Operations wants to buy a new shiny SaaS solution. They go ahead and order the discovery pack, route the report and its findings and recommendations to the decision maker the same day, and file the evidence — not your supplier, not your risk to accept, but always on hand should an auditor ask.
The report format is built to leave the risk decision with a named owner — never with Hume, and not silently defaulted to whoever ordered it.
Approve Hume as the supplier-evidence standard once — set the bar, and what comes back is filed and audit-ready without you reviewing every supplier by hand.
Every report carries uniquely referenced findings and recommended actions, but no severity grade and no affirmative "this is fine" verdict. Operations routes the decision to the risk owner and files the evidence — on hand to present to an auditor, or forwarded to you, under your own organisation's policy.
Mis-classifying a supplier as low-risk is one of the most common mistakes in supplier evaluation. Hume determines the recommended tier from evidence, not simply from what Operations assumes going in — it surfaces the actual signals so you make the classification call, not whoever just wanted the deal to move.
Supplier-agreement checks reference ISO 27001 Annex A 5.20, and Hume Watch's re-run cadence covers Annex A 5.22. Where the evidence warrants it, recommendations point to a deeper tier — and every finding exports to PDF or CSV, straight into whatever risk register or actions tracker you already use.
Same form either way — this just skips straight to what Compliance needs.
Claim early access See the full site — tiers, the report tour, FAQ