Procurement Intake And Risk Tiering

Handles a vendor or purchase request at the front door: capture the underlying need rather than the named product, classify data exposure and business criticality into a risk tier using a fixed table, and list the reviews each tier requires before any evaluation or commercial conversation begins. Use when someone asks to buy, trial, renew or expand a third-party product or service, and when a request has already reached legal or security without being triaged. Trigger on 'we want to buy X', 'can we get a licence for X', 'vendor request', 'someone started a trial of X', 'does this need a security review', 'what checks does this supplier need', 'renewal is coming up'. Not for comparing shortlisted suppliers against weighted criteria (use operations-vendor-evaluation), not for reviewing the contract terms once a supplier is chosen (use legal-compliance-contract-review), and not for granting access to a system already procured (use it-access-review).

alihusains Updated

File contents

alihusains/enterprise-skills/tree/main/skills/procurement/procurement-intake-and-risk-tiering commit b32824dd7e

Frequently asked questions

npx skillmds@latest add alihusains/procurement-intake-and-risk-tiering