Vendor risk management

Vendor risk management, from register to evidence.

Vendor risk management — VRM — is how an organization identifies and controls the risk created by the parties it buys from: what each vendor can reach, how much the business depends on it, whether its security holds up, and what happens when it fails. This page covers the process end to end, what a vendor risk management framework contains, how to build a program that scales past a spreadsheet, the metrics worth reporting, and where VRM sits against third-party risk management.

Last reviewed by Darren Craig

What is vendor risk management?

A subset of third-party risk, and a useful one — as long as the edges are known.

Vendor risk management is the practice of understanding and controlling what you take on when you buy something. That covers more than a security questionnaire: operational dependence and concentration, financial stability, regulatory and sanctions exposure, data protection, and the parties your vendors rely on in turn.

The distinction from third-party risk management is one of scope rather than method. A vendor is someone you buy from. A third party is anyone outside your organization whose failure lands on you, which includes vendors and also includes parties you have no purchase order with: joint venture partners, agents and introducers, franchisees, and the recipients of data you share without paying for the privilege. VRM is the larger half of TPRM in volume and the smaller half in scope.

That matters at exactly one moment: when you scope the program. A register built by exporting the vendor list from finance is complete for spend and incomplete for risk, and the parties it omits are by definition the ones nobody has assessed.

The vendor risk management process process

Six stages. Most programs are strong at stage three and weak at stages one, five and six — which is the wrong distribution, because the first stage bounds everything after it.

  1. 1. Inventory
    Establish who your vendors actually are. Finance knows who you pay; it does not know who has an API key. Expect the real number to exceed the list you started with, and treat discovery as continuous rather than a one-off exercise.
  2. 2. Tiering
    Segment by inherent risk — what the vendor accesses and how badly its failure hurts — not by spend. The cheapest vendor in the estate can hold the most sensitive data, and frequently does.
  3. 3. Due diligence
    Match assessment depth to tier. Collect what already exists — SOC 2, ISO 27001, pen test summaries — before issuing a questionnaire, and use the questionnaire for what the documents did not answer.
  4. 4. Contracting
    Security, notification, audit and exit rights are far easier to secure before signature than after. This is the stage where the leverage exists and the stage most often skipped by risk teams who see it as procurement’s job.
  5. 5. Monitoring
    A point-in-time assessment describes a vendor on one day. Between assessments, outside-in monitoring catches material change without needing the vendor’s cooperation — which matters, because a vendor in trouble is the least likely to volunteer it.
  6. 6. Offboarding
    Access revoked, data destroyed and evidenced, contractual obligations enforced. The stage with the least attention and the longest tail: dormant credentials and undeleted data outlive the commercial relationship by years.

What a vendor risk management framework contains

Six documented components. Everything else is implementation detail.

A vendor risk management framework is the written basis on which the program runs — the thing an auditor asks for first and the thing most programs reconstruct after the fact. It needs six components, and it does not need to be long.

  • Scope and definitions. What counts as a vendor, and what falls outside. Ambiguity here is what produces registers that disagree between teams.
  • Roles and accountability. Who owns the relationship, who owns the risk decision, and who signs off an exception. These are three different people in most organizations and one person in the framework of organizations that have not thought about it.
  • The tiering model. The criteria that put a vendor in a tier, and the assessment depth each tier receives.
  • Assessment standards. What evidence is acceptable, what expires, and what must be independently verified rather than accepted on assertion.
  • Remediation and SLAs. How findings are rated, who fixes them, by when, and what happens when the date passes.
  • Reporting. What goes to the board, at what interval, and which measures it contains.

Frameworks such as NIST SP 800-161, ISO 27036 and the interagency third-party risk guidance issued by the Federal Reserve, OCC and FDIC in 2023 are useful sources for the content. None of them substitutes for writing down how your organization actually operates.

Building a vendor risk management program that scales

The constraint is rarely knowledge. It is arithmetic.

A vendor risk management program fails at scale for a reason that has nothing to do with expertise. A team of three running full questionnaires across four hundred vendors on an annual cycle needs to complete roughly two assessments every working day, forever, while also handling onboarding, remediation and reporting. It does not happen, and what gives way is the monitoring between assessments — the part that would actually have caught something.

