Skip to content
Vendor lifecycle management

Every vendor, from intake to exit, in one record

Scope each relationship at intake, set its depth of due diligence by criticality, contract with conditions, monitor between reviews, reassess on cadence and exit with evidence. One governed workflow, one audit trail, for every vendor, supplier and outsourcing arrangement.

Why lifecycle, not just assessment

Most TPRM failures happen between the assessments

Examiners rarely criticize a single assessment. They criticize the inventory that missed a vendor, the review that lapsed, and the exit nobody can evidence.

The same vendor, five times

Different business units onboard the same provider separately. Risk is assessed five times, or worse, not at all, and nobody sees the combined exposure.

One questionnaire for everyone

A 300-question security questionnaire sent to a catering supplier wastes both teams’ time, and still misses what matters for the payment processor.

Reviews that quietly lapse

Reassessment dates live in a spreadsheet. Expired SOC reports and missed reviews surface during the exam, not before it.

Exits with no evidence

Contracts end, but there is no record that access was revoked or data destroyed. The exit plan was never tested.
Seven stages

A lifecycle you can walk an examiner through

Each stage has an owner, required evidence and an exit condition. Nothing moves forward until it is met, and every decision is recorded.

Reassessment cadence by tier: an example policy

CriticalEvery 12 months
MaterialEvery 24 months
Low riskAt contract renewal

Cadence is set by your policy and enforced by the platform. Confirmed monitoring signals, new services or new data types can bring any date forward.

  1. 01

    Intake

    Business owner
    The request captures the business case, the services, the business units that will rely on them and the data types in scope. Business case plus data types decide control applicability, so the assessment asks only what matters for this relationship. A new engagement with an existing vendor joins that vendor’s record instead of creating a second one.
  2. 02

    Due diligence

    TPRM team
    Inherent risk and criticality set the tier. Sanctions screening and public-source checks run first. The vendor is invited to the vendor portal with a request list sized to its tier, from a short attestation for Low-risk vendors to SOC reports, penetration tests, BCP and DR test results and financials for Critical ones.
  3. 03

    Assessment

    Analyst and reviewer
    A point-in-time, inside-out review of the vendor’s controls across 30+ control domains, based on the artifacts it provided. Your analysts review the evidence, record ratings, findings and notes, and sign off. SOC reports are reviewed for exceptions, carve-outs, subservice organizations and CUECs. With Comprehensive Vendor Risk Assessment Services, VendRisk360 assessors perform the assessment for you.
  4. 04

    Contracting

    Procurement and legal
    Findings that must close before signature become pre-contract conditions. Residual risk goes through the risk acceptance workflow where needed, and multi-stage sign-off with segregation of duties issues a sign-off certificate. Contract and renewal dates are recorded on the vendor record and drive the next review.
  5. 05

    Monitoring

    Ongoing
    Continuous, outside-in monitoring across the vendor’s external attack surface, shadow infrastructure, indicators of compromise, breaches and security incidents, adverse news and litigation, regulatory and enforcement actions and sanctions. Alerts fire only after a signal is confirmed, and each lands on the vendor record for the owner to act on.
  6. 06

    Reassessment

    Cadence or trigger
    Each tier follows the reassessment cadence set in your policy, for example annual for Critical vendors, and the platform tracks every due date. A confirmed high-severity signal, a new service or a new data type can bring the date forward. Recertification asks owners to confirm the relationship, its services and its tier, and reconciles the answers against the register.
  7. 07

    Offboarding

    Exit
    An offboarding case tracks termination steps: access revocation, return or destruction of data with certificates, transition of services, and final invoices or obligations. Exit evidence is stored on the record, and the history remains for audit and examination.
Intake and scoping

Ask the right questions, of the right vendor

Two intake answers do most of the work: why the business needs the vendor, and what data it will touch. From those, VendRisk360 derives which control domains apply and how deep the review goes.

  • Business case, services and relying business units captured up front
  • Data types in scope: personal data, cardholder data, PHI, confidential and regulated data
  • Control applicability derived automatically, then adjustable by the analyst with a reason
  • One record per vendor: new engagements join the existing record

Business case

Outsourced card payment processing

Data types

Cardholder dataCustomer PIITransaction data

Control domains in scope

  • Access management
  • Encryption and key management
  • Business continuity and DR
  • Incident response and notification
  • Subcontractor oversight
  • Privacy and data retention

Illustrative example

Keeping the register true

Recertify what you have. Exit what you no longer need.

