Topics inside this course
Awareness and induction depth — not an accredited occupational qualification.
- Approved supplier versus a new inbox
- Don’t email a customer dump to personal accounts
- Shadow SaaS is still a vendor
- Access: least privilege and offboarding
- Supplier incidents are our incidents too
Built for the people who take the training
Anyone who sends files to suppliers, onboards a tool, or brings in a consultant — hiring managers included.
What learners leave able to do
- Use approved suppliers and official channels before sharing data
- Treat shadow SaaS as a vendor decision, not a personal productivity hack
- Apply least privilege and offboarding when a project ends
- Report a supplier incident the same day
Modules you can expect
Structure may tighten when you localise from your own source pack in Kre8AI — this is the shape of the library title.
- 1They are processing our data
Operators and processors in plain language.
- 2Approved first
Procurement exists.
- 3What you may send
Classification and minimisation.
- 4When the project ends
Accounts, shared drives, WhatsApp groups.
- 5If they are breached
Report like it was us.
- 6Knowledge check
Scored assessment.
Scored assessment for staff and hiring managers. Not a third-party risk questionnaire course for the vendor-risk function.
Written for the workplace, not for the statute book alone
Vendor security programmes often live in procurement while staff still send a full customer spreadsheet to a new designer. This course is the staff layer: approved supplier, official channel, minimum data, offboard access, report their incident as ours.
Shadow SaaS is named because that is how personal information leaves the organisation without a contract. Managers who “just need a tool this week” are in scope. POPIA operator language is translated as “we remain responsible”.
It will not teach anyone to complete a 200-question vendor pack. That stays with the risk function. Pair with information classification so people know what they are sending.
Generate from NCSC supply-chain guidance, POPIA operator extracts, and your vendor policy in Kre8AI. Publish as SCORM or HTML. Keep live vendor scores out of the library demo.
Re-export when the approved-tool list or data-sharing path changes. Assign to anyone who can attach a file to an external email.
Play the library demo, or generate vendor-security awareness from your data-sharing policy in Kre8AI.
What you would upload in Kre8AI
Vendor risk / data sharing policy
- Your vendor-risk / data-sharing / procurement security policy
- NCSC supply-chain security staff guidance
- POPIA operator / GDPR processor extracts at staff level
Formats, coach and provenance
- Standalone HTML to play in the browser; SCORM 2004 for your LMS.
- Optional AI course coach on Growth and Scale — grounded in approved material; off on quizzes and final assessment by default. Course plays offline; coach needs a network.
- Built in Kre8AI and reviewed before we published it. Not a substitute for your organisation's own policy — review before you make it mandatory.
Get the SCORM package while you are here.
Same course, SCORM 2004. Load it to settle the tracking question — and keep it as a course your people can take after you review it.
Request the package
SCORM 2004 zip. We ask for an email so we know which LMS you are testing — and so we can send the download.

