Skip to content

Vendor Management

Vendor management illustration

The Vendor Management module provides a centralised registry for tracking all third-party vendors your organisation works with. Register vendors, track their lifecycle from prospect to offboarding, manage certifications, and maintain a complete record of contact and contract details.

Navigate to Vendor Inventory under the Risk & Third Party section in the sidebar. This opens the Vendor Registry — your central hub for all vendor-related activities.

The registry is a filterable table showing all registered vendors for your organisation.

Use the filter bar at the top to narrow the list:

FilterOptions
SearchFilter by vendor name
StatusAll / Prospect / Active / Under Review / Approved / Suspended / Offboarded
CriticalityAll / Low / Medium / High / Critical
CategoryDynamically populated from your vendors (e.g., Cloud Provider, SaaS, Consultancy)
ColumnDescription
NameVendor name (click to open detail page)
CategoryVendor type or classification
StatusCurrent lifecycle status (colour-coded badge)
CriticalityBusiness criticality level (colour-coded badge)
RiskThe vendor’s single authoritative risk score with a RAG-coloured pill (if assessed)
ReviewNext annual review date, with a Due soon or Overdue badge when the review needs attention
Contract End DateWhen the current contract expires
ContactPrimary contact person
  1. Click the Add Vendor button in the registry header
  2. Complete the modal form with the vendor’s details
  3. Click Save to create the vendor record
FieldRequiredDescription
Vendor NameYesThe vendor’s trading name
DescriptionNoBrief description of what the vendor provides
WebsiteNoVendor’s website URL
CategoryNoClassification (e.g., Cloud Provider, SaaS, Consultancy)
StatusYesInitial lifecycle status
CriticalityYesBusiness criticality level
Data ClassificationNoSensitivity of data shared with this vendor
Contact NameNoPrimary contact person
Contact EmailNoContact email address
Contact PhoneNoContact phone number
Contract Start DateNoWhen the contract begins
Contract End DateNoWhen the contract expires
Contract ValueNoAnnual contract value in GBP
  1. Click a vendor row to open the Vendor Detail page
  2. Click Edit Vendor to open the edit modal
  3. Update the fields as needed
  4. Click Save to apply changes

All fields from the add form can be updated, including status and criticality. Changes take effect immediately.

Vendors progress through a defined lifecycle. Set the status to reflect where each vendor is in your relationship:

StatusDescriptionTypical Use
ProspectVendor under initial considerationPre-contract evaluation
ActiveVendor currently providing servicesNormal operations
Under ReviewVendor being reassessedPeriodic review or incident-triggered
ApprovedVendor has passed assessment and is clearedPost-assessment approval
SuspendedVendor services temporarily haltedPending investigation or remediation
OffboardedVendor relationship terminatedContract ended or vendor replaced

Criticality reflects how important the vendor is to your business operations:

LevelDescriptionExample
LowMinimal business impact if vendor is unavailableOffice supply providers
MediumSome disruption but workarounds existNon-essential SaaS tools
HighSignificant impact on operationsCore business applications
CriticalBusiness cannot function without this vendorCloud infrastructure, primary data processors

Setting the correct criticality level helps prioritise risk assessments and determines the depth of due diligence required.

Data classification indicates the sensitivity of information shared with or processed by the vendor. Set this based on the highest sensitivity level of data the vendor handles:

  • Public — Non-sensitive, publicly available information
  • Internal — Internal business data, not for public release
  • Confidential — Sensitive business or personal data
  • Restricted — Highly sensitive data (PII, financial, health records)

This classification helps prioritise due diligence and frames the vendor’s data protection risk, so it’s important to set it accurately.

Click any vendor row to open the Vendor Detail page. This is the primary working area for an individual vendor, structured around the vendor lifecycle: Add → Assess → Decide → Review.

The header is always visible regardless of which tab you are on. It displays:

  • Vendor name and category — the vendor’s trading name and classification
  • Status badge — colour-coded lifecycle status
  • Criticality badge — colour-coded business criticality level
  • Risk score pill — the vendor’s single authoritative risk score, coloured by RAG status (e.g. Risk 12 · AMBER)
  • Recommendation pill — the latest assessment’s recommendation (Approve / Conditional Approval / Reject)
  • Provenance lineAssessed <date> · Review due <date>, with due soon / overdue highlighted
  • Primary action buttonRun AI assessment, Run annual review, or Re-run assessment, depending on where the vendor is in its lifecycle
  • Edit and Delete buttons for the vendor record

The detail page is organised into four tabs that follow the lifecycle.


The Overview tab provides a snapshot of the vendor’s core details and certifications.

Vendor Details card Displays the vendor’s description, website, category, and data classification.

Contact card Shows the primary contact name, email address, and phone number.

Contract card Shows the contract start date, end date, and contract value in GBP.

Certifications table Lists all tracked certifications with the following columns:

ColumnDescription
Certification Namee.g., ISO 27001:2022, SOC 2 Type II
Certification BodyThe issuing organisation
StatusValid, Expired, Revoked, or Pending
Issue DateWhen the certificate was granted
Expiry DateWhen it expires
Certificate NumberReference number (if available)

The Assess tab is where you run the AI assessment and read the resulting report — RAG status, recommendation, risk analysis (inherent vs residual), CIA triad controls, certifications, breach/CVE/regulatory history, mandatory actions, and research sources. While an assessment is running, this tab shows live progress.

For the full workflow, see the Vendor Risk Assessment guide.


The Decide tab captures the decision outputs of the latest assessment and your remediation tracking:

Recommendation The latest recommendation with its executive summary and, for conditional approvals, the conditions for use.

Action Items Remediation tasks generated automatically from the assessment’s mandatory actions, or added manually. Each item tracks priority, owner, due date, and status. When a new assessment completes, still-open auto-generated items from earlier assessments are superseded automatically.

Compensating Controls Where gaps are identified, compensating controls describe the gap and the mitigation measures your organisation has put in place, each with an effectiveness rating.


The Review tab manages the annual review cycle:

Next Review The next annual review date — set automatically to 12 months after each completed assessment — with a Due soon or Overdue badge and a shortcut to run the annual review when it needs attention.

Assessment History Every assessment for the vendor with its type, date, status, risk score, RAG status, and recommendation.

Track your vendors’ security certifications to understand their compliance posture.

  1. Navigate to the Certifications table on the Overview tab of the Vendor Detail page
  2. Click Add Certification
  3. Enter the certification details:
    • Certification Name — e.g., ISO 27001:2022, SOC 2 Type II, PCI DSS
    • Certification Body — The issuing organisation
    • Status — Valid, Expired, Revoked, or Pending
    • Issue Date — When the certificate was granted
    • Expiry Date — When it expires
    • Certificate Number — Reference number (if available)
  4. Click Save
StatusDescription
ValidCurrent and active certification
ExpiredCertification has passed its expiry date
RevokedCertification withdrawn by the issuing body
PendingCertification application in progress
  1. Register all existing vendors — Start by adding your current third-party relationships
  2. Set criticality levels accurately — This drives assessment prioritisation
  3. Add contract dates — Enables proactive contract renewal tracking
  4. Record certifications — Capture any known certifications upfront
  1. Review vendor statuses quarterly — Ensure statuses reflect reality
  2. Monitor certification expiry dates — Follow up with vendors before certificates lapse
  3. Update contact details — Keep contact information current for incident response
  4. Track contract renewals — Use contract end dates to plan ahead
  5. Offboard promptly — Move vendors to Offboarded status when relationships end