An inventory is only as good as its last reconciliation. Exits are only as good as their evidence.

Recertification and reconciliation

On a set cadence, relationship owners confirm each vendor is still in use, which services it provides, which data it handles and whether the tier still fits. VendRisk360 reconciles the answers against the register and flags drift: a Low-risk vendor now handling customer data, or an owner who has left.

  • Owner attestations with a recorded response
  • Tier and data-type changes routed for review
  • Orphaned relationships reassigned, not lost

Offboarding with exit evidence

DORA, the EBA outsourcing guidelines and APRA CPS 230 all expect documented exit strategies for critical services. When a relationship ends, an offboarding case tracks each step and stores the proof.

  • Access revocation confirmed
  • Data return or destruction certificates stored
  • Service transition and final obligations closed
  • History retained for auditors and examiners
Vendor collaboration

Vendors work their stage in the vendor portal

Due diligence requests, questionnaires, evidence and remediation all go through one portal with one-time-code access. Your team tracks progress from the lifecycle board instead of an inbox.

Requests sized to the tier
Questionnaires scoped by data type
Remediation tracked to closure
Exit evidence collected at the end
One lifecycle, many names

Whatever your regulator calls it

The discipline has a different name in every market. The platform structures the same lifecycle to the vocabulary and records each regime expects.

Market or sectorWhat it is calledKey references
United StatesThird-party relationshipsInteragency Guidance (Fed, FDIC, OCC), NCUA for credit unions and CUSOs, FFIEC
European UnionICT third-party arrangements, outsourcingDORA register of information, critical or important functions, EBA Guidelines on outsourcing
United KingdomOutsourcing and third-party riskPRA SS2/21, material outsourcing, operational resilience
AustraliaMaterial service providersAPRA CPS 230 and CPG 230, material arrangements
SingaporeMaterial outsourcingMAS Guidelines on Outsourcing
IndiaOutsourcing of IT servicesRBI Master Direction on outsourcing of IT services, material outsourcing
HealthcareBusiness associatesHIPAA business associate agreements and safeguards
SaaS and data processorsSub-processorsGDPR Article 28 processor and sub-processor obligations

VendRisk360 is aligned to these frameworks. Each organization remains responsible for its own compliance.

See global regulatory coverage
FAQ

Frequently asked questions

What is vendor lifecycle management?

Vendor lifecycle management is governing each third-party relationship from the first request through due diligence, contracting, ongoing monitoring, periodic reassessment and termination. Regulators in the US, EU, UK, Australia, Singapore and India all describe this lifecycle, and expect the depth of oversight to match the criticality of the service.

How does intake decide which controls apply?

The requester states the business case and the data types the vendor will access or process, such as customer personal data, cardholder data or protected health information. VendRisk360 uses both answers to determine which control domains apply, so the questionnaire and evidence list fit the relationship.

How often are vendors reassessed?

Cadence follows the tier, and your own TPRM policy sets it. A common pattern is annual reassessment for Critical vendors, a longer interval for Material vendors and review at contract renewal for Low-risk vendors. The platform enforces whatever cadence you configure. Confirmed monitoring signals, new services or new data types can trigger an earlier reassessment.

Can the vendor record serve as our DORA register of information or outsourcing register?

The vendor record holds the relationships, services, criticality, contract dates, locations and subcontractors that registers such as the DORA register of information, the EBA outsourcing register and APRA CPS 230 material arrangements draw on, and the data exports to Excel. Your compliance team remains responsible for the final regulatory submission and its format.

What does offboarding record?

An offboarding case tracks each exit step and stores the evidence: access revocation, data return or destruction certificates, service transition and closure of obligations. The vendor record and its history remain available to auditors after the relationship ends.

What is recertification?

Recertification periodically asks each relationship owner to confirm the vendor is still in use, which services it provides, which data it handles and whether the tier is still right. The answers are reconciled against the register so stale or misclassified relationships are corrected.

Get started

See VendRisk360 on your own vendors

A tailored walkthrough with a third-party risk specialist, built around your program, your regulators and your vendors.