Three things make the arithmetic work:

  • Tier honestly. If ninety percent of the estate is “critical”, the tiering has failed and the effort is spread evenly across vendors that do not warrant it.
  • Stop re-collecting what you already hold. Most of a standard questionnaire is answerable from documents the vendor has already sent. Asking again is work you are choosing to do.
  • Make monitoring the default state. Continuous outside-in observation is what turns the annual cycle from the whole program into one input to it. See AI third-party risk management for what can and cannot be automated safely.

Vendor risk management metrics worth reporting

Most VRM reporting measures activity. A board cannot act on activity. These measure coverage and exposure instead.

MeasureWhat it answersWhy activity metrics fail here
Register completenessWhat proportion of live vendors have an owner and a tier"Assessments completed" looks healthy while a third of the estate is unregistered
Tier 1 assessment currencyHow many critical vendors have current, in-date evidenceA count of assessments hides how many are eighteen months stale
Open findings past SLAWhere accepted risk is accumulating without a decision"Findings closed" rises while the overdue tail grows underneath it
Mean time to remediate, by severityWhether severity actually changes the responseAn average across all severities conceals that criticals move no faster
ConcentrationHow many critical services depend on one vendor or one platformPer-vendor reporting cannot show a portfolio-level exposure at all
Material changes detected between assessmentsWhether monitoring is doing anythingIf this is zero, monitoring is not running — not that nothing changed

Where RiskXchange fits

RiskXchange covers the register, tiering, assessment, outside-in monitoring, remediation and reporting on one platform, run by specialist agents rather than by a queue of tasks for your team. The relevant difference for a VRM program is the arithmetic above: pre-population and automated chasing move the constraint, and continuous monitoring means the annual cycle stops being the only time you learn anything.

The honest boundary: if your vendor register is small enough that a spreadsheet and a diary reminder work, they work. The case for a platform starts when the estate is large enough that coverage — not effort — is what is failing. See vendor risk management software for the buying decision, or our vendor risk platform for what we run.

Vendor risk management, answered.

What is vendor risk management?
The practice of identifying and controlling the risk an organization takes on from the parties it buys from — covering what each vendor can access, how much the business depends on it, whether its security posture holds up, and what happens when it fails. It runs as a lifecycle from inventory through offboarding, not as a one-off assessment.
What is the difference between vendor risk management and third-party risk management?
Scope. A vendor is someone you buy from; a third party is anyone outside your organization whose failure lands on you, including parties you have no commercial relationship with at all. VRM is a subset of TPRM. In everyday use the terms are treated as interchangeable, and the distinction only bites when you are deciding what belongs in the register.
Why is vendor risk management important?
Because accountability does not transfer with the work. When you outsource a function you keep the obligation to your regulator, your customers and the public, while giving up direct control of how it is run. VRM is the set of practices that tries to close that gap — and regulators increasingly treat its absence as a finding in its own right rather than only after an incident.
What is a vendor risk management framework?
The documented basis for the program: scope and definitions, roles and accountability, the tiering model, assessment standards, remediation SLAs and reporting. NIST SP 800-161, ISO 27036 and the 2023 US interagency guidance are useful sources, but a framework has to describe how your organization actually operates to be worth anything in an audit.
How often should vendors be reassessed?
By tier, not on a single cycle. Critical vendors annually as a floor, with continuous outside-in monitoring in between; lower tiers on a longer cycle or on trigger events — a breach, a material change in the relationship, an acquisition, a change in what they access. A uniform annual cycle across the whole estate spends the same effort on vendors that do not warrant it.
Where do you start if there is no program at all?
The register, then tiering — in that order, and before any questionnaire goes out. An assessment program running against an incomplete inventory produces confident coverage of the wrong population, which is worse than knowing you have a gap. Build the list, tier it honestly, then assess the top tier properly.

Start with the register, not the questionnaire.

Book a 30-minute call and we will run discovery against your own domain — including the vendors that never reached the finance system.