Managing vendors after go-live
In short. Give every vendor a named owner, record it in one register and tier it by how much damage its failure would do. Spend review time in proportion to the tier: quarterly business reviews and yearly reassessment for critical vendors, a renewal check 120 days out for everyone.
Written for Leaders, finance and operations, administrators.
Most vendor trouble after go-live comes from nobody watching: a renewal that rolls over at a higher price, an invoice for users who left a year ago, a subprocessor change nobody read, a support quality slide that everyone complains about and nobody raises. Managing vendors well takes four things: a named owner for each vendor, one register, a tier that sets how much attention each one gets and a calendar.
Vendor management at a glance
Section titled: Vendor management at a glanceThe table lists each practice, what it prevents and an invented estimate of the effort for a mid-sized distributor.
| Practice | What it prevents | Effort (invented) |
|---|---|---|
| A named owner per vendor | Issues and renewals falling between departments | Minutes per vendor to assign |
| One vendor register | Not knowing what you pay, to whom or who holds your data | A few days to build, an hour a month to keep current |
| Tiering by criticality | Treating a label printer like your ERP host, or the reverse | One meeting |
| Business reviews for top tiers | Slow service decline, surprises at renewal | 1 to 2 hours per critical vendor per quarter |
| Scorecards and KPIs | Arguments based on anecdotes | Set up once, updated at each review |
| Renewal calendar starting 120 days out | Auto-renewals and increases you did not choose | 15 minutes a month |
| Invoice audit | Paying for shelfware, wrong rates, duplicate charges | A few hours a quarter |
| Annual reassessment | Relying on a vendor whose risk changed | Scaled by tier |
The idea is not new. The FTC Safeguards Rule (16 CFR 314.4(f)) requires covered businesses to periodically assess service providers based on their risk. The 2023 interagency guidance for banks treats ongoing monitoring as a core stage of the relationship life cycle, and NIST CSF 2.0 includes supplier monitoring within its supply chain risk management category (GV.SC). You do not need to be regulated to borrow the method.
Step 1: give every vendor an owner
Section titled: Step 1: give every vendor an ownerThe owner is the person who answers for the relationship: its value, its cost, its risk and its renewal. It is usually the manager of the team that uses the service most, rather than purchasing or IT by default. The table lists the roles around each vendor.
| Role | Responsibilities |
|---|---|
| Relationship owner | Runs reviews, raises issues, recommends renew or exit, keeps the register row current |
| Executive sponsor (critical tier only) | Escalation point, signs off on renewals and exits |
| Finance contact | Budget, invoice approval, invoice audit |
| IT or security contact | Access, integrations, security reviews, subprocessor notices |
| Backup owner | Covers when the owner is out or leaves |
- Every vendor has a named owner and backup. A vendor without an owner is a vendor nobody will notice failing.
- Owners know they are owners. Tell them in writing and put it in their role description.
- Ownership moves when people move. Add vendor ownership to your leaver and role-change checklist.
Step 2: keep one vendor register
Section titled: Step 2: keep one vendor registerA vendor register is a single list of every third party you rely on, with the facts you need to manage it. A spreadsheet is fine to start. What matters is that there is one, and that someone keeps it current. Your accounts payable vendor list is a good starting point, plus anything paid by company card. The table lists the fields to record.
| Field | Example (invented) | Why you need it |
|---|---|---|
| Vendor name and service | Supplier A, parcel shipping software | Identification |
| Category | Software add-on, logistics, outsourced service, payments | Reporting and comparison |
| Relationship owner and backup | Warehouse manager, operations analyst | Accountability |
| Tier | 1, 2 or 3 (see below) | Sets review depth |
| Business process supported | Outbound shipping, all branches | Impact if it fails |
| Data held or accessed | Customer names and addresses | Privacy and security risk |
| Systems integrated | ERP order and shipment tables, via API | Change and exit impact |
| Annual spend | $36,000 | Priority and audit |
| Contract start, term, renewal date | 2025-03-01, 36 months, renews 2028-03-01 | Renewal calendar |
| Notice period for non-renewal | 90 days | Calendar trigger |
| Price increase terms | Capped at 5% a year | Budget and negotiation |
| Liability cap and data terms summary | 12 months fees, data export in CSV within 30 days | Risk at a glance |
| Key documents | Links to MSA, order form, DPA, latest SOC 2 report | Speed when something goes wrong |
| Subprocessors or key fourth parties | Public cloud host, label print service | Concentration risk |
| Last review date and result | 2026-06, green | Oversight evidence |
| Exit plan summary | Replacement candidates, export route, estimated switch time | Readiness to leave |
| Users with access and admin accounts | 22 users, 2 admins | Access reviews and offboarding |
Step 3: tier vendors by criticality
Section titled: Step 3: tier vendors by criticalityTiering puts your attention where failure would hurt most. Ask two questions of each vendor: how badly would the business suffer if this vendor stopped for a week, and how sensitive is the data it holds? The table sets out three tiers.
