Vendor risk management, from register to evidence.
Vendor risk management — VRM — is how an organization identifies and controls the risk created by the parties it buys from: what each vendor can reach, how much the business depends on it, whether its security holds up, and what happens when it fails. This page covers the process end to end, what a vendor risk management framework contains, how to build a program that scales past a spreadsheet, the metrics worth reporting, and where VRM sits against third-party risk management.
Last reviewed by Darren Craig
What is vendor risk management?
A subset of third-party risk, and a useful one — as long as the edges are known.
Vendor risk management is the practice of understanding and controlling what you take on when you buy something. That covers more than a security questionnaire: operational dependence and concentration, financial stability, regulatory and sanctions exposure, data protection, and the parties your vendors rely on in turn.
The distinction from third-party risk management is one of scope rather than method. A vendor is someone you buy from. A third party is anyone outside your organization whose failure lands on you, which includes vendors and also includes parties you have no purchase order with: joint venture partners, agents and introducers, franchisees, and the recipients of data you share without paying for the privilege. VRM is the larger half of TPRM in volume and the smaller half in scope.
That matters at exactly one moment: when you scope the program. A register built by exporting the vendor list from finance is complete for spend and incomplete for risk, and the parties it omits are by definition the ones nobody has assessed.
The vendor risk management process process
Six stages. Most programs are strong at stage three and weak at stages one, five and six — which is the wrong distribution, because the first stage bounds everything after it.
- 1. InventoryEstablish who your vendors actually are. Finance knows who you pay; it does not know who has an API key. Expect the real number to exceed the list you started with, and treat discovery as continuous rather than a one-off exercise.
- 2. TieringSegment by inherent risk — what the vendor accesses and how badly its failure hurts — not by spend. The cheapest vendor in the estate can hold the most sensitive data, and frequently does.
- 3. Due diligenceMatch assessment depth to tier. Collect what already exists — SOC 2, ISO 27001, pen test summaries — before issuing a questionnaire, and use the questionnaire for what the documents did not answer.
- 4. ContractingSecurity, notification, audit and exit rights are far easier to secure before signature than after. This is the stage where the leverage exists and the stage most often skipped by risk teams who see it as procurement’s job.
- 5. MonitoringA point-in-time assessment describes a vendor on one day. Between assessments, outside-in monitoring catches material change without needing the vendor’s cooperation — which matters, because a vendor in trouble is the least likely to volunteer it.
- 6. OffboardingAccess revoked, data destroyed and evidenced, contractual obligations enforced. The stage with the least attention and the longest tail: dormant credentials and undeleted data outlive the commercial relationship by years.
What a vendor risk management framework contains
Six documented components. Everything else is implementation detail.
A vendor risk management framework is the written basis on which the program runs — the thing an auditor asks for first and the thing most programs reconstruct after the fact. It needs six components, and it does not need to be long.
- Scope and definitions. What counts as a vendor, and what falls outside. Ambiguity here is what produces registers that disagree between teams.
- Roles and accountability. Who owns the relationship, who owns the risk decision, and who signs off an exception. These are three different people in most organizations and one person in the framework of organizations that have not thought about it.
- The tiering model. The criteria that put a vendor in a tier, and the assessment depth each tier receives.
- Assessment standards. What evidence is acceptable, what expires, and what must be independently verified rather than accepted on assertion.
- Remediation and SLAs. How findings are rated, who fixes them, by when, and what happens when the date passes.
- Reporting. What goes to the board, at what interval, and which measures it contains.
Frameworks such as NIST SP 800-161, ISO 27036 and the interagency third-party risk guidance issued by the Federal Reserve, OCC and FDIC in 2023 are useful sources for the content. None of them substitutes for writing down how your organization actually operates.
Building a vendor risk management program that scales
The constraint is rarely knowledge. It is arithmetic.
A vendor risk management program fails at scale for a reason that has nothing to do with expertise. A team of three running full questionnaires across four hundred vendors on an annual cycle needs to complete roughly two assessments every working day, forever, while also handling onboarding, remediation and reporting. It does not happen, and what gives way is the monitoring between assessments — the part that would actually have caught something.
Three things make the arithmetic work:
- Tier honestly. If ninety percent of the estate is “critical”, the tiering has failed and the effort is spread evenly across vendors that do not warrant it.
- Stop re-collecting what you already hold. Most of a standard questionnaire is answerable from documents the vendor has already sent. Asking again is work you are choosing to do.
- Make monitoring the default state. Continuous outside-in observation is what turns the annual cycle from the whole program into one input to it. See AI third-party risk management for what can and cannot be automated safely.
Vendor risk management metrics worth reporting
Most VRM reporting measures activity. A board cannot act on activity. These measure coverage and exposure instead.
| Measure | What it answers | Why activity metrics fail here |
|---|---|---|
| Register completeness | What proportion of live vendors have an owner and a tier | "Assessments completed" looks healthy while a third of the estate is unregistered |
| Tier 1 assessment currency | How many critical vendors have current, in-date evidence | A count of assessments hides how many are eighteen months stale |
| Open findings past SLA | Where accepted risk is accumulating without a decision | "Findings closed" rises while the overdue tail grows underneath it |
| Mean time to remediate, by severity | Whether severity actually changes the response | An average across all severities conceals that criticals move no faster |
| Concentration | How many critical services depend on one vendor or one platform | Per-vendor reporting cannot show a portfolio-level exposure at all |
| Material changes detected between assessments | Whether monitoring is doing anything | If this is zero, monitoring is not running — not that nothing changed |
Where RiskXchange fits
RiskXchange covers the register, tiering, assessment, outside-in monitoring, remediation and reporting on one platform, run by specialist agents rather than by a queue of tasks for your team. The relevant difference for a VRM program is the arithmetic above: pre-population and automated chasing move the constraint, and continuous monitoring means the annual cycle stops being the only time you learn anything.
The honest boundary: if your vendor register is small enough that a spreadsheet and a diary reminder work, they work. The case for a platform starts when the estate is large enough that coverage — not effort — is what is failing. See vendor risk management software for the buying decision, or our vendor risk platform for what we run.
Vendor risk management, answered.
What is vendor risk management?
What is the difference between vendor risk management and third-party risk management?
Why is vendor risk management important?
What is a vendor risk management framework?
How often should vendors be reassessed?
Where do you start if there is no program at all?
Go deeper.
Start with the register, not the questionnaire.
Book a 30-minute call and we will run discovery against your own domain — including the vendors that never reached the finance system.