Enterprises
Enterprises
Independent supplier assurance.
Supplier questionnaires can be useful, but they are still self-reported.
ACE provides a more credible model for enterprises seeking stronger assurance that suppliers have controls and governance in place.
What ACE Gives Enterprises
Common Questions
We already require ISO/IEC 27001 from some suppliers.
ISO/IEC 27001 remains a rigorous and respected standard. ACE is intended to sit alongside existing assurance models and provide a more practical pathway for suppliers that are unlikely to achieve full ISO/IEC 27001 certification in the near term.
We already use supplier questionnaires.
Questionnaires still reflect what a supplier says about itself. ACE is intended to provide a more credible, independently reviewed basis for assurance.
We already have our own third-party risk framework.
ACE is designed to complement existing supplier risk processes, not replace them.