Skip to main content

Vendors

TPRM → Vendors

The vendor register is the list of third parties you depend on. Everything else in the module hangs off it.

Adding a vendor

FieldNotes
Name / Name (Arabic)As it appears on the contract.
Vendor codeYour own reference. Shown next to the name in lists and reports.
Service categoryCloud, SaaS, BPO, data processing, physical security and so on.
TierCritical, high, medium or low.
ContactWho receives questionnaires. Use a named person, not a shared mailbox.
Next assessment dateDrives the review-due reporting.

Tiering

Tier is your judgement of how much the relationship matters — how much damage this vendor could do if it failed or was breached. It is set on the vendor, not derived, and it drives:

  • how deep a questionnaire you send,
  • how often you re-assess,
  • where the vendor sits in the reports.
Tier the relationship, not the company size

A small supplier holding your customer data is critical. A large supplier selling you office furniture is not. Tier on data access, business dependency and regulatory exposure.

Inherent and residual

Inherent risk is the exposure before any of the vendor's controls — driven by tier and service category.

Residual risk is what remains after their controls, and it is derived from assessment results, not typed in. A vendor with no completed assessment has no residual score, and that blank means "not assessed" — not "safe".

Vendor detail

Opening a vendor shows its assessments, findings, evidence and contacts in one place, with the current rating and next review date. This is the page to open before a contract renewal.

Offboarding

Offboarding a vendor keeps its history. Assessments, findings and evidence stay readable — you may need to show a regulator what you knew about a vendor you no longer use.