Skip to main content

Framework Changes - Suppliers - August 2025

Ish Ladak avatar
Written by Ish Ladak
Updated this week

On 28th August 2025, we will be making some changes to the standardised control framework within Risk Ledger.

We do this periodically so that the framework stays relevant, useful and practical for all users of the Risk Ledger platform.

All changes will be handled automatically within the platform and marked clearly with a full audit history kept within your activity feed.

This page gives you a summary of the changes that are coming.


Whatโ€™s changing?

  • Updating a few small grammatical changes from current questions and descriptions.

  • Updating descriptions of two certification controls to request specific documentation as evidence:

    • Statement of Applicability for ISO 270001 (only if appropriate - often this is only provided to the auditor).

    • For PCI compliance: Attestation of Compliance (AOC), Report on Compliance (ROC), and the Responsibility Matrix.

  • Updating the MFA control question (D6) to ensure it includes customer-facing applications, especially now that suppliers can list multiple products on their Risk Ledger profile.

  • Updating D23-27: moving away from specifically targetting laptops to instead covering all endpoints (laptops, mobile phones, tablets, etc.). Breaking this down to organisation-issued devices and BYOD.

  • Simplifying scoping questions to help suppliers when first completing their profile.

  • Adding a new control question (K1) about AI Policy, in response to developments in AI risk governance standards.


As a supplier, what do you need to do?

If you have already submitted your assessment and your profile is up to date, you do not have to make any changes until your next 6 monthly re-assessment is due or one of your clients asks you to update or confirm a modified control question or answer the new control question.

You will need to update or confirm the modified control questions and answer the new control question before you can submit your next re-assessment.

If you have not yet submitted your assessment, you will need to update or confirm the modified control questions and answer the new control question before you submit.

Did this answer your question?