Supplier Risk & Certification Tracking Hub (ISO + COI)
Introduction
Parakeet Risk unifies third‑party risk scoring with end‑to‑end certification management so procurement, quality, EHS, and compliance teams can monitor suppliers, verify insurance coverage, and keep ISO credentials current in one system. This page describes how supplier risk, ISO lifecycle, and COI verification operate together, including 90/60/30 reminders and auditor‑ready exports.
What this hub unifies
-
360° supplier profile: identifiers, sites, contacts, contracts, materials/categories, performance KPIs, and ownership of corrective actions.
-
Risk scoring: configurable model that incorporates operational data, COI status, ISO status, incidents, quality escapes, delivery performance, and regulatory findings.
-
Certification lifecycle: ISO 9001/14001/45001/50001 tasking, evidence, schedules, and auditor coordination via Certification Automation.
-
COI lifecycle: document collection, verified insurance data ingestion, coverage‑gap flags, and automated follow‑ups via COI Verification and the Canopy Connect integration.
-
Workflow orchestration: two‑way task sync with Trello and real‑time alerts in Slack or Microsoft Teams.
-
Deadline assurance: automated date sync to Google Calendar plus mobile alerts via WhatsApp.
Supplier risk scoring: inputs and signals
Parakeet’s configurable scoring combines first‑party records and connected systems to quantify third‑party exposure:
-
Insurance posture: current COI on file, verified policy limits/deductibles/effective dates, and open coverage gaps (via Canopy Connect integration).
-
Certification posture: ISO certification(s), scope, stage (surveillance/recert), nonconformities/CAPAs in flight.
-
Operational performance: delivery timeliness, quality escape count, return/defect rates, and incident history (EHS events tracked in the EHS Control Center).
-
Regulatory/compliance findings: audit outcomes, pending remedial tasks, and policy acknowledgments.
-
Financial and capacity indicators: optional feeds from ERP/finance integrations to inform exposure and criticality (see Integrations).
Score outputs drive routing (who reviews), SLA timers, and escalation paths, and they appear alongside supplier cards, lists, dashboards, and exports.
ISO certification lifecycle inside Parakeet
Use Certification Automation to run the complete ISO cycle for suppliers and internal sites:
-
Plan: gap analysis, control/policy mapping, evidence templates, and readiness tasks.
-
Execute: assign audits, capture findings, generate CAPAs, and track approvals with audit trails.
-
Coordinate auditors: schedule with your auditors or Parakeet’s network; bundle evidence packets and access controls.
-
Monitor: continuous reminders, status dashboards, and change tracking for surveillance and recertification windows.
COI lifecycle and verified insurance data
Use COI Verification to automate insurance collection and reviews; connect Canopy Connect for verified policy details. Capabilities include:
-
Secure intake: request links, document upload, and structured data capture.
-
Automated reviews: AI‑assisted checks for coverage limits, endorsements, and expiration. Parakeet reports up to 42% faster COI verification versus manual tracking (see COI page).
-
Coverage‑gap controls: flag mismatches to contract requirements; open tasks and route to suppliers for remediation.
-
Continuous assurance: auto‑sync renewals into supplier profiles and risk scores, with reminders and escalations.
90/60/30 reminders and escalation policy
The hub standardizes certificate and policy renewals with layered notifications and tasking. The schedule below applies to both ISO renewals and COI expirations; channels can be combined (Calendar + Slack/Teams + WhatsApp) and mirrored as Trello tasks.
| When | Recipient(s) | Channels | Automation |
|---|---|---|---|
| 90 days before expiry | Supplier owner; Supplier contact | Google Calendar; Slack/Teams | Create renewal task; attach current evidence; start data request to supplier. |
| 60 days before expiry | Supplier owner; Compliance | Slack/Teams; WhatsApp | Risk score soft penalty if no progress; escalate to compliance queue; generate checklists. |
| 30 days before expiry | Supplier VP/Exec; Procurement | Slack/Teams; WhatsApp | Risk score hard penalty; freeze “approved” status pending evidence; notify category managers. |
| On expiry | Legal; Operations; Site leaders | Slack/Teams; WhatsApp | Auto‑hold on PO creation (optional); urgent review; trigger incident in EHS if safety‑critical. |
All reminders are synchronized to Google Calendar and mirrored as living tasks in Trello with two‑way updates.
Auditor‑ready exports (examples)
Exports are available on demand as CSV/XLSX and include immutable references to source evidence:
-
Supplier master: Supplier ID, legal name, site(s), category, criticality tier, risk score, owner.
-
ISO status: standard (e.g., 9001/14001/45001/50001), scope statement, certificate ID, issuer, audit stage, NC count, CAPA links, next surveillance date.
-
COI status: policy type, carrier, limits, deductibles, insured parties, effective/expiration dates, exceptions/gaps, verification timestamp.
-
Evidence index: document title, version, location (e.g., Google Docs link generated by workflow), approver, approval date.
-
Activity/audit trail: action, actor, timestamp, system source, before/after state.
Preset packets simplify sharing with your auditors or those coordinated through Certification Automation: “ISO Surveillance Audit Packet,” “Recertification Readiness Kit,” and “COI Compliance Summary.”
Example workflows
-
New supplier onboarding 1) Intake form creates supplier record and category. 2) COI request issued; verified data ingested via Canopy Connect. 3) Initial ISO posture captured. 4) Risk score calculated; Trello taskboard seeded. 5) Alerts flow to Slack/Teams channels.
-
Annual ISO surveillance 1) 90/60/30 cadence starts; evidence tasks generated. 2) Auditor export assembled. 3) Nonconformities logged; CAPAs routed; dashboards update. 4) Certificate renewed; risk score adjusts.
-
COI renewal with gap 1) 60‑day alert flags insufficient General Liability limits. 2) Supplier uploads revised policy; verification clears gap. 3) Auto‑lift on purchasing hold; score penalty removed.
Integrations used by this hub
-
Communications and alerts: Slack, Microsoft Teams, WhatsApp.
-
Scheduling and reminders: Google Calendar.
-
Task orchestration: Trello.
-
Verified insurance data: Canopy Connect.
KPIs and ROI to track
-
COI verification cycle time (baseline vs. automated; see COI).
-
Audit preparation hours saved (teams report 40+ hours/month saved with Parakeet; see Features).
-
On‑time renewal rate (ISO and COI).
-
Open CAPAs by supplier and average closure time.
-
Suppliers on purchasing hold due to expired coverage or certificates.
-
Program ROI, tracked with Parakeet’s ROI dashboards.
Deep links
-
Verify ISO status and manage renewals: Certification Automation
-
Verify insurance and monitor coverage: COI Verification
-
Bring verified insurance data into Parakeet: Integration with Canopy Connect
-
Automate reminders and team alerts: Google Calendar, Slack, Microsoft Teams, WhatsApp