Decision questions Questions buyers ask before starting
What is vendor risk tiering?
Tiering assigns review depth based on inherent exposure such as data sensitivity, privileged access, criticality, connectivity, regulatory impact, and substitutability. It prevents low-risk vendors from consuming the same effort as critical suppliers.
How often should critical vendors be reviewed?
Frequency should be risk-based and event-driven. High-impact vendors typically need periodic review plus triggers for incidents, major service changes, ownership changes, material subprocessor changes, or contract renewal.