OTRISK
Product · Supplier audits

Audit your suppliers where you audit yourself.

Invite integrators, maintenance parties and product suppliers to answer requirements inside your OTRISK tenant: IEC 62443-2-4, 3-3, 4-1, 4-2 or NIST SP 800-82, against the target you set. They submit, your team accepts, and both verdicts stay on the record.

Supplier audit · Westerdok Automation IEC 62443-2-4 · third-party mode
Third party · Westerdok Automation lead p.janssen · team of 4
Active
Patch management procedure KD
Accepted
Remote access policy PJ
First-stage review
Staff training records KD
Awaiting your verdict
Backup & restore evidence PJ
Rejected
ML 2 target · 62 criteria in scope · nobody accepts their own submission

Illustrative recreation of the workspace · demo data, no customer content.

Their systems, your accountability

Half your OT is theirs to run.
The integrator built the system, the maintenance party holds the keys, the product supplier ships the firmware. The risk stays yours, and NIS2 puts supply-chain security explicitly in your duty of care.
Questionnaires collect claims.
A supplier questionnaire comes back as a filled-in PDF: statements without evidence, checked by nobody, stale by the next contract year.
The proof is scattered.
Certificates in a procurement folder, attestations in mailboxes, audit notes in someone's head. When your auditor asks how you oversee suppliers, assembling the answer takes weeks.

Supplier oversight deserves the same discipline as your own assessments. Same system, same rules.

The invite flow, step by step

A supplier audit in OTRISK is a normal assessment with one difference: the organisation answering is not yours. The flow enforces who does what.

1
Create the assessment. Pick the standard first: IEC 62443-2-4 for a service provider, 3-3 for a delivered system, 4-1 or 4-2 for a product supplier, NIST SP 800-82 for an OT program. Set the maturity or security-level target; only requirements your target demands enter scope.
2
Invite the supplier organisation. Their lead gets their own role in your tenant and assembles their own team. You keep sight of progress from day one.
3
They answer, with evidence. Each requirement gets the supplier's answer and evidence, attached to the requirement it belongs to instead of an email thread.
4
Their lead reviews first. First-stage review happens inside the supplier's team: their lead approves internally before anything reaches you. Half-finished work stays on their side.
5
Your team gives the verdict. Accept or reject in your Review Queue, with a logged reason. Rejections go back to the supplier with the reason attached; acceptances close the requirement, on the record.
SUP-14 · Patch management procedure Awaiting your verdict Westerdok Automation · third party
Evidence
PDF patch-process-v3.pdf k.devries · 22 Jul 2026
XLSX rollout-log-Q2.xlsx k.devries · 22 Jul 2026
Stage 1 · supplier lead
Approved · p.janssen · 23 Jul 2026
Stage 2 · your verdict
Open · assigned s.willems
Accept Reject with reason submitted · k.devries · first stage passed
SUP-14 · Patch management procedure
Accepted
2026-07-24 10:12 · s.willems · final verdict: accepted · "procedure matches contract annex B"
2026-07-23 15:40 · p.janssen · first stage: approved · "evidence complete"
2026-07-22 09:18 · k.devries · evidence uploaded · patch-process-v3.pdf
2026-07-15 11:02 · s.willems · rejected · "Q2 rollout log missing"
process log · permanent · both stages logged

Two stages, both on the record

The supplier submits. Their lead approves, stage one. Your reviewer decides, stage two. The platform enforces the order and the separation: nobody accepts their own submission, and a supplier approval never counts as your acceptance.

Why it matters for procurement: when the renewal or the next bid comes, nobody trades recollections. Both sides look at the same requirement, the same evidence and the same logged verdicts, each with a name, a timestamp and a reason. The conversation stays factual.

What the asset owner sees

A questionnaire leaves and silence follows. A supplier audit in your own tenant behaves differently: you watch it move.

Criteria in scope
62
IEC 62443-2-4 · ML 2 target
Answered by supplier
47
evidence attached per criterion
Awaiting your verdict
5
grouped in your Review Queue
Progress
68%

Progress without chasing.

Every requirement shows its owner, its deadline and its state. Overdue items surface on their own; nobody chases by email.

Evidence with verdicts attached.

Each piece of evidence stays linked to its requirement and both verdicts, for years. Downloads are policy-guarded.

Reports on demand.

Generate the assessment report as a PDF whenever someone asks, and export the audit data to XLSX or PDF for procurement or your auditor.

The 2-4 profile: your contract baseline

IEC 62443-2-4 describes the security capabilities an OT service provider must bring: staffing, architecture, remote access, patching, backup and more. That makes it the natural baseline for integration and maintenance contracts: agree the profile and the maturity target in the contract, then keep a standing assessment against it in your tenant.

Contract renewals change character. Instead of a fresh questionnaire, you open the record: what was accepted, what was rejected and why, and what changed since last year.

Maintenance contract · security annex renewal 2027
BaselineIEC 62443-2-4 profile
Maturity targetML 2
Standing assessmentasset owner tenant
Reviewtwo-stage · logged
last verdict 2026-07-24 · 47 of 62 criteria answered

What runs in third-party mode

Five requirement standards support the supplier flow today. Each runs the same loop: their answer, their lead's first-stage review, your verdict.

IEC 62443-2-4
Service providers
Integration and maintenance programs at a maturity target. The natural supplier audit for the parties running your OT.
IEC 62443-3-3
Delivered systems
The system an integrator hands over, assessed against its security-level target. Requirements above the target stay out of scope.
IEC 62443-4-1
Secure development
A product supplier evidences their development lifecycle, vulnerability handling and patch delivery included.
IEC 62443-4-2
Component requirements
Component capabilities per security level: the clauses your RFPs quote.
NIST SP 800-82
OT security programs
The OT guidance many corporate frameworks mandate, answered by the supplier that operates it.
Deliberately not here
IEC 62443-3-2

The risk assessment stays a self-assessment: the risk decision is yours, taken with two-person review. Supplier evidence can inform it; it never replaces it.

For asset owners →

Owning OT risk across supplier-run systems: targets, evidence, proof.

For integrators & service providers →

The other side of the audit: answer once, properly, and reuse it every bid.

Assessments & evidence →

The requirement, owner, evidence, verdict loop that every standard runs on.

Put your next supplier audit on the record.

Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.