Skip to content

Managing vendors after go-live

  • Any ERP

How-toIntermediate11 min read

View Markdown

In short. Give every vendor a named owner, record it in one register and tier it by how much damage its failure would do. Spend review time in proportion to the tier: quarterly business reviews and yearly reassessment for critical vendors, a renewal check 120 days out for everyone.

Written for Leaders, finance and operations, administrators.

Most vendor trouble after go-live comes from nobody watching: a renewal that rolls over at a higher price, an invoice for users who left a year ago, a subprocessor change nobody read, a support quality slide that everyone complains about and nobody raises. Managing vendors well takes four things: a named owner for each vendor, one register, a tier that sets how much attention each one gets and a calendar.

The table lists each practice, what it prevents and an invented estimate of the effort for a mid-sized distributor.

Practice What it prevents Effort (invented)
A named owner per vendor Issues and renewals falling between departments Minutes per vendor to assign
One vendor register Not knowing what you pay, to whom or who holds your data A few days to build, an hour a month to keep current
Tiering by criticality Treating a label printer like your ERP host, or the reverse One meeting
Business reviews for top tiers Slow service decline, surprises at renewal 1 to 2 hours per critical vendor per quarter
Scorecards and KPIs Arguments based on anecdotes Set up once, updated at each review
Renewal calendar starting 120 days out Auto-renewals and increases you did not choose 15 minutes a month
Invoice audit Paying for shelfware, wrong rates, duplicate charges A few hours a quarter
Annual reassessment Relying on a vendor whose risk changed Scaled by tier

The idea is not new. The FTC Safeguards Rule (16 CFR 314.4(f)) requires covered businesses to periodically assess service providers based on their risk. The 2023 interagency guidance for banks treats ongoing monitoring as a core stage of the relationship life cycle, and NIST CSF 2.0 includes supplier monitoring within its supply chain risk management category (GV.SC). You do not need to be regulated to borrow the method.

Step 1: give every vendor an owner

Section titled: Step 1: give every vendor an owner

The owner is the person who answers for the relationship: its value, its cost, its risk and its renewal. It is usually the manager of the team that uses the service most, rather than purchasing or IT by default. The table lists the roles around each vendor.

Role Responsibilities
Relationship owner Runs reviews, raises issues, recommends renew or exit, keeps the register row current
Executive sponsor (critical tier only) Escalation point, signs off on renewals and exits
Finance contact Budget, invoice approval, invoice audit
IT or security contact Access, integrations, security reviews, subprocessor notices
Backup owner Covers when the owner is out or leaves
  • Every vendor has a named owner and backup. A vendor without an owner is a vendor nobody will notice failing.
  • Owners know they are owners. Tell them in writing and put it in their role description.
  • Ownership moves when people move. Add vendor ownership to your leaver and role-change checklist.

Step 2: keep one vendor register

Section titled: Step 2: keep one vendor register

A vendor register is a single list of every third party you rely on, with the facts you need to manage it. A spreadsheet is fine to start. What matters is that there is one, and that someone keeps it current. Your accounts payable vendor list is a good starting point, plus anything paid by company card. The table lists the fields to record.

Field Example (invented) Why you need it
Vendor name and service Supplier A, parcel shipping software Identification
Category Software add-on, logistics, outsourced service, payments Reporting and comparison
Relationship owner and backup Warehouse manager, operations analyst Accountability
Tier 1, 2 or 3 (see below) Sets review depth
Business process supported Outbound shipping, all branches Impact if it fails
Data held or accessed Customer names and addresses Privacy and security risk
Systems integrated ERP order and shipment tables, via API Change and exit impact
Annual spend $36,000 Priority and audit
Contract start, term, renewal date 2025-03-01, 36 months, renews 2028-03-01 Renewal calendar
Notice period for non-renewal 90 days Calendar trigger
Price increase terms Capped at 5% a year Budget and negotiation
Liability cap and data terms summary 12 months fees, data export in CSV within 30 days Risk at a glance
Key documents Links to MSA, order form, DPA, latest SOC 2 report Speed when something goes wrong
Subprocessors or key fourth parties Public cloud host, label print service Concentration risk
Last review date and result 2026-06, green Oversight evidence
Exit plan summary Replacement candidates, export route, estimated switch time Readiness to leave
Users with access and admin accounts 22 users, 2 admins Access reviews and offboarding

Step 3: tier vendors by criticality

Section titled: Step 3: tier vendors by criticality

Tiering puts your attention where failure would hurt most. Ask two questions of each vendor: how badly would the business suffer if this vendor stopped for a week, and how sensitive is the data it holds? The table sets out three tiers.

