Explainer

What is vendor risk management (VRM)?

Vendor risk management (VRM) is the practice of understanding and controlling the risk that comes with relying on other businesses. It sounds heavy; it doesn't have to be.

5 min read Updated 1 July 2026

The three questions VRM answers

  1. Who do we rely on?
  2. What would hurt if they fell over?
  3. What evidence do we hold that they're safe today?

The typical VRM toolkit

A vendor register, a tiering framework, an evidence pack per tier, a review cadence and a way to react quickly to incidents. That's it. Everything else is enhancement.

How VRM sits alongside TPRM

'Vendor' typically means someone you pay. 'Third-party' includes vendors, partners, resellers and integrations. VRM is a subset of TPRM, and for many teams they're used interchangeably.

Frequently asked questions

Put this into practice today.

Start a free Credbase workspace, add your first supplier and share a live evidence pack in ten minutes.