The catalog

RONA SupplierWatch

Your supplier audit runs once a year. Your suppliers do not.

Your supplier audit runs once a year. Your suppliers do not.

RONA SupplierWatch sits alongside the procurement flow you already run and re-checks it on a cadence, verifying each vendor and shipment against the frameworks you care about and auditing the whole supply chain for violations and risk. So you find a breached third party from your own watch, not from a regulator, an onsite auditor, or a headline.

Start a supplier watch See a sample cycle report

THE PROBLEM

You audit your suppliers the way the whole market does, onsite and once, a static snapshot that is stale the day the auditor leaves. But a supplier can lapse a certification, get named on a sanctions list, or route through a banned facility on any day of the year, and 98% of firms are already working with a third party that was breached since the last look. The $5B spent on human supplier audits buys a point in time, not the twelve months in between, and that is exactly the window a due-diligence regulator (EU CSDDD, forced-labor import bans, CBAM reporting) now expects you to be watching. As of August 2, 2026, the EU AI Act turns prove-what-your-AI-did into a board-level obligation for high-risk decisions, so a once-a-year binder stops being enough.

HOW IT WORKS

SupplierWatch does not replace your procurement system, and it does not ask you to change your workflow, it runs beside it on a schedule. Each cycle it does two things, it checks the named vendors and shipments against your compliance frameworks and returns a verdict, and it runs a supply-chain audit across your vendors and the audit window to surface violations and risk areas. It is built by composing two capabilities Rona already runs (a compliance check and a supply-chain audit) and putting them on a cadence, so nothing here is a science project. And it fails closed, a check that cannot be resolved reads as non-compliant or undetermined, never a silent green.

WHAT YOU GET (the cycle report)

Every cycle, on your schedule, one report you can hand to a compliance officer: - a compliance verdict for each vendor and shipment you named, against the frameworks you chose, - a supply-chain audit surfacing violations and risk areas across vendors, shipments, and processes, - what changed since last cycle, so drift shows up in-cycle instead of at the next annual review, - fail-closed handling, an unresolved check is flagged, never quietly passed.

A watch that tells you the day a supplier drifts, not the quarter you happen to audit.

WHO IT'S FOR

Supply-chain, procurement, and trade-compliance teams at operators with multi-vendor supply chains under trade, sanctions, or due-diligence regulation, first, then manufacturers, importers, and retailers whose third-party suppliers carry regulatory or reputational risk. If a lapsed or breached supplier can end up in front of a regulator, a customer, or a headline, this is for you. If a lapsed supplier costs you nothing, it is not.

PRICING (the ladder)

We price the ladder, not a single number, and every number below is a hypothesis we validate with you, not a commitment. - Watch, a flat monthly recurring watch on a defined set of suppliers. You see the in-cycle violations and risk report before you climb. - Value-metered, per verified supplier per cycle, once the watch proves it catches drift the annual audit misses. - Platform, license the on-cadence verification into your supply-chain and compliance stack.

IP is licensed, never assigned. The verification stays ours, the proof is yours. Any step that takes your money is gated and confirmed before it runs, nothing charges silently.

THE PROOF (dogfood)

We run this discipline on ourselves before we sell it. AYA is itself a multi-vendor operation (LLM providers, cloud, domains, secrets vaults), and the same on-cadence compliance-watch shape can run against AYA's own supplier set, so we eat the watch we sell. And the product's own build left a receipt, the deliverable pattern was scored and both of the capabilities it composes were verified on disk before this page was written. That is the same kind of evidence trail this product produces for you.

HONEST NOTE

We would rather under-promise. SupplierWatch has been built and structurally verified, the pattern composes on a schedule, the two Rona capabilities it stands on resolve, and the execution and scheduling substrate already exists in the system. What it has NOT done yet is run against a live supplier dataset on a booted mesh, and we have not independently confirmed that the underlying Rona acolyte returns fully computed compliance and audit results rather than a partial shell for every framework. That is the next test, and it needs your data and read access, not more code. We will show you a real cycle report on your own suppliers before we ask you to rely on it.

*This page is a specification. The capability it describes is not built yet, and nothing here is a claim that it runs today.*