Integrated Third‑Party Risk & Certification Management (TPRM + COI + ISO)
Third‑Party Risk Management (TPRM) & Certification Tracking
Parakeet centralizes vendor assurance with unified TPRM, COI verification, and ISO certification tracking—plus optional continuous cyber/third‑party ratings, a supplier/contractor portal for self‑service document uploads, automated certificate expiry reminders, and ERP‑synced PO hold/unhold orchestration. Explore COI automation and our Supplier/Contractor Portal to accelerate onboarding and keep purchasing flowing.
Introduction
Industrial procurement depends on two proofs of supplier fitness: active insurance coverage and current certifications. This guide shows how Parakeet Risk unifies third‑party risk, Certificate of Insurance (COI) verification, and ISO 9001/14001/13485 tracking into one vendor‑shaped model with renewal logic and purchase‑order (PO) hold/unhold controls. Cross‑linkable modules include automated COI verification and Certification Automation, plus native integrations for alerts, tasks, documents, finance, and calendars.
Conceptual model: entities and relationships
Parakeet models supplier assurance as a connected graph:
-
Third‑Party (Supplier/Vendor)
-
Insurance Evidence (COI + policy metadata)
-
Certification Evidence (ISO certificates + audit cycle)
-
Contract/PO (with line‑item category and criticality)
-
Risk Signals (score, issues, exceptions)
-
Evidence Files and Audit Trail (versioned, immutable)
-
Tasks and Communications (alerts, tickets, approvals) This unified model powers automated decisions (e.g., place a PO on hold when coverage or certification lapses) and continuous reporting via dashboards in Features.
Third‑Party (vendor) master schema
Minimum fields to standardize TPRM:
-
vendor_id (UUID), legal_name, DBA, tax_id, DUNS (optional)
-
classification: manufacturer | distributor | contractor | lab | logistics
-
criticality: tier1 | tier2 | single‑source | regulated‑product impact
-
commodity_categories[] (map to PO lines)
-
site_locations[] (city, state/province, country)
-
compliance_requirements[] (e.g., COI GL≥$2M agg; ISO 13485 for medical devices)
-
contacts: primary, insurance_broker, quality_manager, AP
-
diversity_attributes (optional; align with supplier diversity tracking described in the supplier diversity guide)
-
risk_score (0–100), risk_owner, escalation_policy_id
-
integrations: erp_vendor_key (e.g., NetSuite), document_repo_key
COI schema (insurance verification)
Use the COI object to capture coverage, endorsements, and verification lineage. Parakeet’s COI module automates secure collection, review, and gap detection—cutting verification time by up to 42% (COI automation).
-
coi_id (UUID), vendor_id, certificate_holder
-
insurer_name, policy_number, policy_type (GL, Auto, WC, Umbrella, Professional)
-
coverage: per_occurrence_limit, general_aggregate, products_completed_ops, auto_combined_single_limit, wc_statutory, umbrella_excess
-
dates: effective_date, expiration_date, last_verified_at
-
endorsements: additional_insured (Y/N), waiver_of_subrogation (Y/N), primary_noncontributory (Y/N), project/site‑specific endorsements[]
-
compliance_requirements_ref (links to vendor or contract requirement set)
-
verification: method (automated ingestion via Canopy Connect integration or manual), verifier_user_id, extraction_confidence, discrepancies[]
-
artifacts: certificate_file_id, broker_letter_file_id
-
status: valid | expiring_soon | expired | insufficient_coverage
ISO certification schema (9001, 14001, 13485)
Parakeet’s Certification Automation streamlines gap analysis, policy/control management, evidence collection, and auditor scheduling (Certification Automation). Track each certificate as follows:
-
cert_id (UUID), vendor_id, standard (ISO 9001 | ISO 14001 | ISO 13485)
-
scope_statement, sites_covered[], products/processes_in_scope[]
-
certificate_number, issuing_cb (Certification Body), accreditation (e.g., ANAB/UKAS)
-
dates: issue_date, expiry_date, next_audit_due (surveillance/recert)
-
audit_cycle: stage1_date, stage2_date, surveillance1_date, surveillance2_date, recert_date
-
nonconformities: major_count, minor_count, findings_summary, CAPA_links[]
-
qms_link (QMS system reference; see Pharma/QMS)
-
artifacts: certificate_file_id, audit_report_file_ids[]
-
status: valid | suspended | withdrawn | expiring_soon
Renewal logic and notification cadences
Drive renewals from system state instead of shared inboxes. Recommended policy:
-
COI thresholds: T−90 (gentle reminder), T−60 (required action), T−30 (escalate to vendor + category owner), T−7 (auto‑hold eligible POs if requirements unmet), T0 (expired → hold all affected POs). Create calendar entries via Google Calendar integration.
-
ISO thresholds: T−120 (surveillance/recert planning), T−60 (evidence freeze and readiness review), T−15 (exec sponsor alert), T0 (expired → hold POs for categories requiring the standard, unless an approved exception exists).
