← All articles

Vendor risk

How to prove you vetted your vendors

The question lands in the last meeting before signing, and almost nobody can answer it with evidence. What counts as proof, and how to have it in a week.

Published September 1, 2026

There's a question that always shows up at the same moment: the last meeting before signing, contract already drafted, when someone from the client's procurement or legal team says *"we need to see how you assess your vendors."* It isn't a technical question. It's a condition.

And it almost never gets answered with evidence — not because nobody thought about it, but because the answer lives scattered across a spreadsheet someone maintained until they changed roles, an email from two years ago, and the memory of three people.

Why it happens to well-run operations

A company that works accumulates vendors with real access: whoever hosts the application, whoever sends the email, whoever runs payroll, whoever comes in over VPN for support, the system that stores customer data. Each one arrived solving a concrete problem, with a reasonable decision behind it.

What doesn't exist is the thread connecting them. Assessing them systematically required, until recently, one more tool: its own console, its own learning curve, its own invoice. Faced with that, almost everyone picks the spreadsheet. And a spreadsheet isn't evidence — it's a good-faith reminder.

What counts as evidence

The gap between "we have it under control" and an answer that survives an audit is more concrete than it looks:

What people usually haveWhat gets asked for
A list of vendorsAn inventory of who has access to what, and since when
"We asked them at the time"A questionnaire with a date, answers, and who answered them
A general sense of the riskAn assessment criterion applied the same way to everyone
A signed contractProof the assessment was repeated at renewal
Loose screenshotsAn exportable document you can hand over without depending on anyone

None of those five things is hard on its own. What's hard is sustaining them over time when nobody owns the job.

How to have evidence in a week

  1. 1

    Build the inventory by access, not by spend

    The accounting list sorts vendors by what they cost. The one you need sorts them by what they can see or do. Start with the ones that touch customer data, production systems, or email.

  2. 2

    Sort them into three tiers, not seven

    Critical, relevant, marginal. A finer scale looks more serious and gets abandoned faster, because it forces a debate on every case instead of a decision.

  3. 3

    Send everyone the same questionnaire

    The value is in it being the same one, not in it being long. A different questionnaire per vendor can't be compared, and uniform criteria is exactly what an audit wants to see.

  4. 4

    Store the answer with a date and an author

    An undated answer proves nothing: there's no way to tell whether it describes today or three years ago. The date is half the evidence.

  5. 5

    Decide when it repeats

    Annually for critical vendors, at renewal for the rest. Written down, even if it's one line. A process with no stated cadence is a process that happened once.

Where we fit

All five steps can be done by hand. What breaks by hand is month six, when the inventory goes stale and nobody notices until the next audit.

Vendor Risk is our platform's anchor module and it sits in the lowest tier: inventory, a questionnaire sent by link — the vendor doesn't need to create an account — per-vendor assessment, renewal reminders, and exportable evidence. It's part of the same subscription as the other seven modules, not one more tool with its own invoice.

There's a 30-day trial, no credit card. In the first session you can already load your inventory and send the first questionnaire: if the question is coming at next month's meeting, that week is enough. And if you would rather walk through your case with someone before opening an account, let's talk.

Eight modules, one subscription

Vendor Risk, Attack Surface, Breach Exposure and five more modules under a single contract. Nothing to install.

Start a 30-day trial, no card