Skip to main content

Entities (Vendors)

Overview

Entities represent external organizations you depend on, such as vendors, subprocessors, and service providers. This record helps you keep third-party relationships organized with the operational and compliance context needed for reviews and audits.

In Openlane, entities are typically connected to vendor contacts, supporting documents, and assessment activity. You can also relate an entity to the assets it supports so vendor risk and technical scope stay aligned.

Compliance Significance

  • SOC 2: CC3, CC5, CC7, CC9
  • ISO 27001: supplier and external party governance (A.5 and A.15)
  • GDPR and HIPAA: third-party accountability expectations

Practical Examples

  • A procurement lead tracks annual renewals and scheduled vendor reviews in one entity record instead of separate spreadsheets.
  • A GRC team links vendor assessments and SOC reports to each entity to quickly answer due diligence requests.

Examples

OperationAPI
CreatecreateBulkCSVEntity
UpdateupdateBulkCSVEntity
# Create
Name,DisplayName,Status,RiskRating,ReviewFrequency,NextReviewAt,ApprovedForUse,HasSoc2
stripe,Stripe,active,HIGH,YEARLY,2026-10-01T00:00:00Z,true,true
aws,Amazon Web Services,active,MEDIUM,YEARLY,2026-09-15T00:00:00Z,true,true
# Update
ID,RiskRating,NextReviewAt,ContractRenewalAt,ApprovedForUse
ENT01J9ABCD111111111111111,MEDIUM,2026-11-01T00:00:00Z,2027-01-31T00:00:00Z,true
ENT01J9ABCD222222222222222,HIGH,2026-08-01T00:00:00Z,2026-12-31T00:00:00Z,true