Classify a vendor by risk tier before selecting diligence and governance requirements.
The reframe: Small contract does not mean small risk. Data Sensitivity A vendor that stores personal, financial, health, employee, source code, or customer data deserves more diligence than its price may suggest. Operational Criticality Ask what breaks if the vendor is down for a day. Payroll, identity, payments, safety, and customer-facing services require stronger SLAs and continuity proof. Replaceability A vendor is riskier when switching takes months, integrations are deep, or internal teams cannot run a workaround. Extended Supply Chain Subprocessors, subcontractors, cloud dependencies, and offshore support can change the risk picture. Tiering should include the vendor's dependencies, not just…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in