Explainer

What is vendor risk management (VRM)?

Vendor risk management (VRM) is the practice of understanding and controlling the risk that comes with relying on other businesses. It sounds heavy; it does not have to be. This explainer covers what VRM actually involves, how to tier your vendors, what evidence to hold at each tier and how small teams run a defensible programme in a week.

8 min read Updated 31 July 2026Recently updated

The three questions VRM answers

  1. Who do we rely on?
  2. What would hurt if they fell over?
  3. What evidence do we hold that they're safe today?

The typical VRM toolkit

A vendor register, a tiering framework, an evidence pack per tier, a review cadence and a way to react quickly to incidents. That's it. Everything else is enhancement. The failure mode is not missing tooling, it is a register nobody updates because updating it is manual.

How to tier vendors without over-thinking it

Tiering is a judgement about impact, not a scoring science project. Three tiers is usually enough. Ask what happens to your customers, your data and your revenue if this vendor stops working tomorrow, then place them accordingly and set the evidence expectation per tier.

TierTypical vendorEvidence expectedReview
CriticalHolds customer data or you cannot trade without themInsurance, ISO 27001 or SOC 2, DPA, BCP, financialsAnnually plus on incident
ImportantOn site, customer-facing or material spendInsurance, H&S policy, key accreditationsAnnually
RoutineLow spend, no data, easily replacedInsurance and entity detailsOn renewal only

What the risks actually are

  • Operational: they cannot deliver and your work stops.
  • Financial: they fail mid-contract and you carry the cost of replacement.
  • Information security: they hold your data and get breached.
  • Legal and regulatory: a missing DPA or an unlawful transfer becomes your problem.
  • Reputational: their conduct on your site or in your name lands on you.
  • Concentration: five services from one supplier is one failure, not five.

A four-week rollout for a small team

  1. Week one: list every vendor you pay and what they do. Accounts payable is the fastest source.
  2. Week two: tier them. Twenty minutes of judgement beats a scoring matrix nobody trusts.
  3. Week three: request the evidence pack for critical and important tiers using one upload link each.
  4. Week four: set expiry reminders, agree who owns each vendor and diary the annual review.

How VRM sits alongside TPRM

'Vendor' typically means someone you pay. 'Third-party' includes vendors, partners, resellers and integrations. VRM is a subset of TPRM, and for many teams they're used interchangeably. If your auditor uses TPRM language, the same register and evidence answer both.

Signs your programme is working

  • You can name your critical vendors from memory and prove their evidence is current.
  • Nobody has to email a supplier to answer a client due-diligence question.
  • Expiries are noticed before the date, not after a rejected invoice.
  • The annual review is a one-hour meeting, not a fortnight of chasing.

Frequently asked questions

Your next step

Two ways to act on this guide right now - one hands-on, one to read next.

Put this into practice today.

Start a free Credbase workspace, add your first supplier and share a live document pack in ten minutes.