EN
Deutsch
English
Glossary
The essential terms around RFPs, tenders and security questionnaires.
All
Tenders
Certificates
Regulatory Compliance
Evidence & Audits
BCM (Business Continuity Management)
The management that keeps operations running during disruptions and crises.
Learn More
Bidding Process
The sequence in which providers apply for a contract.
Learn More
BSI IT-Grundschutz
BSI methodology for a systematic level of information security.
Learn More
C5
BSI auditing standard for the security of cloud services.
Learn More
CAIQ
Standardised questionnaire by the Cloud Security Alliance for cloud providers.
Learn More
Cloud Controls Matrix
Control framework by the Cloud Security Alliance for cloud security.
Learn More
DORA
EU regulation for digital operational resilience in the financial sector.
Learn More
DSGVO / AVV
**Data protection law and the contract governing data processing agreements.**
Learn More
Due Diligence
Careful examination of a provider before a partnership begins.
Learn More
EBA Guidelines
Supervisory IT requirements for insurers and banks.
Learn More
IDW PS 951
German auditing standard for the internal control system of service providers.
Learn More
IKT-Dienstleistung
Term defined by DORA for IT and communication services provided to financial entities.
Learn More
ISAE 3402
International auditing standard for controls over outsourced processes.
Learn More
ISMS
The systematic management of information security in a company.
Learn More
ISO 27001
The leading international standard for information security.
Learn More
IT-Audit
The systematic audit of IT systems, processes, and controls.
Learn More
MaGo
Supervisory requirements for the business organisation of insurance companies.
Learn More
MaRisk
Supervisory minimum requirements for the risk management of banks.
Learn More
NIS2
EU directive for stronger cybersecurity in essential sectors.
Learn More
Notfallübungen
Planned tests that verify the effectiveness of emergency and recovery plans.
Learn More
Outsourcing (Auslagerung)
Transferring tasks to external providers, often heavily regulated.
Learn More
Penetrationstest
A controlled attack that exposes vulnerabilities in systems.
Learn More
Proposal Management
Managing all offers from request to close.
Learn More
References & Case Studies
Proof of successful projects that builds trust with new customers.
Learn More
RFI (Request for Information)
The preliminary inquiry used by a client to explore the market.
Learn More
RFP (Request for Proposal)
The formal request to submit a specific proposal.
Learn More
RFQ (Request for Quotation)
The pure price inquiry for a clearly defined service.
Learn More
RTO & RPO
Two key metrics that define how quickly and with how much data loss a system must be restored.
Learn More
Security Questionnaire
A standardised set of questions a customer uses to assess a provider's information security.
Learn More
SIG (Standardized Information Gathering)
Comprehensive standard questionnaire for evaluating the security of providers.
Learn More
SOC 2
A US audit standard for the secure handling of customer data.
Learn More
Supplier Evaluation
The systematic assessment of providers against fixed criteria.
Learn More
TPRM (Third Party Risk Management)
The process companies use to manage the risks posed by their providers.
Learn More
Vendor Assessment
The structured review of a provider by the customer.
Learn More
Verfügbarkeit
The proportion of time a system is available, typically guaranteed as a percentage.
Learn More
Bidding Process
The sequence in which providers apply for a contract.
Mehr erfahren
Due Diligence
Careful examination of a provider before a partnership begins.
Mehr erfahren
Proposal Management
Managing all offers from request to close.
Mehr erfahren
References & Case Studies
Proof of successful projects that builds trust with new customers.
Mehr erfahren
RFI (Request for Information)
The preliminary inquiry used by a client to explore the market.
Mehr erfahren
RFP (Request for Proposal)
The formal request to submit a specific proposal.
Mehr erfahren
RFQ (Request for Quotation)
The pure price inquiry for a clearly defined service.
Mehr erfahren
Security Questionnaire
A standardised set of questions a customer uses to assess a provider's information security.
Mehr erfahren
Supplier Evaluation
The systematic assessment of providers against fixed criteria.
Mehr erfahren
TPRM (Third Party Risk Management)
The process companies use to manage the risks posed by their providers.
Mehr erfahren
Vendor Assessment
The structured review of a provider by the customer.
Mehr erfahren
C5
BSI auditing standard for the security of cloud services.
Mehr erfahren
Cloud Controls Matrix
Control framework by the Cloud Security Alliance for cloud security.
Mehr erfahren
ISO 27001
The leading international standard for information security.
Mehr erfahren
SIG (Standardized Information Gathering)
Comprehensive standard questionnaire for evaluating the security of providers.
Mehr erfahren
SOC 2
A US audit standard for the secure handling of customer data.
Mehr erfahren
Bidding Process
The sequence in which providers apply for a contract.
Mehr erfahren
Due Diligence
Careful examination of a provider before a partnership begins.
Mehr erfahren
Proposal Management
Managing all offers from request to close.
Mehr erfahren
References & Case Studies
Proof of successful projects that builds trust with new customers.
Mehr erfahren
RFI (Request for Information)
The preliminary inquiry used by a client to explore the market.
Mehr erfahren
RFP (Request for Proposal)
The formal request to submit a specific proposal.
Mehr erfahren
RFQ (Request for Quotation)
The pure price inquiry for a clearly defined service.
Mehr erfahren
Security Questionnaire
A standardised set of questions a customer uses to assess a provider's information security.
Mehr erfahren
Supplier Evaluation
The systematic assessment of providers against fixed criteria.
Mehr erfahren
TPRM (Third Party Risk Management)
The process companies use to manage the risks posed by their providers.
Mehr erfahren
Vendor Assessment
The structured review of a provider by the customer.
Mehr erfahren
Bidding Process
The sequence in which providers apply for a contract.
Mehr erfahren
Due Diligence
Careful examination of a provider before a partnership begins.
Mehr erfahren
Proposal Management
Managing all offers from request to close.
Mehr erfahren
References & Case Studies
Proof of successful projects that builds trust with new customers.
Mehr erfahren
RFI (Request for Information)
The preliminary inquiry used by a client to explore the market.
Mehr erfahren
RFP (Request for Proposal)
The formal request to submit a specific proposal.
Mehr erfahren
RFQ (Request for Quotation)
The pure price inquiry for a clearly defined service.
Mehr erfahren
Security Questionnaire
A standardised set of questions a customer uses to assess a provider's information security.
Mehr erfahren
Supplier Evaluation
The systematic assessment of providers against fixed criteria.
Mehr erfahren
TPRM (Third Party Risk Management)
The process companies use to manage the risks posed by their providers.
Mehr erfahren
Vendor Assessment
The structured review of a provider by the customer.
Mehr erfahren