Tier Definition Examples (categories) Oversight
1, critical Failure stops order-to-cash, shipping or finance, or the vendor holds sensitive data at scale ERP host or cloud publisher, payment processor, EDI provider, 3PL, managed IT provider Quarterly review, KPI scorecard, annual reassessment with SOC report, documented exit plan
2, important Failure causes real disruption with a workaround available, or moderate data exposure Sales tax engine, shipping software, CRM, e-commerce platform Semi-annual or annual review, annual security check, renewal review
3, routine Easily replaced, little or no sensitive data Office supplies, single-user tools, marketing subscriptions Renewal check and invoice audit only

Most mid-sized distributors end up with fewer than 15 tier 1 vendors. If you have 40, the definition is too loose. If you have two, check again for the ones you forgot, such as the managed IT provider with administrator access to everything. See Third-party risk management for a fuller risk method.

A quarterly business review (QBR) is a structured meeting with a critical vendor about performance, issues and plans. Vendors will try to turn it into a sales meeting, so you set the agenda.

  1. Send the agenda and your scorecard two weeks ahead. Ask the vendor to bring their own data for the same period.

  2. Review performance against the KPIs (15 minutes). Uptime, support tickets and resolution times, SLA misses and credits, volumes.

  3. Walk through open issues and escalations (15 minutes). Each with an owner and a date.

  4. Hear the vendor's changes (10 minutes). Product roadmap items that affect you, ownership or leadership changes, subprocessor changes, planned price or packaging changes.

  5. Share your changes (10 minutes). New branches, volume changes, projects that will touch their service.

  6. Agree actions (10 minutes). Written, owned, dated and reviewed at the start of the next QBR.

Set the cadence and attendance by tier.

Tier Review cadence Your attendees
1 Quarterly, plus an annual strategic review Owner, a user lead, IT contact, sponsor at least yearly
2 Semi-annual or annual Owner and a user lead
3 None, renewal check only Owner

Step 5: measure with scorecards and KPIs

Section titled: Step 5: measure with scorecards and KPIs

Pick five to eight measures per critical vendor, measured the same way each period. Where possible, measure from your own data rather than the vendor's report. The table suggests KPIs by vendor category.

Vendor category KPIs to track
Software or cloud service Uptime from your own monitoring, incidents affecting you, support response and resolution times, open defects, release problems
Logistics provider or 3PL On-time pickup and delivery, damage and claims rate, invoice accuracy, dock-to-stock time
Outsourced service (IT, payroll, collections) Tasks completed on time, error rate, escalations, staff turnover on your account
Payment or tax provider Transaction success rate, reconciliation breaks, filing timeliness

Score each KPI green, amber or red against the target in the contract or the one you agreed at the last review. Two consecutive reds on the same KPI go on the executive sponsor's desk.

Step 6: keep a renewal calendar that starts 120 days out

Section titled: Step 6: keep a renewal calendar that starts 120 days out

Renewals are where most money is saved or lost. The 120-day start is a rule of thumb. It leaves time to review, get competing quotes and negotiate before a typical 60 to 90 day notice window closes. The table sets out the countdown.

Days before renewal Action
120 Owner confirms the notice date from the contract and starts the renewal review
110 Pull usage: active users, volumes, modules in use
100 Scorecard summary and user feedback
90 Decide: renew as is, renegotiate or replace. If replacing, or to strengthen your position, request competing quotes
75 Negotiate: price, cap, term, rightsizing, any data or exit terms that were weak
60 Send written non-renewal or change notice if the contract needs it, even while still negotiating
30 Sign the renewal or confirm the exit plan is running
  • Every renewal date and notice date is in a shared calendar. A personal calendar leaves with the person.
  • Notice dates are calculated from the contract, not the invoice. Contracts often count from the effective date.
  • Notices are sent the way the contract requires. Some require written notice to a named address, and an email to the account manager may not count.

