Skip to content

Vendor Management

Vendor management illustration

The Vendor Management module provides a centralised registry for tracking all third-party vendors your organisation works with. Register vendors, track their lifecycle from prospect to offboarding, manage certifications, and maintain a complete record of contact and contract details.

Click Vendor Management in the sidebar navigation. This opens the Vendor Registry — your central hub for all vendor-related activities.

The registry is a filterable table showing all registered vendors for your organisation.

Use the filter bar at the top to narrow the list:

FilterOptions
SearchFilter by vendor name
StatusAll / Prospect / Active / Inactive / Archived
CriticalityAll / Low / Medium / High / Critical
CategoryDynamically populated from your vendors (e.g., Cloud Provider, SaaS, Consultancy)
ColumnDescription
NameVendor name (click to open detail page)
CategoryVendor type or classification
StatusCurrent lifecycle status (colour-coded badge)
CriticalityBusiness criticality level (colour-coded badge)
Risk ScoreCalculated risk score (if assessed)
Contract End DateWhen the current contract expires
ContactPrimary contact person
  1. Click the Add Vendor button in the registry header
  2. Complete the modal form with the vendor’s details
  3. Click Save to create the vendor record
FieldRequiredDescription
Vendor NameYesThe vendor’s trading name
DescriptionNoBrief description of what the vendor provides
WebsiteNoVendor’s website URL
CategoryNoClassification (e.g., Cloud Provider, SaaS, Consultancy)
StatusYesInitial lifecycle status
CriticalityYesBusiness criticality level
Data ClassificationNoSensitivity of data shared with this vendor
Contact NameNoPrimary contact person
Contact EmailNoContact email address
Contact PhoneNoContact phone number
Contract Start DateNoWhen the contract begins
Contract End DateNoWhen the contract expires
Contract ValueNoAnnual contract value in GBP
  1. Click a vendor row to open the Vendor Detail page
  2. Click Edit Vendor to open the edit modal
  3. Update the fields as needed
  4. Click Save to apply changes

All fields from the add form can be updated, including status and criticality. Changes take effect immediately.

Vendors progress through a defined lifecycle. Set the status to reflect where each vendor is in your relationship:

StatusDescriptionTypical Use
ProspectVendor under initial considerationPre-contract evaluation
ActiveVendor currently providing servicesNormal operations
Under ReviewVendor being reassessedPeriodic review or incident-triggered
ApprovedVendor has passed assessment and is clearedPost-assessment approval
SuspendedVendor services temporarily haltedPending investigation or remediation
OffboardedVendor relationship terminatedContract ended or vendor replaced

Criticality reflects how important the vendor is to your business operations:

LevelDescriptionExample
LowMinimal business impact if vendor is unavailableOffice supply providers
MediumSome disruption but workarounds existNon-essential SaaS tools
HighSignificant impact on operationsCore business applications
CriticalBusiness cannot function without this vendorCloud infrastructure, primary data processors

Setting the correct criticality level helps prioritise risk assessments and determines the depth of due diligence required.

Data classification indicates the sensitivity of information shared with or processed by the vendor. Set this based on the highest sensitivity level of data the vendor handles:

  • Public — Non-sensitive, publicly available information
  • Internal — Internal business data, not for public release
  • Confidential — Sensitive business or personal data
  • Restricted — Highly sensitive data (PII, financial, health records)

This classification feeds into the risk scoring algorithm, so it’s important to set it accurately.

Click any vendor row to open the Vendor Detail page. This is the primary working area, organised into 12 sections:

SectionPurpose
OverviewBasic vendor information, risk score, and data classification
Contact InformationContact name, email, and phone number
Contract DetailsStart date, end date, and contract value
AssessmentsHistorical assessment records with CIA scores and risk ratings
CertificationsTracked security certifications and their validity status
CIA Control BreakdownGranular control scores across Confidentiality, Integrity, and Availability
Risk Scoring5-factor risk breakdown with calculated score
Claim VerificationCross-referencing of vendor claims against evidence
Action ItemsRemediation tasks with priority, ownership, and deadlines
Compensating ControlsGap descriptions and mitigation measures
ReportsGenerated reports with export and email options
AI-Powered ResearchDPSIA assessment and automated security research

For details on the assessment-related sections (Risk Scoring, CIA Controls, Claim Verification, DPSIA, and Reports), see the Vendor Risk Assessment guide.

Track your vendors’ security certifications to understand their compliance posture.

  1. Navigate to the Certifications section on the Vendor Detail page
  2. Click Add Certification
  3. Enter the certification details:
    • Certification Name — e.g., ISO 27001:2022, SOC 2 Type II, PCI DSS
    • Certification Body — The issuing organisation
    • Status — Valid, Expired, Revoked, or Pending
    • Issue Date — When the certificate was granted
    • Expiry Date — When it expires
    • Certificate Number — Reference number (if available)
  4. Click Save
StatusDescription
ValidCurrent and active certification
ExpiredCertification has passed its expiry date
RevokedCertification withdrawn by the issuing body
PendingCertification application in progress
  1. Register all existing vendors — Start by adding your current third-party relationships
  2. Set criticality levels accurately — This drives assessment prioritisation
  3. Add contract dates — Enables proactive contract renewal tracking
  4. Record certifications — Capture any known certifications upfront
  1. Review vendor statuses quarterly — Ensure statuses reflect reality
  2. Monitor certification expiry dates — Follow up with vendors before certificates lapse
  3. Update contact details — Keep contact information current for incident response
  4. Track contract renewals — Use contract end dates to plan ahead
  5. Offboard promptly — Move vendors to Offboarded status when relationships end