Vendor risk
How to prove you vetted your vendors
The question lands in the last meeting before signing, and almost nobody can answer it with evidence. What counts as proof, and how to have it in a week.
Published September 1, 2026
There's a question that always shows up at the same moment: the last meeting before signing, contract already drafted, when someone from the client's procurement or legal team says *"we need to see how you assess your vendors."* It isn't a technical question. It's a condition.
And it almost never gets answered with evidence — not because nobody thought about it, but because the answer lives scattered across a spreadsheet someone maintained until they changed roles, an email from two years ago, and the memory of three people.
Why it happens to well-run operations
A company that works accumulates vendors with real access: whoever hosts the application, whoever sends the email, whoever runs payroll, whoever comes in over VPN for support, the system that stores customer data. Each one arrived solving a concrete problem, with a reasonable decision behind it.
What doesn't exist is the thread connecting them. Assessing them systematically required, until recently, one more tool: its own console, its own learning curve, its own invoice. Faced with that, almost everyone picks the spreadsheet. And a spreadsheet isn't evidence — it's a good-faith reminder.
What counts as evidence
The gap between "we have it under control" and an answer that survives an audit is more concrete than it looks:
| What people usually have | What gets asked for |
|---|---|
| A list of vendors | An inventory of who has access to what, and since when |
| "We asked them at the time" | A questionnaire with a date, answers, and who answered them |
| A general sense of the risk | An assessment criterion applied the same way to everyone |
| A signed contract | Proof the assessment was repeated at renewal |
| Loose screenshots | An exportable document you can hand over without depending on anyone |
None of those five things is hard on its own. What's hard is sustaining them over time when nobody owns the job.
How to have evidence in a week
- 1
Build the inventory by access, not by spend
The accounting list sorts vendors by what they cost. The one you need sorts them by what they can see or do. Start with the ones that touch customer data, production systems, or email.
- 2
Sort them into three tiers, not seven
Critical, relevant, marginal. A finer scale looks more serious and gets abandoned faster, because it forces a debate on every case instead of a decision.
- 3
Send everyone the same questionnaire
The value is in it being the same one, not in it being long. A different questionnaire per vendor can't be compared, and uniform criteria is exactly what an audit wants to see.
- 4
Store the answer with a date and an author
An undated answer proves nothing: there's no way to tell whether it describes today or three years ago. The date is half the evidence.
- 5
Decide when it repeats
Annually for critical vendors, at renewal for the rest. Written down, even if it's one line. A process with no stated cadence is a process that happened once.
Where we fit
All five steps can be done by hand. What breaks by hand is month six, when the inventory goes stale and nobody notices until the next audit.
Vendor Risk is our platform's anchor module and it sits in the lowest tier: inventory, a questionnaire sent by link — the vendor doesn't need to create an account — per-vendor assessment, renewal reminders, and exportable evidence. It's part of the same subscription as the other seven modules, not one more tool with its own invoice.
There's a 30-day trial, no credit card. In the first session you can already load your inventory and send the first questionnaire: if the question is coming at next month's meeting, that week is enough. And if you would rather walk through your case with someone before opening an account, let's talk.