Invoice errors are common, rarely in your favor and easy to miss when the same amount auto-renews every month. A quarterly check of tier 1 and tier 2 invoices is enough for most companies.

  • Users or seats billed match active users. Compare with your own user list and remove leavers.
  • Rates match the contract and the cap. Increases above the cap are the most common finding.
  • No charges for modules or services you do not use. Shelfware builds up between renewals.
  • Usage charges match your own volume data. Transactions, shipments, API calls.
  • Credits owed were applied. SLA credits and negotiated credits often need chasing.
  • No duplicates. Check for the same invoice under two vendor records.
  • Freight and logistics bills are audited against rates. For carriers and 3PLs, accessorial charges are where errors cluster.

Vendors change things: subprocessors, terms of service, data center locations, product features, pricing packages, ownership. Many contracts let them do so by notice, often by email to whoever signed up years ago. The table lists common notices and the response to each.

Change notice What to do
New subprocessor Check what data it touches and where, and object within the window if the contract allows and it matters
Updated online terms Compare to the version you accepted and ask counsel about material changes
Product end of life or feature removal Assess impact, start a plan, check the contract for notice commitments
Price or packaging change Check against the cap and plan for the renewal
Acquisition or merger Check assignment and change-of-control clauses, and bring the next review forward
Security incident Follow your incident process and ask for a written report and actions
  • Vendor notices go to a shared mailbox, not a person. Update the notice contact with every vendor.
  • Someone reads that mailbox weekly. They route each notice to the owner.

Once a year, look at each tier 1 vendor as if you were choosing it again. The vendor has changed, and so have you.

  • Security evidence is current. A new SOC 2 report (check the period and any exceptions), or updated questionnaire answers.
  • Financial health and ownership are unchanged. If either changed, the change has been assessed.
  • The tier is still right. Usage grows, and a tier 2 vendor may now be critical.
  • Data held is still necessary. Ask the vendor to delete what you no longer need them to keep.
  • Access is reviewed. Vendor staff and integration accounts in your systems, and your users in theirs. See Security roles and access reviews.
  • The exit plan is still realistic. Replacement options, export tested, time to switch.
  • Their key providers are known. See Fourth parties and concentration risk.

A good vendor relationship is a working partnership. Vendors put their best people on customers who are clear, organized and fair. The table lists signs on each side.

Healthy sign Warning sign
Issues are raised early and in writing, and get owners Issues are raised only at renewal, all at once
The vendor tells you about problems before you find them You learn about incidents from your customers
Same account team for a year or more A new account manager every quarter
Escalations are rare and resolved Every ticket needs an escalation
You pay on time and give usable feedback Disputed invoices sit for months
Roadmap conversations include your needs Only sales pitches for new modules

These patterns are worth raising at the next review.

Red flag What it often means
Support response slipping for two or more quarters Staffing cuts or a shift of focus away from your product line
Repeated key staff departures on the vendor side Instability, often before or after an acquisition
Pressure to move to a new product or plan "by year end" End of life for what you use, or a price reset
SOC report late, qualified or suddenly unavailable Control problems
Invoices that change shape without a conversation Repackaging that usually costs more
The vendor cannot say which subprocessors hold your data They may not know

Questions to ask at every review

Section titled: Questions to ask at every review
  • What changed in your company, product or subprocessors since our last review?
  • Which of our open issues will be fixed, by whom and when?
  • What is on your roadmap that affects the features we use, including anything being retired?
  • What does our usage look like against our contract, and are we paying for things we do not use?
  • If we had to leave, how would we get our data out today, and has anything about that changed?

Build the register first, even if it has only the top 20 vendors by spend plus anyone who holds customer data or has access to your systems. Then assign an owner and a tier to each, put every renewal and notice date into a shared calendar with a 120-day reminder and book the first quarterly review with your most critical vendor.

For what the contract should already say, see Contracts, SLAs and data rights.

Sources