About FiorLab
FiorLab Limited is an EU-native supplier risk intelligence platform serving regulated companies across the European Union, the United Kingdom, and Ireland. FiorLab helps procurement, compliance, and third-party risk teams assess, verify, and monitor supplier risk with audit-ready evidence — mapped directly to the EU regulatory frameworks their supervisors ask about.
The platform scores suppliers across six dimensions (financial health, compliance, sustainability, delivery performance, quality management, innovation capability). Every score is built on evidence verified live against five public government registries — Companies House UK, German Handelsregister, CRO Ireland, VIES EU-wide, and GLEIF — plus OCR-verified documents with graduated staleness tracking and the IAF CertSearch accredited-certification registry.
FiorLab is architected around EU regulatory reality: DORA Article 28 (uniform across all 27 member states), EBA outsourcing guidelines with national variants (CBI Ireland, BaFin/MaRisk Germany, DNB Netherlands, ACPR France, CSSF Luxembourg), the EU AI Act GPAI regime, GxP for pharmaceutical supply, MiFID II, GDPR, and CSRD.
Founder — Gabor Banyai
Gabor Banyai is the founder and CEO of FiorLab Limited. He built FiorLab after fifteen years in procurement and third-party risk across regulated industries in Ireland and mainland Europe, with more than €800 million in managed spend across financial services and pharmaceutical supply chains.
Gabor is available for expert commentary on the following topics, in English or Hungarian, remote or in person from Dublin.
Boilerplate biographies
Gabor Banyai is the founder and CEO of FiorLab Limited, an EU-native supplier risk intelligence platform based in Dublin.
Gabor Banyai is the founder and CEO of FiorLab Limited, the EU-native supplier risk intelligence platform. Before founding FiorLab, Gabor spent fifteen years in procurement and third-party risk across financial services and pharmaceutical supply chains, managing more than €800 million in spend. FiorLab is Dublin-headquartered, registered in Ireland (CRO 813471), and built specifically for procurement and compliance teams under DORA, EU AI Act, and EBA outsourcing supervision.
Gabor Banyai is the founder and CEO of FiorLab Limited, an EU-native supplier risk intelligence platform for regulated European industries. FiorLab scores suppliers across six dimensions with data verified live against five government registries and delivers audit-ready evidence for DORA Article 28, EU AI Act GPAI obligations, EBA outsourcing (including CBI Ireland, BaFin/MaRisk, DNB, ACPR, and CSSF national variants), and GxP pharmaceutical supply. Before founding FiorLab, Gabor spent fifteen years in procurement and third-party risk across regulated industries in Ireland and mainland Europe, with over €800 million in managed spend. He built FiorLab after seeing procurement teams forced to choose between spreadsheets that cannot survive a supervisory review and enterprise GRC platforms that cost €50,000-€200,000 per year and take months to deploy. FiorLab is registered in Ireland (CRO 813471), headquartered in Dublin, hosts customer data exclusively in the European Union, and is available for pilot deployment inside one working day. Gabor is available for expert commentary on DORA enforcement, EU AI Act GPAI compliance for regulated buyers, EBA non-ICT TPRM, national outsourcing regimes, and third-party risk economics.
Expert commentary areas
The founder is available for written comment, quotes, panel, or interview on the topics below. Where relevant, primary regulatory citations are provided on request.
DORA Article 28 enforcement
Live obligations for financial-services buyers, register of information, evidence expectations of CBI / BaFin / DNB / ACPR / CSSF.
EU AI Act — GPAI enforcement (2 Aug 2026)
Article 50 transparency, Article 101 penalty ceilings (€15M / 3% turnover), the intersection with DORA for financial-services buyers of AI-embedded ICT suppliers.
EBA non-ICT TPRM (final imminent)
Extension of outsourcing supervision to non-ICT third-party arrangements, what it means for procurement teams outside financial services.
CBI Cross-Industry Outsourcing Guidance
2026 supervisory priorities, why the Central Bank of Ireland classifies third-party risk as a "very high threat", CBI Register of Outsourcing Arrangements expectations.
BaFin MaRisk 9th Amendment
Central outsourcing management function, sub-outsourcing reporting, AML gate on pre-outsourcing risk assessment, contingency planning when no viable exit exists, DORA delineation.
Procurement economics under regulation
The €50K-€200K enterprise GRC gap that leaves EU mid-market procurement stuck on spreadsheets; the cost of onboarding a supplier; the price of a failed supervisory review.
ESRB frontier-AI cyber warning
The 25 June and 7 July 2026 European Systemic Risk Board notices, Joint Supervisory Team action plans due 31 October 2026, and what this means for AI-embedded ICT suppliers.
Data sovereignty in TPRM
Why EU-headquartered TPRM vendors sit outside FISA 702 and the US CLOUD Act — a structural distinction that regulated buyers increasingly ask about.
Quote-ready statements
Journalists on deadline are welcome to use the statements below verbatim with attribution to Gabor Banyai, founder and CEO, FiorLab Limited. For custom quotes on a specific angle, contact hello@fiorlab.com — response within one working day.
"DORA Article 28 is not a checkbox. It is a live register that CBI, BaFin, DNB, ACPR, and CSSF supervisors are already asking to see. The question stopped being 'do we need this?' and started being 'can we produce it inside forty-eight hours of a request?'"
"The EU mid-market has been asked to comply with the same third-party risk regime as a Tier 1 bank, using a fraction of the budget. The current market has been generic GRC platforms at €50,000-€200,000 per year at one end, and spreadsheets at the other. FiorLab was built for the gap in the middle."
"Data sovereignty is not a marketing badge. It is a legal fact. An EU-registered TPRM provider is outside the territorial scope of FISA 702 and the US CLOUD Act. Regulated buyers under DORA and CBI's 2026 supervisory priorities are increasingly asking their vendors to answer that question in writing."
"The EU AI Act GPAI regime turns live on 2 August 2026. For financial-services buyers under DORA Article 28, the question is not whether the AI Act applies to them directly — it is whether their AI-embedded ICT suppliers can produce Article 50 transparency documentation, and whether the buyer's own register of information reflects that dependency."
Assets and downloads
All assets below may be used editorially without permission, provided attribution is preserved. For higher-resolution files, custom crops, or specific composite images, contact hello@fiorlab.com.
Founder headshot
High-resolution headshot of Gabor Banyai (2000×2000, colour + black-and-white on request).
Request via emailPlatform screenshot pack
Anonymised platform screenshots (supplier scorecard, register of information, audit trail, comparison dashboard).
Request via emailBuyer's Guide (PDF)
Vendor-neutral 2026 buyer's guide to EU supplier risk platforms — 3,000 words, no product pitch.
Read onlineDORA Article 28 checklist
18-point evidence checklist with 48-hour readiness drill for supervisory reviews.
Read onlineOpen-source register schemas
JSON Schema + YAML schema for the ICT third-party register required under DORA Article 28(3). MIT licensed.
GitHub repository