The three questions VRM answers
- Who do we rely on?
- What would hurt if they fell over?
- What evidence do we hold that they're safe today?
The typical VRM toolkit
A vendor register, a tiering framework, an evidence pack per tier, a review cadence and a way to react quickly to incidents. That's it. Everything else is enhancement. The failure mode is not missing tooling, it is a register nobody updates because updating it is manual.
How to tier vendors without over-thinking it
Tiering is a judgement about impact, not a scoring science project. Three tiers is usually enough. Ask what happens to your customers, your data and your revenue if this vendor stops working tomorrow, then place them accordingly and set the evidence expectation per tier.
| Tier | Typical vendor | Evidence expected | Review |
|---|---|---|---|
| Critical | Holds customer data or you cannot trade without them | Insurance, ISO 27001 or SOC 2, DPA, BCP, financials | Annually plus on incident |
| Important | On site, customer-facing or material spend | Insurance, H&S policy, key accreditations | Annually |
| Routine | Low spend, no data, easily replaced | Insurance and entity details | On renewal only |
What the risks actually are
- Operational: they cannot deliver and your work stops.
- Financial: they fail mid-contract and you carry the cost of replacement.
- Information security: they hold your data and get breached.
- Legal and regulatory: a missing DPA or an unlawful transfer becomes your problem.
- Reputational: their conduct on your site or in your name lands on you.
- Concentration: five services from one supplier is one failure, not five.
A four-week rollout for a small team
- Week one: list every vendor you pay and what they do. Accounts payable is the fastest source.
- Week two: tier them. Twenty minutes of judgement beats a scoring matrix nobody trusts.
- Week three: request the evidence pack for critical and important tiers using one upload link each.
- Week four: set expiry reminders, agree who owns each vendor and diary the annual review.
How VRM sits alongside TPRM
'Vendor' typically means someone you pay. 'Third-party' includes vendors, partners, resellers and integrations. VRM is a subset of TPRM, and for many teams they're used interchangeably. If your auditor uses TPRM language, the same register and evidence answer both.
Signs your programme is working
- You can name your critical vendors from memory and prove their evidence is current.
- Nobody has to email a supplier to answer a client due-diligence question.
- Expiries are noticed before the date, not after a rejected invoice.
- The annual review is a one-hour meeting, not a fortnight of chasing.
Frequently asked questions
Your next step
Two ways to act on this guide right now - one hands-on, one to read next.
Ten quick questions on how organised your supplier record really is. Get a plain-English red, amber or green score with next steps.
Open the toolA pragmatic, right-sized guide to third-party risk management (TPRM) for teams that don't have a full risk function, with tiering, evidence packs and continuous monitoring.
Read the guidePut this into practice today.
Start a free Credbase workspace, add your first supplier and share a live document pack in ten minutes.