Home About
Vendor Management ⌄
Procurement ⌄
Reviews & Compare ⌄
Industries ⌄
Resources ⌄
Request Demo →
Vendor Risk & CompliancePillar GuideUpdated September 24, 2026

Vendor Risk and Compliance: How to Build a Program That Holds Up to Audit

Your vendors can expose your data, disrupt your operations, and create legal liability you never agreed to. This guide covers the program that keeps that exposure visible and managed.

The short answer

A vendor risk and compliance program identifies which third parties could harm your business, checks them before contracting, writes protections into contracts, monitors them over time, and documents all of it. For US companies, the requirements come from sector rules (banking, healthcare, public company disclosure, government contracting), privacy laws, and customer contracts. Tier vendors by risk so effort goes where exposure is highest.

On this page
  1. Which US requirements apply to you
  2. The program in six parts
  3. Compliance in sourcing, not just after it
  4. Who does what
  5. What auditors and examiners look for
  6. Tools that help
  7. Frequently asked questions

When a vendor causes a problem, regulators, customers, and plaintiffs rarely accept "it was the vendor's fault" as an answer. The data was yours, the customers were yours, and the decision to use that vendor was yours. That is the core reason vendor risk and compliance programs exist.

This page is the hub for our vendor risk and compliance content. It covers the program end to end, with links to deeper guides on each piece.

Which US requirements apply to you

There is no single US law requiring every company to manage vendor risk. Instead, requirements come from several directions, and most companies are subject to at least one.

SourceWho it affectsWhat it expects
Interagency Guidance on Third-Party Relationships (Federal Reserve, FDIC, OCC, 2023)Banks and their service providersRisk-based lifecycle management of third parties, from planning through termination
HIPAAHealthcare providers, health plans, and their business associatesBusiness associate agreements and safeguards for protected health information
SEC cybersecurity disclosure rules (Regulation S-K Item 106)Public companiesDescribing processes to oversee and identify cybersecurity risks from third-party service providers
SOX internal controlsPublic companiesControls over financial reporting, which extend to outsourced processes
State privacy laws such as the CCPACompanies handling residents' personal dataSpecific contract terms with service providers and contractors
Federal contracting rules (FAR, DFARS, CMMC)Government contractorsFlow-down clauses and cybersecurity requirements for subcontractors
Customer contracts and security questionnairesMost B2B companiesEvidence that you manage your own vendors responsibly

For industry-specific detail, see our pages on financial services vendor management and healthcare vendor management.

Frameworks help too. NIST's Cybersecurity Framework 2.0, released in 2024, added a Govern function that explicitly covers cybersecurity supply chain risk management. Many companies map their vendor program to it.

The program in six parts

1. Inventory and ownership

You cannot manage vendors you do not know about. Build a complete inventory from AP, card, and expense data, and assign a business owner to each vendor. Include SaaS tools bought on cards. They often hold more sensitive data than large contracted suppliers.

2. Risk tiering

Rate each vendor's inherent risk based on what it does for you: access to sensitive data, access to your systems, how critical the service is, regulatory relevance, and how hard it would be to replace. Most programs use three or four tiers. Tiering decides how much diligence and monitoring each vendor gets.

3. Due diligence before contracting

Match diligence to tier. Low-risk vendors might need only tax forms and a sanctions screen. Critical vendors typically need security evidence (such as a SOC 2 Type II report), financial review, business continuity plans, insurance certificates, and privacy review. Our vendor due diligence checklist lists what to request by tier.

4. Contract controls

Contracts turn diligence findings into enforceable obligations. Standard protections include confidentiality, data protection and breach notification timelines, audit rights, security requirements, subcontractor controls, insurance, and data return at exit. See contract terms procurement should negotiate for how to push on these.

5. Ongoing monitoring

Risk changes after signature. Reassess critical vendors at least yearly and watch for triggers between reviews: security incidents, ownership changes, financial distress, sanctions changes, or repeated service failures. Continuous monitoring tools can surface news, cyber ratings, and financial signals, but only for vendors you have tiered, or the alerts become noise.

6. Offboarding

Revoke access, confirm data return or destruction in writing, and close out the supplier record. Offboarding gaps are a frequent audit finding.

Compliance in sourcing, not just after it

Risk checks work best when they start before a supplier is chosen. Building security, legal, and compliance gates into sourcing events means suppliers who cannot meet requirements drop out early, before anyone gets attached to them. Our guide to strategic sourcing automation with compliance built in shows how that works in practice.

Who does what

  • Procurement or the vendor management office runs the process, keeps the inventory, and makes sure steps happen.
  • Information security reviews technical controls and security evidence.
  • Privacy and legal review data handling and contract terms.
  • Business owners manage the relationship and report issues.
  • Internal audit tests whether the program works as written.
  • The board or a risk committee oversees the program at larger or regulated companies.

A vendor management office often coordinates all of this at scale.

What auditors and examiners look for

Whether it is an internal audit, an external auditor, a bank examiner, or a customer's security team, the questions are similar:

  1. Is there a written policy, and does it match what actually happens? Our vendor management policy guide covers the document.
  2. Is the vendor inventory complete, including card-purchased SaaS?
  3. Are vendors tiered, and is diligence consistent with the tier?
  4. Are required contract terms present in critical vendor contracts?
  5. Are reassessments done on schedule, with evidence?
  6. Are issues tracked to resolution?
  7. Is offboarding documented?

A program that can answer these with records, not just policy language, is in good shape.

Tools that help

Spreadsheets work for a small vendor base. Beyond a few hundred vendors, most companies move to a vendor management or third-party risk platform that handles questionnaires, document collection with expiry dates, tiering, reassessment scheduling, and reporting. Our vendor risk management guide compares approaches, and our risk and compliance platform page shows how ProcurementVMS handles it.

Key takeaways

  • US vendor compliance requirements come from sector rules, SEC disclosure, privacy laws, government contracting, and customer contracts.
  • Tier vendors by inherent risk so diligence and monitoring match exposure.
  • Build compliance gates into sourcing so non-compliant suppliers drop out early.
  • Auditors want records that prove the policy is followed, not just a policy document.

Frequently asked questions

It is the process of identifying which third parties could harm your business, assessing them before contracting, building protections into contracts, monitoring them over time, and documenting that work for auditors, regulators, and customers.

Not for every company, but many are covered by sector rules. Banks follow interagency third-party guidance, healthcare organizations need HIPAA business associate agreements, public companies must describe third-party cybersecurity risk processes, and government contractors face flow-down requirements.

Critical vendors are commonly reassessed at least annually, high-risk vendors every one to two years, and others at renewal. Events such as a breach or ownership change should trigger an early review.

Typical evidence includes a SOC 2 Type II report or equivalent, a completed security questionnaire, insurance certificates, financial information, a business continuity plan, and privacy documentation such as a data processing agreement.

Vendor risk management focuses on identifying and reducing potential harm from vendors. Vendor compliance focuses on meeting legal, regulatory, and contractual requirements. In practice they run as one program.

Make vendor risk visible and manageable

Let us show you a vendor risk program running from inventory to offboarding, with the records auditors ask for.