In brief
Set review frequency from residual risk and criticality, then add event triggers. Trigger review for expiry, incidents, ownership, access and scope changes.
Set review frequency from residual risk and criticality, then add event triggers. Trigger review for expiry, incidents, ownership, access and scope changes.
Direct answer: Set a justified review schedule for each vendor relationship and add triggers for material changes. A calendar date is a planning control; it should not postpone a review required by a new incident, changed access or another applicable obligation.
Describe what the supplier does, how difficult it is to replace and what information, systems or sites it can access. Consider the effect of failure, not just annual spend. A modestly priced service can still be critical if it supports a process the business cannot readily perform elsewhere.
Ask the relevant policy and specialist owners to define the review basis. Record any contractual or applicable regulatory requirements separately from an internal risk-based schedule. This guide does not prescribe a universal annual, quarterly or monthly interval.
A periodic reassessment can revisit the overall relationship, while monitoring identifies signals that may need action sooner. Document which events each mechanism is intended to detect. Do not describe a scheduled questionnaire as continuous monitoring if nobody checks for changes between reviews.
Give alerts an owner and a route to resolution. A dashboard showing expired evidence is not an effective control if the responsible team does not receive or act on the information. Keep the decision and resulting action with the alert record.
Examples for policy consideration include ownership changes, serious service incidents, a new subcontractor, expanded system access and a move into another service category. Identify who is expected to report each change and how procurement will learn about it.
Determine whether the event requires a targeted review or a broader reassessment. A changed support contact may need a different response from a new hosting arrangement involving customer data. Specialists should decide the affected controls rather than automatically repeating every questionnaire.
Compare current evidence with the prior assessment and identify what has changed. Record unresolved items, conditions and any revised permission. Keep an unchanged outcome explicit so the next reviewer can distinguish a completed review from one that was never started.
Set the next review date with its rationale. Where a case is overdue, escalate according to policy rather than silently moving the date forward. If service must continue while a question is resolved, use the approved exception route and make its limits visible.
Track overdue reviews, unassigned alerts and material changes discovered only after an incident. Examine whether high-volume low-risk checks are consuming capacity needed for critical cases. Adjust the process through accountable policy review, with evidence of what the earlier schedule missed or handled poorly.
Vendoreye can coordinate structured intake, tenant-controlled categories, document requirements, evidence review, assessment, remediation, approval, lifecycle status and audit history. Tenant-scoped APIs can expose governed vendor information to ERP and procurement systems. Vendoreye does not replace the customer's responsibility for legal interpretation, policy, source verification or final decisions. Continue with the related implementation resource.
These sources establish the official or recognised framework used in this article. Vendoreye's workflow recommendations are identified as implementation guidance rather than statements of universal law.
These references provide background and further reading. Last recorded editorial review: 2026-08-13. Verify current requirements with the relevant authority.