The short answer
A vendor management policy sets the rules for how your company selects, approves, contracts with, monitors, and exits third-party vendors. At minimum it should cover scope, roles, risk tiering, due diligence by tier, contract requirements, onboarding, performance monitoring, issue escalation, offboarding, and exceptions. Keep it short enough that a budget owner can find their obligations in two minutes.
On this page
- 1. Purpose and scope
- 2. Roles and responsibilities
- 3. Risk tiering
- 4. Due diligence requirements by tier
- 5. Contract requirements
- 6. Onboarding
- 7. Ongoing monitoring and performance
- 8. Issue management and escalation
- 9. Offboarding
- 10. Exceptions and enforcement
- Common mistakes that make a policy unenforceable
- Frequently asked questions
A vendor management policy fails in one of two ways. It is either a 40-page document nobody reads, or a two-paragraph statement that says "vendors must be approved" without saying by whom. Both leave you exposed when a vendor has a data breach and the auditor asks what your process was.
The structure below sits in the middle. It is built for US companies that answer to external auditors, regulators, or enterprise customers who send security questionnaires. If you are writing one from scratch, our step-by-step guide on how to write and roll out a vendor policy covers the drafting and approval process.
1. Purpose and scope
State why the policy exists and who it covers. Be specific about which relationships are in scope, because this is where most gaps start.
The card purchase line matters. A marketing team buying a $40-a-month SaaS tool that stores customer emails is a vendor relationship, even if it never touched a PO.
2. Roles and responsibilities
Name the roles, not the people, so the policy survives turnover. Most policies need at least four:
- Business owner: the person who requested the vendor and is accountable for the relationship day to day.
- Procurement or the vendor management office: runs the process, keeps records, and checks the policy was followed.
- Information security and privacy: reviews vendors that touch systems or personal data.
- Legal: approves contract terms outside the standard template.
A short RACI table in an appendix does more than a page of prose here.
3. Risk tiering
Tiering is the heart of the policy. It decides how much scrutiny each vendor gets, which keeps the process fast for low-risk vendors and thorough for the ones that could hurt you.
| Tier | Typical profile | Examples |
|---|---|---|
| Tier 1 (critical) | Access to sensitive data or systems, hard to replace, or tied to a regulated activity | Payroll provider, cloud hosting, payment processor |
| Tier 2 (high) | Limited data access or meaningful spend, replaceable within a quarter | Marketing automation tool, staffing agency |
| Tier 3 (moderate) | No sensitive data, moderate spend | Facilities services, event vendors |
| Tier 4 (low) | No data, low spend, easy to replace | Office supplies, catering |
Tier by the inherent risk of what the vendor does for you, not by how much you like them. Our vendor risk management guide goes deeper on scoring.
4. Due diligence requirements by tier
Spell out what each tier must provide before approval. A Tier 4 vendor might need a W-9 and a sanctions screen. A Tier 1 vendor might need a SOC 2 Type II report, financial statements, a business continuity plan, insurance certificates, and a completed security questionnaire.
Link to the actual checklist rather than copying it into the policy. Checklists change more often than policy. Our vendor due diligence checklist is a good starting point.
5. Contract requirements
List the clauses that must appear in every contract above a threshold, and the extra clauses required for Tier 1 and 2. Typical must-haves include confidentiality, data protection and breach notification timelines, right to audit, insurance minimums, subcontractor approval, termination rights, and return or destruction of data at exit.
If you are in a regulated industry, this section is where you map regulatory requirements. Healthcare companies need business associate agreements under HIPAA for vendors handling protected health information. Banks follow the 2023 interagency guidance on third-party risk from the Federal Reserve, FDIC, and OCC.
6. Onboarding
Cover what has to happen between contract signature and first payment: supplier master setup, bank detail verification, tax forms, system access provisioning, and a kickoff with the business owner. Bank detail verification deserves its own sentence in the policy. Payment fraud through changed vendor bank details is common enough that most finance teams now require a callback to a known phone number before any change. See the vendor onboarding checklist for the full sequence.
7. Ongoing monitoring and performance
State how often each tier is reviewed. A common pattern is annual reassessment for Tier 1, every two years for Tier 2, and on renewal for everything else. Add the triggers that force an early review, such as a reported breach, a change of ownership, or a missed SLA for two consecutive months.
Performance reviews belong here too. Our vendor performance management guide shows how to tie scorecards to contract terms.
8. Issue management and escalation
Say what happens when something goes wrong: who the business owner notifies, how fast, and who decides whether to suspend the vendor. Without this section, incidents get handled in hallway conversations and nothing is documented.
9. Offboarding
Exit is the most neglected stage. The policy should require revoking system access, confirming return or destruction of data in writing, settling final invoices, and marking the supplier inactive in the ERP so nobody pays them by accident six months later.
10. Exceptions and enforcement
Every policy needs a way to handle the urgent purchase that cannot wait for full review. Define who can approve an exception, how long it lasts, and where it is recorded. Then state what happens when someone ignores the policy, such as an invoice that will not be paid without a PO.
Common mistakes that make a policy unenforceable
- Writing rules nobody has the tools to follow. If the policy requires annual reviews but you have no system tracking review dates, the policy is fiction.
- Leaving out card and expense spend, which is where shadow SaaS lives.
- Tiering by spend alone. A $3,000 analytics tool with access to customer data is riskier than a $300,000 janitorial contract.
- Putting procedure detail in the policy. Keep the policy stable and link to procedures and checklists that can change.
A policy works when the process behind it is easy. Many teams pair the policy with a vendor management platform so tiering, reminders, and document collection happen without someone maintaining a spreadsheet.
Key takeaways
- Scope must include card-purchased SaaS and contractors, not only PO-backed vendors.
- Risk tiering decides how much diligence each vendor gets. Tier by inherent risk, not spend alone.
- Put required contract clauses in the policy and link to checklists that change more often.
- Offboarding and exceptions are the two sections most policies leave out.
Frequently asked questions
It is a formal document that sets the rules for selecting, approving, contracting with, monitoring, and exiting third-party vendors. It defines who is responsible for each step and how much review each vendor gets based on risk.
Usually the CFO or COO, with input from procurement, legal, information security, and internal audit. In regulated industries, a board risk committee may also approve it.
Review it at least once a year and whenever a regulation, major system, or organization structure changes. The linked procedures and checklists can be updated more often without re-approving the policy.
No single US law requires one for every company, but many rules make it effectively mandatory. Banks follow interagency third-party risk guidance, healthcare organizations need HIPAA business associate agreements, and public companies must describe how they manage cybersecurity risk from third-party service providers in SEC filings.
The policy states what must happen and who is accountable. Procedures describe how to do it step by step, including forms, systems, and checklists. Keeping them separate lets you update procedures without a full policy re-approval.
Make your vendor policy easy to follow
A policy only works when the process behind it is simple. Let us show you what that looks like for your vendor base.