Back to 360 Playbooks
Account & Programsintermediate

Vendor Risk Lifecycle

Onboard vendors, monitor unlocked portfolios, run annual reviews, and handle incidents.

SecurityAudit360 Team
6/25/2026
6 min read
tprmworkflowvendor-riskgrc

Vendor Risk Lifecycle

Who this is for: GRC and procurement owners running a third-party risk program.

What you'll learn:

  • Onboard → assess → decide → monitor → offboard
  • Which dashboard tools fit each phase
  • Tiering unlock spend

Phase 1 — Discover & tier

  1. Define critical / important / low vendors.
  2. Browse and search or use /assessments.
  3. Record baseline grade.
  4. Request indexing if missing.

Phase 2 — Assess & unlock

  1. Unlock critical tier within quota.
  2. Read profile + findings.
  3. Map supply chain for critical vendors.
  4. Add reputation review for customer-facing suppliers.

Phase 3 — Decide & document

Grade / findings Typical action
A–B, no criticals Proceed with standard controls
C with isolated highs Conditional approval + deadline
D–F or critical exposure Escalate or alternate vendor

Export PDF for committee records.

Phase 4 — Monitor

  • Keep active vendors in Unlocked Profiles
  • Watch rating alerts and re-scan (Pro+)
  • Annual refresh: re-benchmark with Competitor Analysis
  • Re-audit after vendor M&A or cloud migration

Phase 5 — Offboard

Export final PDF snapshot; retain per your retention policy; free unlock slot if your process allows.

Related articles

Still stuck? Support · FAQs

Last updated: 6/25/2026