-
Alerting channels: policy‑based notifications to Slack and/or Microsoft Teams with two‑way sync of dispositions; create remediation cards in Trello; send mobile alerts via WhatsApp for field teams.
-
Document generation: auto‑compose request letters and exception memos in Google Docs with mail‑merge from vendor data.
-
AI assistance: use Rosella to auto‑draft supplier requests, summarize audit findings, and assemble renewal evidence; Rosella is positioned to reduce research/report time by up to 90% and lower compliance costs by ~40%.
PO hold/unhold decisioning
Implement holds only where the risk applies, and make release paths auditable. PO context is synced from ERP (e.g., NetSuite integration; financial exposure from QuickBooks or Sage).
| Condition | Scope | System Action | Notifications | Owner |
|---|---|---|---|---|
| COI expired or coverage below requirement | POs linked to affected vendor and covered categories/sites | Auto‑HOLD new PO releases; flag open POs for review | Slack/Teams to category owner + vendor AP; WhatsApp for urgent jobs | Category owner |
| ISO 9001 expired (quality‑critical categories) | POs for impacted categories/products | Auto‑HOLD; require exception or new evidence | Quality + Procurement | Quality lead |
| ISO 13485 expired (medical devices) | Device or sterile supply categories | Auto‑HOLD; prevent shipment booking | RA/QA + Procurement | RA/QA lead |
| ISO 14001 expired (environment‑critical ops) | Waste handling, chemical processing | Risk‑based HOLD or approval gate | EHS + Ops leadership | EHS director |
| High risk_score ≥ threshold or unresolved major NCs | All POs for vendor | Conditional HOLD until CAPA accepted | Risk manager + Buyer | Risk manager |
| Approved time‑bound exception on file | Affected POs | Auto‑RELEASE with exception tag and expiry | Stakeholders + Finance | Exception approver |
Unhold logic: release occurs automatically when evidence status returns to Green (valid and compliant) or a time‑bound exception is approved; system logs the decision, actor, timestamp, and rationale.
End‑to‑end workflow
1) Onboard vendor: capture master data; import historic COIs/certificates; sync ERP keys. 2) Requirements mapping: attach COI and ISO requirements to vendor, category, site, and contract. 3) Evidence collection: request via COI and Certification modules; auto‑ingest insurance data (Canopy Connect); store artifacts with audit trails. 4) Review and gap closure: Rosella drafts gaps and outreach; Trello tasks drive closure. 5) Decisioning: policy engine evaluates POs; applies holds/releases. 6) Continuous monitoring: calendar‑driven renewals; Slack/Teams alerts; ROI/KPI tracking in dashboards and the ROI calculator.
Evidence, auditability, and change control
-
Immutable audit trail of every file, decision, and communication (who/what/when/why).
-
Versioned evidence packages for each renewal window.
-
Exception workflow: risk‑based approvals with expiry and auto‑reminders.
-
Document automation for CAPA, supplier quality agreements, and attestations (Google Docs integration).
Implementation notes for spreadsheet‑heavy teams
Parakeet augments—rather than replaces—Excel‑based processes. Import your existing COI trackers and supplier cert lists, then layer validation, workflows, and audit trails to reduce error rates and manual effort. See the perspective on evolving beyond spreadsheets without abandoning them in the Parakeet blog on spreadsheet synergy (article).
FAQs
-
How is this page related to Parakeet’s product modules? It unifies the data model and decision logic exposed in COI verification and Certification Automation so sourcing, quality, and EHS teams work from one source of truth.
-
Can alerts flow into collaboration tools we already use? Yes—native integrations with Slack, Microsoft Teams, and Trello support real‑time triage and two‑way sync.
-
How are PO holds applied technically? POs sync from ERP (e.g., NetSuite); Parakeet evaluates policy rules and sets a hold flag or blocks release according to ERP capabilities, logging the action.
-
What about multi‑site or multi‑standard suppliers? Use sites_covered[] and commodity_categories[] to scope requirements so only relevant POs are affected.
-
How are medical‑device suppliers handled? Track ISO 13485 specifically and tie it to device categories; holds are enforced when certificates lapse or are suspended.
-
Can we prove ROI? Yes—track lead‑time to verify COIs (Parakeet reports up to 42% time savings on verification) and cycle time to close audit findings; quantify savings in the ROI tool.
-
How are reminders scheduled? Create date‑driven events via Google Calendar and route escalations to Slack/Teams; Rosella drafts vendor emails and summaries.
-
Where do artifacts live? Certificates, audit reports, and memos live in Parakeet’s evidence store and can be auto‑generated/synced with Google Docs.
Cross‑links for navigation
-
COI Automation → this page: integrated decisioning and schemas.
-
Certification Automation → this page: ISO schemas, audit cycle, renewal logic.
-
Related industry pages: Manufacturing, Packaging, Pharma.