Vendor Risk Reviews Are Broken. Here's a Better Workflow.
Here’s how vendor risk management works at most companies: a 200-question spreadsheet goes out to every vendor once a year. Some answers come back weeks later, mostly copied from last year. Someone skims them, files them in a shared drive, and marks the review “complete.” Meanwhile, the vendor that matters most — the one with production database access — shipped a breach notification to an inbox nobody monitors.
The ritual satisfies the checkbox. It doesn’t manage the risk. Frameworks agree that it should: SOC 2 expects vendor oversight, ISO 27001 Annex A addresses supplier relationships, HIPAA requires business associate agreements, and GDPR’s Article 28 makes controllers accountable for their processors. But none of them require the specific ritual we’ve all inherited. Here’s a workflow that meets the requirements and actually reduces risk.
Why the traditional model fails
- Uniform depth, regardless of risk. The marketing swag vendor and the data warehouse provider get the same questionnaire. One is over-reviewed; the other is under-reviewed.
- Point-in-time answers for continuous relationships. A vendor’s posture in January says little about October. Subprocessors change, certifications lapse, incidents happen.
- Questionnaires nobody reads. Long questionnaires produce long answers that no one has time to evaluate, so review becomes filing.
- No connection to reality. The review lives in a drive; the vendor’s actual access lives in your identity provider. The two are never reconciled — which is how offboarded vendors keep API keys.
A better workflow, in four moves
1. Tier by data access and business impact
Before asking vendors anything, classify them on two axes: what data they touch (none, internal, confidential, regulated) and how badly their failure would hurt (inconvenience, degraded operations, existential). Three or four tiers is plenty:
- Critical: production data access or single points of failure
- High: confidential data or important operational dependence
- Moderate: limited internal data, easy to replace
- Low: no meaningful data access
Tiering is the highest-leverage hour in vendor risk. Everything downstream — review depth, cadence, contract terms — flows from it.
2. Match diligence to the tier
Critical vendors warrant real scrutiny: an independent audit report (such as a SOC 2 Type II) reviewed with attention to exceptions and scope, a targeted follow-up on the gaps, security and privacy contract terms, and a look at their subprocessor list. Moderate vendors might need only proof of certification and a short questionnaire. Low-tier vendors need a record that you decided they’re low tier — and nothing more. Shorter, sharper diligence gets read; encyclopedic diligence gets filed.
3. Review continuously, not annually
Replace the annual big bang with triggers and cadences:
- Cadence by tier: critical vendors annually with depth, high semi-annually or annually, moderate every two years
- Event triggers: a reported incident, a lapsed certification, a subprocessor change, a scope expansion, a renewal
- Certificate tracking: log expiry dates for audit reports and certifications, and chase renewals automatically
4. Tie reviews to offboarding and access
A vendor review program that never revokes anything is theater. Connect the vendor inventory to reality: every vendor record should note what access it has (SSO app, API keys, network paths, data shares), and offboarding a vendor should be a checklist that ends with access verifiably removed. When a 300-person logistics software company ran this reconciliation for the first time, they found active credentials for eleven vendors whose contracts had ended — a finding no questionnaire would ever surface.
Making it stick
The workflow above fails in a spreadsheet for the same reason everything else does: no owners, no reminders, no audit trail. It succeeds when the vendor inventory, tiering, review tasks, evidence, and expiry tracking live in one system that nags the right person at the right time.
That’s how vendor risk works in ComplianceDL: vendors are tiered once, review tasks generate themselves on the right cadence, uploaded audit reports and DPAs carry expiry alerts, and every review satisfies the vendor-management requirements of each framework in scope simultaneously. The work you’re already obligated to do finally accumulates into a defensible record.
Start small: tier your current vendor list this week. Most teams discover they have fewer than a dozen vendors that truly matter — and that they’ve been spending their review effort almost everywhere else.