Controls for approvals, exceptions, ownership, audit trails, master data and accountable vendor decisions.
Registration, onboarding and prequalification are separate governance decisions. Registration captures identity and basic information.
Set review frequency from residual risk and criticality, then add event triggers. Trigger review for expiry, incidents, ownership, access and scope changes.
Every vendor exception needs authority, rationale, controls and an expiry date. Define controls that cannot be excepted.
Offboarding must close access, obligations, data handling and vendor status. Confirm open orders, payments, assets and disputes.
Never verify a bank change using contact details supplied only in the request. Use an independently established contact and callback.
Assign each vendor record a purpose, retention trigger, owner and deletion outcome. Separate active records, archives and legal holds.