 5-tier verification multiplier, and audit-ready export mapped to DORA Article 28, EBA outsourcing, NIS2, and GxP. EU-hosted. Free Starter tier, no credit card.
Vendor management software is the system of record for a regulated buyer's third-party vendor population. It handles onboarding, evidence collection, risk assessment, contract terms, ongoing monitoring, and off-boarding. In 2026 the category has quietly changed. Vendor management software is no longer a procurement convenience — it is a regulator-facing capability. The buyer must be able to show which vendor was assessed on which date, on what evidence, by whom, and with what outcome, at the moment the supervisor asks.
DORA is now enforced across all 27 EU states. Financial entities that fail to maintain an Article 28 Register of Information on every ICT third-party service provider face administrative penalties up to EUR 10 million or 2% of annual worldwide turnover, whichever is higher. NIS2 has been in force since October 2024 for essential and important entities and pushes the same evidence obligation into critical infrastructure. National EBA outsourcing implementations — CBI in Ireland, BaFin MaRisk in Germany, DNB in the Netherlands, ACPR in France, CSSF in Luxembourg — add jurisdiction-specific ongoing-monitoring cadences. GxP Annex 11 requires qualified vendors for GxP-relevant activities in life sciences.
Generic vendor management tools cannot answer the regulator's evidence question. SAP Ariba, Coupa, and Oracle Procurement Cloud are procure-to-pay suites optimised for spend, sourcing events, and invoicing across an entire vendor base. They store the contract, the purchase order, and the invoice. They do not verify the ISO 27001 certificate against the accredited certification body. They do not check the VAT number against the national tax authority. They do not track document staleness on a defensible decay curve. When the supervisor asks "walk us through how you knew this vendor was compliant on the day you renewed the contract", the answer inside a generic vendor management platform is a screenshot of a PDF someone uploaded eighteen months ago.
Regulator-facing vendor management software carries different evidence. It verifies against the source. It scores the verification. It timestamps the check. It surfaces the gap. That is the category FiorLab is built for.
Three steps from a first vendor to an auditor-defensible assessment. Five minutes to first assessment on a real EU vendor.
Add a vendor to the vendor management platform in under a minute — legal name, jurisdiction, VAT or company number, primary contact. Optional self-attestation on ISO certifications, financial data, and ESG posture. The vendor can be invited to complete their own onboarding, or the buyer's team can enter it directly. Every field is audit-trailed with who added it and when.
FiorLab runs the six-dimension scoring engine — financial stability, regulatory compliance, ESG/sustainability, delivery performance, quality management, innovation capability. Each dimension is verified against the source: five live EU registries (CRO Ireland, UK Companies House, German Handelsregister, VIES, GLEIF) plus IAF CertSearch for ISO 9001, 14001, 27001, 45001, 22000, 50001, 13485, 27701, IATF 16949, and AS9100. The 5-tier verification multiplier (registry_verified 1.0x down to self_declared 0.65x) applies per dimension.
The vendor management platform re-verifies registry data on a 30-day cadence and ISO certifications weekly against IAF CertSearch. Document staleness is scored on a 5-tier decay curve. Export a regulator-ready PDF with the full per-dimension evidence chain — every score traced to a registry record, a certification body lookup, or an OCR-verified document with a timestamp. Mapped to DORA Article 28, EBA outsourcing guidelines, NIS2, and GxP.
The vendor management platform features that separate a regulator-facing tool from a spreadsheet with a login.
Invite the vendor into the vendor management platform directly. Structured intake — legal identity, jurisdiction, tax numbers, primary contact, ISO certifications, financial disclosures, ESG posture, sub-processor list. The vendor completes the form, uploads supporting documents, and signs the T&C. Every field is audit-trailed with who filled it and when. No email PDF ping-pong.
Five EU registry integrations run inline: CRO Ireland (services.cro.ie), UK Companies House, German Handelsregister, VIES for EU VAT validation, GLEIF for the Legal Entity Identifier lookup. IAF CertSearch verifies ISO certificates against the global accredited-body database. French Infogreffe is planned. Every call is timestamped and stored as evidence in the vendor management record.
Deterministic rules-based scoring across financial stability (Altman Z-Score, Piotroski F-Score), regulatory compliance (registry status, certifications, sanctions), ESG/sustainability (CSRD-mapped disclosures, LkSG, CSDDD), delivery performance (SLA history, breach log), quality management (accredited ISO evidence), innovation capability. Version 3.2.0 of the scoring engine — the same engine used across every vendor management tenant.
