The short answer
A vendor risk and compliance program identifies which third parties could harm your business, checks them before contracting, writes protections into contracts, monitors them over time, and documents all of it. For US companies, the requirements come from sector rules (banking, healthcare, public company disclosure, government contracting), privacy laws, and customer contracts. Tier vendors by risk so effort goes where exposure is highest.
On this page
When a vendor causes a problem, regulators, customers, and plaintiffs rarely accept "it was the vendor's fault" as an answer. The data was yours, the customers were yours, and the decision to use that vendor was yours. That is the core reason vendor risk and compliance programs exist.
This page is the hub for our vendor risk and compliance content. It covers the program end to end, with links to deeper guides on each piece.
Which US requirements apply to you
There is no single US law requiring every company to manage vendor risk. Instead, requirements come from several directions, and most companies are subject to at least one.
| Source | Who it affects | What it expects |
|---|---|---|
| Interagency Guidance on Third-Party Relationships (Federal Reserve, FDIC, OCC, 2023) | Banks and their service providers | Risk-based lifecycle management of third parties, from planning through termination |
| HIPAA | Healthcare providers, health plans, and their business associates | Business associate agreements and safeguards for protected health information |
| SEC cybersecurity disclosure rules (Regulation S-K Item 106) | Public companies | Describing processes to oversee and identify cybersecurity risks from third-party service providers |
| SOX internal controls | Public companies | Controls over financial reporting, which extend to outsourced processes |
| State privacy laws such as the CCPA | Companies handling residents' personal data | Specific contract terms with service providers and contractors |
| Federal contracting rules (FAR, DFARS, CMMC) | Government contractors | Flow-down clauses and cybersecurity requirements for subcontractors |
| Customer contracts and security questionnaires | Most B2B companies | Evidence that you manage your own vendors responsibly |
For industry-specific detail, see our pages on financial services vendor management and healthcare vendor management.
Frameworks help too. NIST's Cybersecurity Framework 2.0, released in 2024, added a Govern function that explicitly covers cybersecurity supply chain risk management. Many companies map their vendor program to it.
The program in six parts
1. Inventory and ownership
You cannot manage vendors you do not know about. Build a complete inventory from AP, card, and expense data, and assign a business owner to each vendor. Include SaaS tools bought on cards. They often hold more sensitive data than large contracted suppliers.
2. Risk tiering
Rate each vendor's inherent risk based on what it does for you: access to sensitive data, access to your systems, how critical the service is, regulatory relevance, and how hard it would be to replace. Most programs use three or four tiers. Tiering decides how much diligence and monitoring each vendor gets.
3. Due diligence before contracting
Match diligence to tier. Low-risk vendors might need only tax forms and a sanctions screen. Critical vendors typically need security evidence (such as a SOC 2 Type II report), financial review, business continuity plans, insurance certificates, and privacy review. Our vendor due diligence checklist lists what to request by tier.
4. Contract controls
Contracts turn diligence findings into enforceable obligations. Standard protections include confidentiality, data protection and breach notification timelines, audit rights, security requirements, subcontractor controls, insurance, and data return at exit. See contract terms procurement should negotiate for how to push on these.
5. Ongoing monitoring
Risk changes after signature. Reassess critical vendors at least yearly and watch for triggers between reviews: security incidents, ownership changes, financial distress, sanctions changes, or repeated service failures. Continuous monitoring tools can surface news, cyber ratings, and financial signals, but only for vendors you have tiered, or the alerts become noise.
6. Offboarding
Revoke access, confirm data return or destruction in writing, and close out the supplier record. Offboarding gaps are a frequent audit finding.
Compliance in sourcing, not just after it
Risk checks work best when they start before a supplier is chosen. Building security, legal, and compliance gates into sourcing events means suppliers who cannot meet requirements drop out early, before anyone gets attached to them. Our guide to strategic sourcing automation with compliance built in shows how that works in practice.
Who does what
- Procurement or the vendor management office runs the process, keeps the inventory, and makes sure steps happen.
- Information security reviews technical controls and security evidence.
- Privacy and legal review data handling and contract terms.
- Business owners manage the relationship and report issues.
- Internal audit tests whether the program works as written.
- The board or a risk committee oversees the program at larger or regulated companies.
A vendor management office often coordinates all of this at scale.
What auditors and examiners look for
Whether it is an internal audit, an external auditor, a bank examiner, or a customer's security team, the questions are similar:
- Is there a written policy, and does it match what actually happens? Our vendor management policy guide covers the document.
- Is the vendor inventory complete, including card-purchased SaaS?
- Are vendors tiered, and is diligence consistent with the tier?
- Are required contract terms present in critical vendor contracts?
- Are reassessments done on schedule, with evidence?
- Are issues tracked to resolution?
- Is offboarding documented?
A program that can answer these with records, not just policy language, is in good shape.
Tools that help
Spreadsheets work for a small vendor base. Beyond a few hundred vendors, most companies move to a vendor management or third-party risk platform that handles questionnaires, document collection with expiry dates, tiering, reassessment scheduling, and reporting. Our vendor risk management guide compares approaches, and our risk and compliance platform page shows how ProcurementVMS handles it.
Key takeaways
- US vendor compliance requirements come from sector rules, SEC disclosure, privacy laws, government contracting, and customer contracts.
- Tier vendors by inherent risk so diligence and monitoring match exposure.
- Build compliance gates into sourcing so non-compliant suppliers drop out early.
- Auditors want records that prove the policy is followed, not just a policy document.
Frequently asked questions
It is the process of identifying which third parties could harm your business, assessing them before contracting, building protections into contracts, monitoring them over time, and documenting that work for auditors, regulators, and customers.
Not for every company, but many are covered by sector rules. Banks follow interagency third-party guidance, healthcare organizations need HIPAA business associate agreements, public companies must describe third-party cybersecurity risk processes, and government contractors face flow-down requirements.
Critical vendors are commonly reassessed at least annually, high-risk vendors every one to two years, and others at renewal. Events such as a breach or ownership change should trigger an early review.
Typical evidence includes a SOC 2 Type II report or equivalent, a completed security questionnaire, insurance certificates, financial information, a business continuity plan, and privacy documentation such as a data processing agreement.
Vendor risk management focuses on identifying and reducing potential harm from vendors. Vendor compliance focuses on meeting legal, regulatory, and contractual requirements. In practice they run as one program.
Make vendor risk visible and manageable
Let us show you a vendor risk program running from inventory to offboarding, with the records auditors ask for.