Skip to main content
Vendor Governance

How Often Should Vendors Be Reassessed?

In brief

Set review frequency from residual risk and criticality, then add event triggers. Trigger review for expiry, incidents, ownership, access and scope changes.

Direct answer: Set a justified review schedule for each vendor relationship and add triggers for material changes. A calendar date is a planning control; it should not postpone a review required by a new incident, changed access or another applicable obligation.

Start with the relationship's exposure

Describe what the supplier does, how difficult it is to replace and what information, systems or sites it can access. Consider the effect of failure, not just annual spend. A modestly priced service can still be critical if it supports a process the business cannot readily perform elsewhere.

Ask the relevant policy and specialist owners to define the review basis. Record any contractual or applicable regulatory requirements separately from an internal risk-based schedule. This guide does not prescribe a universal annual, quarterly or monthly interval.

Separate scheduled review from monitoring

A periodic reassessment can revisit the overall relationship, while monitoring identifies signals that may need action sooner. Document which events each mechanism is intended to detect. Do not describe a scheduled questionnaire as continuous monitoring if nobody checks for changes between reviews.

Give alerts an owner and a route to resolution. A dashboard showing expired evidence is not an effective control if the responsible team does not receive or act on the information. Keep the decision and resulting action with the alert record.

Use specific event triggers

Examples for policy consideration include ownership changes, serious service incidents, a new subcontractor, expanded system access and a move into another service category. Identify who is expected to report each change and how procurement will learn about it.

Determine whether the event requires a targeted review or a broader reassessment. A changed support contact may need a different response from a new hosting arrangement involving customer data. Specialists should decide the affected controls rather than automatically repeating every questionnaire.

Close the review with a decision

Compare current evidence with the prior assessment and identify what has changed. Record unresolved items, conditions and any revised permission. Keep an unchanged outcome explicit so the next reviewer can distinguish a completed review from one that was never started.

Set the next review date with its rationale. Where a case is overdue, escalate according to policy rather than silently moving the date forward. If service must continue while a question is resolved, use the approved exception route and make its limits visible.

Measure whether the schedule works

Track overdue reviews, unassigned alerts and material changes discovered only after an incident. Examine whether high-volume low-risk checks are consuming capacity needed for critical cases. Adjust the process through accountable policy review, with evidence of what the earlier schedule missed or handled poorly.

How Vendoreye supports this workflow

Vendoreye can coordinate structured intake, tenant-controlled categories, document requirements, evidence review, assessment, remediation, approval, lifecycle status and audit history. Tenant-scoped APIs can expose governed vendor information to ERP and procurement systems. Vendoreye does not replace the customer's responsibility for legal interpretation, policy, source verification or final decisions. Continue with the related implementation resource.

Sources and editorial basis

  1. NIST SP 800-161 Rev. 1
  2. ISO 31000 risk management overview

These sources establish the official or recognised framework used in this article. Vendoreye's workflow recommendations are identified as implementation guidance rather than statements of universal law.

General information only, not legal advice. Requirements vary by entity, sector, jurisdiction and contract. Official sources and links last reviewed 13 August 2026.

References and further reading

  1. NIST SP 800-161 Rev. 1 — NIST SP 800-161 Rev. 1
  2. ISO 31000 risk management overview — ISO 31000 risk management overview
  3. OECD public procurement — OECD

These references provide background and further reading. Last recorded editorial review: 2026-08-13. Verify current requirements with the relevant authority.

Vendor GovernanceVendor OnboardingProcurement Governance