Independent risk intelligence on every EdTech vendor
Risk intelligence you inherit, not research
Schools are expected to know every vendor that processes children's data: what it holds, where it transfers it, how it is secured and what its AI does. Vendor contracts are long. Privacy policies change without notice. AI features appear in familiar tools between reviews. Vendor replaces manual, inconsistent review with independently maintained intelligence your school inherits from day one.
Assessed at product level
Different products from the same supplier carry different data flows, AI features and safeguarding implications. 9ine assesses each product separately, so you get intelligence for the tool actually in use rather than the parent brand.
Six risk dimensions
Every vendor is rated across privacy, AI, safeguarding, cyber security, system security and regulatory compliance. Traffic-light ratings mean any stakeholder can read the risk without specialist expertise.
Maintained continuously
Assessments are updated as vendors change their policies, data practices and AI capabilities. Your view stays current without anyone in school tracking vendor announcements.
Everything you need to govern the vendor environment
Over 250 vendors, assessed independently
The assessment stages
A consistent structure, every vendor
Traffic-light risk ratings
Risk anyone can read at a glance
AI risk identifier
See which tools use AI, and how
Processing Operation Assessments
The vendor data your DPIAs need
Vendor risk dashboard
Live view of the whole estate
Vendor log
Your estate, not just the library
Connected approval workflow
Requests trigger assessment automatically
Every vendor assessed the same way
Each assessment follows a set structure: processing operation description, processing compliance, safeguarding, security and systems, and an assessment summary. Because the structure never changes, findings are comparable across suppliers, and nothing depends on who happened to carry out the review.
Risk that reads clearly to everyone
Every assessed vendor carries colour-coded ratings across all six risk dimensions. Red, amber and green tell the story immediately, and each rating opens into the detailed assessment behind it. Headteachers, DSLs and DPOs read the same picture without needing to interpret technical findings.
Know which tools use AI before you approve them
The AI risk identifier flags which vendors incorporate AI features, identifies the type and categorises the risk. For UK schools, assessments are benchmarked against the DfE Generative AI Product Safety Standards. That gives safeguarding leads and DPOs a government-aligned basis for decisions about AI in the classroom.
DPIA-ready vendor data, captured once
Processing Operation Assessments record data transfer locations, personal data categories, sub-processors, international transfers and security measures for each vendor. That data feeds straight into DPIA workflows in Privacy, so your DPO completes assessments from structured records rather than chasing suppliers for documentation.
Your whole vendor estate in one view
The dashboard shows risk across every vendor by risk level, AI use, compliance status and assessment currency. Filter to find the tools that need attention first. Leadership gets a live picture of exposure without anyone compiling a report.
One log for every tool you actually use
Import assessments straight from the library for every EdTech provider your school uses, then build your log around them with your own notes, status and approval history. Existing vendors can be reviewed periodically rather than only when something goes wrong, so your estate stays governed rather than drifting between audits.
Every tool request follows the same path
When a teacher requests a tool through Application, the vendor assessment workflow triggers automatically and routes to the right assessor. Findings populate the application card so the approver decides with the risk picture in front of them. Every decision leaves an audit trail.
Stop relying on vendors to assess themselves
9ine reviews the contracts, privacy policies, AI documentation and security certifications independently, and updates assessments as vendors change. Schools get an honest picture rather than a supplier's own compliance claims.
Speak with usBuilt for everyone who carries the risk
Vendor oversight is rarely one person's job. Leadership, IT, privacy, safeguarding and teaching staff each need a different view of the same estate.
Senior leadership and business management
A live dashboard showing risk exposure across the whole supplier estate by risk level, AI use and compliance status. Accountability conversations with governors and inspectors start from evidence rather than estimates.
IT team
Structured security assessments, Processing Operation Assessments and the AI risk identifier in one place. No more manual research for every new tool, and no more tracking spreadsheet to maintain.
DPO and privacy lead
A pre-assessed library and structured POA data supply the vendor intelligence DPIAs require. Your DPO stops chasing suppliers for documentation that arrives inconsistently and late.
Safeguarding lead and DSL
Clear visibility of safeguarding risk for every digital tool, with AI-enabled tools flagged and categorised. You can see whether a tool has been assessed for use with pupils before it reaches a classroom.
Teachers
A structured way to request the tools you want to use. The assessment happens automatically behind the scenes, so you get a clear answer without needing to understand the governance process.
What changes when vendor review is structured
Most schools vet vendors through spreadsheets, email threads and one-off reviews. Here is what that approach can and cannot do.
Assessed against the standards schools answer to
Vendor assessments are framed by the regulatory and safeguarding landscape schools actually operate in, not a generic enterprise compliance checklist.
UK GDPR and Data Protection Act 2018
Structured third-party due diligence, Processing Operation Assessments and the audit trail needed for Article 30 Records of Processing and controller accountability.
DfE Generative AI Product Safety Standards
AI risk assessments in the vendor library are benchmarked against DfE standards, giving schools a government-aligned basis for governing AI tools and evidencing that decision.
KCSIE safeguarding obligations
Safeguarding assessments support DSLs in evidencing due diligence on the tools used with pupils, in line with Keeping Children Safe in Education.
"The team at 9ine have been instrumental in supporting us in our journey toward stronger data privacy controls and a better cybersecurity posture. Their materials are thorough, precise, and easy to use, all at the same time. What really makes a difference is that 9ine understands the nuance of international schools in a way that other out-of-the-box consultancies do not."
"We began to work with 9ine for our Digital Privacy Management. We quickly expanded to their Cybersecurity services due to their professionalism, especially when such a wide range of aspects can benefit from each other. The different teams are always aware of what's happening, and we benefit significantly, whether at board level or on a very granular scale."
"They felt like an extension of our IT support team for the time they were with us and were never judgemental on the approach we take with our systems and security. I'd have no concerns about recommending them again in the future."
Intelligence that reaches every decision
Vendor is the risk intelligence layer of the 9ine platform. Its findings surface wherever a decision gets made, rather than sitting in an isolated report.
Application
Vendor assessment data surfaces directly on application cards, so teachers and approvers see AI risk, safeguarding flags and privacy status at the point of decision.
Privacy
POA data feeds DPIA workflows and keeps Records of Processing accurate, so compliance documentation stays current as vendors change.
Contract
Vendor risk profiles sit alongside cost, renewal dates and notice periods, giving a complete picture of what each supplier costs and what risk it carries.
Common questions about Vendor
How many vendors are in the pre-assessed library, and what if ours isn't there?
+Why assess products rather than companies?
+We already have a process for reviewing vendors. Why do we need this?
+Our DPO handles vendor reviews. Does this replace them?
+We don't use many EdTech tools. Is this still relevant?
+We're waiting to see how AI guidance develops. Should we hold off?
+More on governing your vendor estate
From Prompt to Production: Why AI-Generated Code Still Needs Developers
The AI, Technology and Safeguarding Jigsaw Is Complete: The Academy Trust Handbook 2026 Requires Digital Risk Leadership
DfE EdTech procurement guidance: the Department is joining the dots for schools
KCSIE 2026 is confirmed: AI is now part of the safeguarding system
Vet every vendor. Evidence every decision.
Tell us a little about your school and we'll show you the assessments that already exist for the tools you use. Most schools find gaps they weren't aware of.

