Common questions
What is vendor governance in simple terms?
Vendor governance is the set of rules about who decides what regarding a vendor, on what evidence, and how often those decisions are revisited. In practice it is six artefacts — an inventory, a tiering model, a risk register, a contract register, an evidence file and a decision log — each with a named owner and a review cadence.
What is the difference between vendor governance and vendor management?
Vendor management asks whether a vendor is delivering and is run continuously by the relationship owner. Vendor governance asks whether the organisation should still accept the exposure, and is exercised by a forum with the authority to stop something. Management produces performance data; governance produces recorded decisions with named owners and expiry dates.
Who should own vendor governance?
A named risk owner in the business for each vendor, with a central function maintaining the artefacts and convening the forum. The one rule that matters is that residual risk acceptance is accountable to the forum rather than to the budget holder who wants the vendor — otherwise the framework has no ability to say no.
How often should vendor governance reviews happen?
Quarterly register review for critical vendors, monthly sweeps for expiring evidence, annual re-tiering and questionnaire refresh across the population, plus defined event triggers: breach, change of ownership, sanctions listing, material change of service, or an adverse audit finding. The event triggers catch more real failures than the calendar does.
What is the minimum viable vendor governance framework?
A vendor list that is complete, a tiering rule based on consequence rather than spend, a named risk owner per tier 1 and tier 2 vendor, expiry dates recorded against every piece of assurance evidence, and an append-only decision log. That is achievable in a spreadsheet and outperforms a detailed policy nobody operates.
Does a small company need vendor governance?
It needs the tiering and the decision log, and can reasonably skip the rest until the vendor population grows. A ten-person company with two critical vendors still has to be able to say who accepted the residual risk on those two and when that acceptance lapses. Contractual obligations under GDPR Article 28 apply regardless of headcount.