- Vendor
- Any external company or individual that provides goods, services, or software to the organization in exchange for payment.
- Preferred Vendor List
- A pre-approved roster of suppliers that have passed due diligence and can be engaged without a full re-evaluation process.
- Due Diligence
- The process of investigating a prospective vendor's financial stability, compliance status, security posture, and operational capacity before awarding a contract.
- Vendor Tiering
- A classification system that groups vendors by spend level, criticality, or risk β typically Tier 1 (critical), Tier 2 (significant), and Tier 3 (low-risk) β to calibrate oversight effort.
- KPI (Key Performance Indicator)
- A measurable metric used to evaluate whether a vendor is meeting agreed service, quality, or delivery standards.
- SLA (Service Level Agreement)
- A contractual commitment that defines the minimum performance standards a vendor must meet, including uptime, response times, or defect rates.
- Vendor Offboarding
- The formal process of terminating a vendor relationship, including contract close-out, data deletion, access revocation, and transition of services.
- Concentration Risk
- Operational exposure that arises when a company relies on a single vendor or a small number of vendors for a critical function, leaving it vulnerable if one fails.
- Fourth-Party Risk
- Risk introduced by a vendor's own suppliers or subcontractors β parties the organization has no direct relationship with but whose failures can affect service delivery.
- Remediation Plan
- A documented corrective action plan issued to a vendor when performance falls below agreed thresholds, specifying what must change and by when.