| Tier | Definition | Examples (categories) | Oversight |
|---|---|---|---|
| 1, critical | Failure stops order-to-cash, shipping or finance, or the vendor holds sensitive data at scale | ERP host or cloud publisher, payment processor, EDI provider, 3PL, managed IT provider | Quarterly review, KPI scorecard, annual reassessment with SOC report, documented exit plan |
| 2, important | Failure causes real disruption with a workaround available, or moderate data exposure | Sales tax engine, shipping software, CRM, e-commerce platform | Semi-annual or annual review, annual security check, renewal review |
| 3, routine | Easily replaced, little or no sensitive data | Office supplies, single-user tools, marketing subscriptions | Renewal check and invoice audit only |
Most mid-sized distributors end up with fewer than 15 tier 1 vendors. If you have 40, the definition is too loose. If you have two, check again for the ones you forgot, such as the managed IT provider with administrator access to everything. See Third-party risk management for a fuller risk method.
Step 4: run business reviews
Section titled: Step 4: run business reviewsA quarterly business review (QBR) is a structured meeting with a critical vendor about performance, issues and plans. Vendors will try to turn it into a sales meeting, so you set the agenda.
-
Send the agenda and your scorecard two weeks ahead. Ask the vendor to bring their own data for the same period.
-
Review performance against the KPIs (15 minutes). Uptime, support tickets and resolution times, SLA misses and credits, volumes.
-
Walk through open issues and escalations (15 minutes). Each with an owner and a date.
-
Hear the vendor's changes (10 minutes). Product roadmap items that affect you, ownership or leadership changes, subprocessor changes, planned price or packaging changes.
-
Share your changes (10 minutes). New branches, volume changes, projects that will touch their service.
-
Agree actions (10 minutes). Written, owned, dated and reviewed at the start of the next QBR.
Set the cadence and attendance by tier.
| Tier | Review cadence | Your attendees |
|---|---|---|
| 1 | Quarterly, plus an annual strategic review | Owner, a user lead, IT contact, sponsor at least yearly |
| 2 | Semi-annual or annual | Owner and a user lead |
| 3 | None, renewal check only | Owner |
Step 5: measure with scorecards and KPIs
Section titled: Step 5: measure with scorecards and KPIsPick five to eight measures per critical vendor, measured the same way each period. Where possible, measure from your own data rather than the vendor's report. The table suggests KPIs by vendor category.
| Vendor category | KPIs to track |
|---|---|
| Software or cloud service | Uptime from your own monitoring, incidents affecting you, support response and resolution times, open defects, release problems |
| Logistics provider or 3PL | On-time pickup and delivery, damage and claims rate, invoice accuracy, dock-to-stock time |
| Outsourced service (IT, payroll, collections) | Tasks completed on time, error rate, escalations, staff turnover on your account |
| Payment or tax provider | Transaction success rate, reconciliation breaks, filing timeliness |
Score each KPI green, amber or red against the target in the contract or the one you agreed at the last review. Two consecutive reds on the same KPI go on the executive sponsor's desk.
Step 6: keep a renewal calendar that starts 120 days out
Section titled: Step 6: keep a renewal calendar that starts 120 days outRenewals are where most money is saved or lost. The 120-day start is a rule of thumb. It leaves time to review, get competing quotes and negotiate before a typical 60 to 90 day notice window closes. The table sets out the countdown.
| Days before renewal | Action |
|---|---|
| 120 | Owner confirms the notice date from the contract and starts the renewal review |
| 110 | Pull usage: active users, volumes, modules in use |
| 100 | Scorecard summary and user feedback |
| 90 | Decide: renew as is, renegotiate or replace. If replacing, or to strengthen your position, request competing quotes |
| 75 | Negotiate: price, cap, term, rightsizing, any data or exit terms that were weak |
| 60 | Send written non-renewal or change notice if the contract needs it, even while still negotiating |
| 30 | Sign the renewal or confirm the exit plan is running |
- Every renewal date and notice date is in a shared calendar. A personal calendar leaves with the person.
- Notice dates are calculated from the contract, not the invoice. Contracts often count from the effective date.
- Notices are sent the way the contract requires. Some require written notice to a named address, and an email to the account manager may not count.
Step 7: audit invoices
Section titled: Step 7: audit invoicesInvoice errors are common, rarely in your favor and easy to miss when the same amount auto-renews every month. A quarterly check of tier 1 and tier 2 invoices is enough for most companies.
