Skip to content

Vendor Management

Vendor management illustration

The Vendor Management module provides a centralised registry for tracking all third-party vendors your organisation works with. Register vendors, track their lifecycle from prospect to offboarding, manage certifications, and maintain a complete record of contact and contract details.

Navigate to Vendor Inventory under the Risk & Third Party section in the sidebar. This opens the Vendor Registry — your central hub for all vendor-related activities.

The registry is a filterable table showing all registered vendors for your organisation.

Use the filter bar at the top to narrow the list:

FilterOptions
SearchFilter by vendor name
StatusAll / Prospect / Active / Inactive / Archived
CriticalityAll / Low / Medium / High / Critical
CategoryDynamically populated from your vendors (e.g., Cloud Provider, SaaS, Consultancy)
ColumnDescription
NameVendor name (click to open detail page)
CategoryVendor type or classification
StatusCurrent lifecycle status (colour-coded badge)
CriticalityBusiness criticality level (colour-coded badge)
Risk ScoreCalculated risk score (if assessed)
Contract End DateWhen the current contract expires
ContactPrimary contact person
  1. Click the Add Vendor button in the registry header
  2. Complete the modal form with the vendor’s details
  3. Click Save to create the vendor record
FieldRequiredDescription
Vendor NameYesThe vendor’s trading name
DescriptionNoBrief description of what the vendor provides
WebsiteNoVendor’s website URL
CategoryNoClassification (e.g., Cloud Provider, SaaS, Consultancy)
StatusYesInitial lifecycle status
CriticalityYesBusiness criticality level
Data ClassificationNoSensitivity of data shared with this vendor
Contact NameNoPrimary contact person
Contact EmailNoContact email address
Contact PhoneNoContact phone number
Contract Start DateNoWhen the contract begins
Contract End DateNoWhen the contract expires
Contract ValueNoAnnual contract value in GBP
  1. Click a vendor row to open the Vendor Detail page
  2. Click Edit Vendor to open the edit modal
  3. Update the fields as needed
  4. Click Save to apply changes

All fields from the add form can be updated, including status and criticality. Changes take effect immediately.

Vendors progress through a defined lifecycle. Set the status to reflect where each vendor is in your relationship:

StatusDescriptionTypical Use
ProspectVendor under initial considerationPre-contract evaluation
ActiveVendor currently providing servicesNormal operations
Under ReviewVendor being reassessedPeriodic review or incident-triggered
ApprovedVendor has passed assessment and is clearedPost-assessment approval
SuspendedVendor services temporarily haltedPending investigation or remediation
OffboardedVendor relationship terminatedContract ended or vendor replaced

Criticality reflects how important the vendor is to your business operations:

LevelDescriptionExample
LowMinimal business impact if vendor is unavailableOffice supply providers
MediumSome disruption but workarounds existNon-essential SaaS tools
HighSignificant impact on operationsCore business applications
CriticalBusiness cannot function without this vendorCloud infrastructure, primary data processors

Setting the correct criticality level helps prioritise risk assessments and determines the depth of due diligence required.

Data classification indicates the sensitivity of information shared with or processed by the vendor. Set this based on the highest sensitivity level of data the vendor handles:

  • Public — Non-sensitive, publicly available information
  • Internal — Internal business data, not for public release
  • Confidential — Sensitive business or personal data
  • Restricted — Highly sensitive data (PII, financial, health records)

This classification feeds into the risk scoring algorithm, so it’s important to set it accurately.

Click any vendor row to open the Vendor Detail page. This is the primary working area for an individual vendor.

The header is always visible regardless of which tab you are on. It displays:

  • Vendor name — the vendor’s trading name
  • Status badge — colour-coded lifecycle status
  • Criticality badge — colour-coded business criticality level
  • Risk score badge — calculated risk score (if assessed)
  • Edit Vendor button — opens the edit modal
  • Delete Vendor button — removes the vendor record

The detail page is organised into three tabs that group related information by workflow stage.


The Overview tab provides a snapshot of the vendor’s core details, certifications, and assessment history.

Vendor Details card Displays the vendor’s description, website, category, and data classification.

Contact card Shows the primary contact name, email address, and phone number.

Contract card Shows the contract start date, end date, and contract value in GBP.

Certifications table Lists all tracked certifications with the following columns:

ColumnDescription
Certification Namee.g., ISO 27001:2022, SOC 2 Type II
Certification BodyThe issuing organisation
StatusValid, Expired, Revoked, or Pending
Issue DateWhen the certificate was granted
Expiry DateWhen it expires
Certificate NumberReference number (if available)

Assessment History table Shows a historical record of all assessments performed on this vendor:

ColumnDescription
TypeAssessment type (e.g., DPSIA)
DateWhen the assessment was conducted
StatusAssessment status
C / I / A ScoresConfidentiality, Integrity, and Availability scores
Risk RatingOverall risk rating from the assessment
AssessorPerson who conducted the assessment

The Assessment tab is where you conduct and review vendor security assessments. For full details on assessment workflows, see the Vendor Risk Assessment guide.

DPSIA Assessment The primary assessment action. Launch an AI-powered Data Protection Security Impact Assessment that evaluates the vendor across confidentiality, integrity, and availability dimensions. The DPSIA generates a structured risk profile based on vendor data, certifications, and automated security research.

CIA Control Breakdown Granular control-level scores across Confidentiality, Integrity, and Availability. Each control is scored individually, giving you visibility into specific strengths and weaknesses in the vendor’s security posture.

Claim Verification Cross-references the vendor’s self-reported claims (certifications, compliance statements, security measures) against available evidence. Highlights discrepancies between what the vendor states and what can be verified.


The Results & Actions tab captures the outputs of assessments and tracks remediation activities.

Action Items Remediation tasks generated from assessments or added manually. Each action item tracks:

  • Priority level
  • Assigned owner
  • Deadline
  • Current status

Compensating Controls Where gaps are identified, compensating controls describe the gap and the mitigation measures your organisation has put in place to address the risk. Each entry includes a gap description and the corresponding compensating control.

Reports Generated vendor assessment reports with options to export (PDF) or share. Reports consolidate the assessment results, risk scores, action items, and compensating controls into a single document.

Track your vendors’ security certifications to understand their compliance posture.

  1. Navigate to the Certifications table on the Overview tab of the Vendor Detail page
  2. Click Add Certification
  3. Enter the certification details:
    • Certification Name — e.g., ISO 27001:2022, SOC 2 Type II, PCI DSS
    • Certification Body — The issuing organisation
    • Status — Valid, Expired, Revoked, or Pending
    • Issue Date — When the certificate was granted
    • Expiry Date — When it expires
    • Certificate Number — Reference number (if available)
  4. Click Save
StatusDescription
ValidCurrent and active certification
ExpiredCertification has passed its expiry date
RevokedCertification withdrawn by the issuing body
PendingCertification application in progress
  1. Register all existing vendors — Start by adding your current third-party relationships
  2. Set criticality levels accurately — This drives assessment prioritisation
  3. Add contract dates — Enables proactive contract renewal tracking
  4. Record certifications — Capture any known certifications upfront
  1. Review vendor statuses quarterly — Ensure statuses reflect reality
  2. Monitor certification expiry dates — Follow up with vendors before certificates lapse
  3. Update contact details — Keep contact information current for incident response
  4. Track contract renewals — Use contract end dates to plan ahead
  5. Offboard promptly — Move vendors to Offboarded status when relationships end