Skip to main content

Vendor management

Vendor Management is your register of external AI suppliers and services: details, review status, a score from sensitivity and criticality, linked use cases, and vendor-specific risks.

Open Governance → Vendor Management in the sidebar.

This is not the organisation Risk Register. Vendor risks on this page are separate rows attached to a vendor.


What you see​

Chips at the top: Vendors, Vendor risks, and risk-level counts (Very high, High, Medium, Low).

Two areas:

AreaPurpose
Vendor directoryThe vendor table — add, edit, or delete.
Vendor risksRisks logged against vendors.

Vendor directory​

Search by vendor name. Table typically shows name (and website), applicable use cases, review status, vendor score, assignee, and review date.

Add new vendor — Admin and Editor. If your plan does not allow more records, you are asked to upgrade.

⋯ menu: Edit for people who can open the menu; Delete for Admin only.

Vendor form​

  • Identity: name, website, what they provide
  • People: assignee, reviewer, owner
  • Review: status, date, result
  • Scorecard: data sensitivity, business criticality, past issues, regulatory exposure — these feed the vendor score
  • Applicable use cases (AI projects)
  • Description, contact, and risk notes when shown

Review status examples: Not reviewed, In review, Reviewed, Approved, Rejected.


Vendor risks​

Risks attached to a vendor: description, impact, likelihood, severity, and a derived risk level. Search and paginate like the directory.

Add vendor risk — Admin / Editor. Changing likelihood or severity updates the stored risk level.

Delete on a vendor risk is available to Admin and Editor (unlike deleting a vendor, which is Admin only).