The vendor management platform captures the contract lifecycle with signature evidence stored alongside the assessment score. Every T&C document is versioned and linked to the vendor record. Signatures are cryptographically bound; supporting documents included by reference. The audit trail records who signed, when, and against which version.
Run an RFP inside the vendor management platform. Invite candidates, capture their responses in a structured template, and rank on the scored evidence — not a subjective evaluation matrix. The winning bid arrives with the six-dimension assessment already attached. When the regulator asks "how did you select this vendor", the answer is the assessment PDF, not a memory of a procurement meeting.
Every action inside the vendor management software is written to an append-only audit log — who invited the vendor, who assessed which dimension, who signed the T&C, who exported the PDF, who granted access to whom. The log is the answer to "walk us through what happened" that a supervisor is trained to ask. EU-hosted, customer-owns-data, deletion on off-boarding is a one-click action with the log preserved.
Every dimension in the vendor management platform is scored against a verification tier. The tier determines the multiplier. The multiplier disincentivises self-declaration and rewards verified evidence.
| Verification level | Multiplier | What it means for the vendor management record |
|---|---|---|
| registry_verified | 1.0x | Verified against the source registry (CRO, Companies House, Handelsregister, VIES, GLEIF) or the accredited certification body (IAF CertSearch). The gold standard for auditor defensibility. |
| verified | 0.95x | Verified via OCR-extracted document with cross-reference integrity check against company name and registry status. Strong evidence, slight discount versus a direct registry call. |
| partially_verified | 0.88x | Some evidence verified, some gaps. The dimension is scored on the verified portion with the gap flagged in the vendor management assessment output. |
| unverified | 0.80x | Document uploaded but no cross-reference integrity check possible. Suitable for non-critical signals. |
| self_declared | 0.65x | Tick-box claim with no evidence. Significant discount applied. Not defensible at supervisory review on its own. |
Every vendor management software vendor claims to "verify". Almost none surface the tier of verification back to the buyer with a multiplier attached. FiorLab does. A vendor whose ISO 27001 is registry-verified through IAF CertSearch scores materially higher than one who ticked the same box on the intake form. When the supervisor asks "how do you know this vendor holds this certification", the answer is a link to the accredited body's confirmation, not a vendor's assurance.
How FiorLab's vendor management platform compares to incumbents on the criteria that matter for EU regulated buyers. Based on publicly available product documentation, official websites, and analyst coverage as of 22 July 2026. To request a correction, email hello@fiorlab.com.
| FiorLab | OneTrust Vendor Risk | Aprovall | Vendorica | |
|---|---|---|---|---|
| HQ jurisdiction | Ireland (EU) | USA | France (EU) | USA |
| Data residency | EU-hosted, customer-owns-data | Multi-region, US default | EU-hosted | US-hosted |
| Published pricing | From EUR 329/mo (annual) | Contact sales | Contact sales | Contact sales |
| Free tier | Yes — up to 5 vendors | Demo only | Trial only | Demo only |
| Time to first assessment | ~5 minutes, self-serve | Weeks — implementation-led | Days — onboarding-led | Days — onboarding-led |
| Live EU registry integrations | 5 (CRO, CH, HR, VIES, GLEIF) + IAF | D&B / Bureau van Dijk partner data | Comparable EU set | D&B / CreditSafe partner data |
| DORA Article 28 native | Native, mapped in export | Add-on module | Native (EU-focused) | Add-on module |
| Target segment | Mid-market EU (200–2000) | Enterprise multi-region | Mid-market to enterprise EU | Enterprise US-first |
Vendor management platform designed around the roles that carry the regulator-facing evidence obligation at mid-market EU firms.
EU financial services (DORA + national EBA outsourcing). Life sciences (GxP Annex 11, GDPR Article 28). Manufacturing (CSDDD, LkSG, IATF 16949 supply chains). Construction (public procurement, ESG/CSRD, subcontractor cascades). Critical infrastructure (NIS2 essential and important entities). If the buyer is in one of these five, generic procurement software is no longer sufficient. Vendor management EU has become its own category.
Published pricing. No contact-sales gate. Free Starter is not time-limited — it is the permanent free entry point to the vendor management software.
Vendor management software is the system of record for a regulated buyer's third-party vendor population. It handles vendor onboarding, evidence collection, risk assessment, contract terms, performance monitoring, and off-boarding. Under DORA, EBA outsourcing guidelines, NIS2, and GxP, vendor management software is now a regulator-facing capability: the buyer must be able to show which vendor was assessed on which date, on what evidence, by whom, and with what outcome. Vendor management software that only stores contact details and contract PDFs no longer meets the 2026 supervisory bar.
