Vendor management
Vendor Management is your register of external AI suppliers and services: details, review status, a score from sensitivity and criticality, linked use cases, and vendor-specific risks.
Open Governance → Vendor Management in the sidebar.
This is not the organisation Risk Register. Vendor risks on this page are separate rows attached to a vendor.
What you see
Chips at the top: Vendors, Vendor risks, and risk-level counts (Very high, High, Medium, Low).
Two areas:
| Area | Purpose |
|---|---|
| Vendor directory | The vendor table — add, edit, or delete. |
| Vendor risks | Risks logged against vendors. |
Vendor directory
Search by vendor name. Table typically shows name (and website), applicable use cases, review status, vendor score, assignee, and review date.
Add new vendor — Admin and Editor. If your plan does not allow more records, you are asked to upgrade.
⋯ menu: Edit for people who can open the menu; Delete for Admin only.
Vendor form
- Identity: name, website, what they provide
- People: assignee, reviewer, owner
- Review: status, date, result
- Scorecard: data sensitivity, business criticality, past issues, regulatory exposure — these feed the vendor score
- Applicable use cases (AI projects)
- Description, contact, and risk notes when shown
Review status examples: Not reviewed, In review, Reviewed, Approved, Rejected.
Vendor risks
Risks attached to a vendor: description, impact, likelihood, severity, and a derived risk level. Search and paginate like the directory.
Add vendor risk — Admin / Editor. Changing likelihood or severity updates the stored risk level.
Delete on a vendor risk is available to Admin and Editor (unlike deleting a vendor, which is Admin only).