- Users or seats billed match active users. Compare with your own user list and remove leavers.
- Rates match the contract and the cap. Increases above the cap are the most common finding.
- No charges for modules or services you do not use. Shelfware builds up between renewals.
- Usage charges match your own volume data. Transactions, shipments, API calls.
- Credits owed were applied. SLA credits and negotiated credits often need chasing.
- No duplicates. Check for the same invoice under two vendor records.
- Freight and logistics bills are audited against rates. For carriers and 3PLs, accessorial charges are where errors cluster.
Step 8: handle change notices
Section titled: Step 8: handle change noticesVendors change things: subprocessors, terms of service, data center locations, product features, pricing packages, ownership. Many contracts let them do so by notice, often by email to whoever signed up years ago. The table lists common notices and the response to each.
| Change notice | What to do |
|---|---|
| New subprocessor | Check what data it touches and where, and object within the window if the contract allows and it matters |
| Updated online terms | Compare to the version you accepted and ask counsel about material changes |
| Product end of life or feature removal | Assess impact, start a plan, check the contract for notice commitments |
| Price or packaging change | Check against the cap and plan for the renewal |
| Acquisition or merger | Check assignment and change-of-control clauses, and bring the next review forward |
| Security incident | Follow your incident process and ask for a written report and actions |
- Vendor notices go to a shared mailbox, not a person. Update the notice contact with every vendor.
- Someone reads that mailbox weekly. They route each notice to the owner.
Step 9: reassess each year
Section titled: Step 9: reassess each yearOnce a year, look at each tier 1 vendor as if you were choosing it again. The vendor has changed, and so have you.
- Security evidence is current. A new SOC 2 report (check the period and any exceptions), or updated questionnaire answers.
- Financial health and ownership are unchanged. If either changed, the change has been assessed.
- The tier is still right. Usage grows, and a tier 2 vendor may now be critical.
- Data held is still necessary. Ask the vendor to delete what you no longer need them to keep.
- Access is reviewed. Vendor staff and integration accounts in your systems, and your users in theirs. See Security roles and access reviews.
- The exit plan is still realistic. Replacement options, export tested, time to switch.
- Their key providers are known. See Fourth parties and concentration risk.
Keep the relationship healthy
Section titled: Keep the relationship healthyA good vendor relationship is a working partnership. Vendors put their best people on customers who are clear, organized and fair. The table lists signs on each side.
| Healthy sign | Warning sign |
|---|---|
| Issues are raised early and in writing, and get owners | Issues are raised only at renewal, all at once |
| The vendor tells you about problems before you find them | You learn about incidents from your customers |
| Same account team for a year or more | A new account manager every quarter |
| Escalations are rare and resolved | Every ticket needs an escalation |
| You pay on time and give usable feedback | Disputed invoices sit for months |
| Roadmap conversations include your needs | Only sales pitches for new modules |
Red flags after go-live
Section titled: Red flags after go-liveThese patterns are worth raising at the next review.
| Red flag | What it often means |
|---|---|
| Support response slipping for two or more quarters | Staffing cuts or a shift of focus away from your product line |
| Repeated key staff departures on the vendor side | Instability, often before or after an acquisition |
| Pressure to move to a new product or plan "by year end" | End of life for what you use, or a price reset |
| SOC report late, qualified or suddenly unavailable | Control problems |
| Invoices that change shape without a conversation | Repackaging that usually costs more |
| The vendor cannot say which subprocessors hold your data | They may not know |
Questions to ask at every review
Section titled: Questions to ask at every review- What changed in your company, product or subprocessors since our last review?
- Which of our open issues will be fixed, by whom and when?
- What is on your roadmap that affects the features we use, including anything being retired?
- What does our usage look like against our contract, and are we paying for things we do not use?
- If we had to leave, how would we get our data out today, and has anything about that changed?
Next steps
Section titled: Next stepsBuild the register first, even if it has only the top 20 vendors by spend plus anyone who holds customer data or has access to your systems. Then assign an owner and a tier to each, put every renewal and notice date into a shared calendar with a 120-day reminder and book the first quarterly review with your most critical vendor.
For what the contract should already say, see Contracts, SLAs and data rights.
Sources
- Interagency Guidance on Third-Party Relationships: Risk Management (Federal Reserve, FDIC, OCC, June 2023)
- 16 CFR 314.4, FTC Safeguards Rule elements, including periodic assessment of service providers (eCFR)
- The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 (GV.SC supply chain risk management category)
- SOC 2 and SOC for Service Organizations (AICPA and CIMA)