Vendor management software is the broader system of record — it handles the lifecycle from onboarding through off-boarding, and includes contract, spend, and performance data. Vendor risk management software is one module inside that lifecycle: the assessment of financial, regulatory, cyber, operational, and ESG risk on each vendor. FiorLab covers both — a single vendor management platform where the risk assessment is the core scored artefact, not a bolt-on questionnaire.
DORA (Digital Operational Resilience Act, in force since 17 January 2025, penalties up to €10 million or 2% of annual worldwide turnover) requires financial entities to maintain a Register of Information on every ICT third-party service provider (Article 28) with prescribed data fields. EBA outsourcing guidelines and their national implementations — CBI Cross-Industry Outsourcing (Ireland), BaFin MaRisk 9th Amendment (Germany), DNB Good Practice on Outsourcing (Netherlands), ACPR outsourcing guidance (France), CSSF Circular 22/806 (Luxembourg) — require documented vendor due diligence, ongoing monitoring, and exit planning. NIS2 (from October 2024) requires vendor-chain cyber risk management for essential and important entities. GxP (Annex 11, GMP) requires qualified vendors for GxP-relevant activities. Vendor management software carries the evidence for every one of these.
No. SAP Ariba and Coupa are procure-to-pay suites optimised for spend, sourcing events, contracts, and invoicing across a very large vendor base. FiorLab is vendor management software optimised for the regulator's evidence question on the smaller subset of vendors that carry regulatory exposure — typically 5% to 20% of the buyer's vendor list. FiorLab sits alongside procure-to-pay tools, not in their place. Buyers keep their Ariba or Coupa contract lifecycle and pull the regulator-facing vendors into FiorLab for scored, evidence-backed assessment and audit-ready export.
FiorLab applies a per-dimension verification multiplier: registry_verified 1.0x (verified against the source registry or accredited certification body), verified 0.95x, partially_verified 0.88x, unverified 0.80x, self_declared 0.65x. In vendor management terms this means a vendor that produces a registry-checked ISO 27001 certificate through IAF CertSearch scores materially higher than a vendor that self-attests it. The multiplier is what makes the vendor management software auditor-defensible: a supervisor can trace every score back to a registry record, a certification body lookup, or an OCR-verified document with a timestamp.
Yes. The vendor management platform onboards any vendor globally. The registry verification set is EU-first (CRO Ireland, UK Companies House, German Handelsregister, VIES, GLEIF) plus global IAF CertSearch for ISO certifications, so EU-domiciled vendors get the deepest registry-verified scoring. Non-EU vendors are assessed on OCR-verified documents, GLEIF LEI lookup, and self-attested fields — the verification multiplier applies, so the assessment surfaces the evidence gap honestly rather than papering over it.
Yes — small procurement and compliance teams are our design centre. Vendor management software historically priced smaller regulated buyers out of the category (enterprise seat licences, six-figure implementations, US-hosted data). FiorLab publishes pricing from Free (up to 5 vendors) through Growth (€329 annual billing, up to 25 vendors), so a two-person procurement team at a mid-market EU firm can run a full DORA Article 28 assessment on their in-scope vendors without a procurement approval process of their own.
Free Starter includes vendor management for up to 5 vendors, the full 6-dimension scoring engine, live registry verification against CRO Ireland, UK Companies House, German Handelsregister, VIES, GLEIF, and IAF CertSearch, the 5-tier verification multiplier, document staleness decay, audit-ready PDF export with the per-dimension evidence chain attached, immutable audit trail, and EU hosting. No credit card. The Starter tier is not time-limited — it is the permanent free entry point to the vendor management platform.
Vendor management software used to be a filing cabinet with a search bar. In 2026 it is the artefact a supervisor reads first. We built FiorLab because the buyers we spoke to in Dublin, Frankfurt, Amsterdam, and Paris were being asked the same question by their regulator and reaching for the same answer: a folder of PDFs, a spreadsheet with a "last reviewed" column, and a hope that no one asked for the accreditation body confirmation. The evidence question is not going away — DORA is enforced, NIS2 is in force, the EBA guidelines are being tightened, and every national regulator has vendor risk in its 2026 supervisory priorities. Run a real assessment on a real vendor in our free Starter plan, no card required. If the evidence chain stands up to your supervisor's scrutiny, the rest is conversation. Reach us at hello@fiorlab.com.
— Word from our founder
Free, live in 5 minutes. Full 6-dimension scoring, live EU registry verification, and audit-ready PDF export from the vendor management platform. EU-hosted, customer-owns-data. No credit card.
Start managing vendors free