Back to 360 Playbooks
Account & Programsintermediate
Vendor Risk Lifecycle
Onboard vendors, monitor unlocked portfolios, run annual reviews, and handle incidents.
SecurityAudit360 Team
6/25/2026
6 min read
tprmworkflowvendor-riskgrc
Vendor Risk Lifecycle
Who this is for: GRC and procurement owners running a third-party risk program.
What you'll learn:
- Onboard → assess → decide → monitor → offboard
- Which dashboard tools fit each phase
- Tiering unlock spend
Phase 1 — Discover & tier
- Define critical / important / low vendors.
- Browse and search or use
/assessments. - Record baseline grade.
- Request indexing if missing.
Phase 2 — Assess & unlock
- Unlock critical tier within quota.
- Read profile + findings.
- Map supply chain for critical vendors.
- Add reputation review for customer-facing suppliers.
Phase 3 — Decide & document
| Grade / findings | Typical action |
|---|---|
| A–B, no criticals | Proceed with standard controls |
| C with isolated highs | Conditional approval + deadline |
| D–F or critical exposure | Escalate or alternate vendor |
Export PDF for committee records.
Phase 4 — Monitor
- Keep active vendors in Unlocked Profiles
- Watch rating alerts and re-scan (Pro+)
- Annual refresh: re-benchmark with Competitor Analysis
- Re-audit after vendor M&A or cloud migration
Phase 5 — Offboard
Export final PDF snapshot; retain per your retention policy; free unlock slot if your process allows.
Related articles
Last updated: 6/25/2026