Vendor intake and risk tiering
Purpose
Requests arrive as a product name and a deadline. What is missing is the need
behind the name, and the two facts that determine how much diligence is required:
what data the vendor will hold and what breaks if the vendor stops. Without a
tiering step at the front door, every request gets either the full review — so the
queue jams and people buy on a card instead — or none, so a supplier holding
regulated data is onboarded on a click-through agreement. This skill is the intake
and the tiering rule, applied before evaluation starts.
Prerequisites
- Inputs: the requester and their business unit, the problem being solved, the
data the third party would process, the users and geographies affected, the
indicative spend and term, and the required date.
- Access: the existing supplier register and application inventory, to check
whether the capability is already licensed. This check kills a meaningful share
of requests and must come before any external contact.
If the request names a product but cannot state the problem, stop and get the
problem. A product-shaped request produces a single-option evaluation, which is not
an evaluation.
Step 1 — Intake capture
Record all of these. A field left blank blocks tiering; it does not default.
| Field |
Why it decides something |
| Business need and current workaround |
Determines whether anything needs buying |
| Requester and accountable business owner |
The owner signs off the risk, not the requester |
| Data types processed by the vendor |
Drives the data-exposure axis |
| Data volume, subjects and geographies |
Drives cross-border and regulatory review |
| Users affected and whether external parties are exposed |
Drives criticality |
| Business process supported, and the impact of a 24-hour outage |
Drives the criticality axis |
| Integration required (system access, API scopes, SSO, data feeds) |
Drives security and access review |
| Whether AI or automated decision-making is involved, and on what data |
Drives model, disclosure and regulatory review |
| Spend, term, renewal and exit terms |
Drives approval authority and lock-in risk |
| Alternatives considered, including existing licensed tools |
Prevents duplicate spend |
| Required date and what drives it |
Distinguishes real urgency from a trial that already started |
Already-running trials: if the product is already in use, record it as an
in-flight exception, tier it immediately, and route it at its tier. Do not let
prior use lower the tier — an unreviewed supplier already holding data is a higher
priority, not a lower one.
Step 2 — Score the two axes
Data exposure — the highest applicable band, based on what the vendor can
access, not what the requester intends to send:
| Band |
Definition |
| D0 |
No organisational data; public information only |
| D1 |
Internal non-personal data (documents, aggregate operational data) |
| D2 |
Personal data of staff or customers, or commercially sensitive data |
| D3 |
Special-category personal data, financial account or payment data, credentials, client positions, or data under a specific regulatory retention or residency obligation |
Business criticality — the impact of the vendor failing or being unavailable:
| Band |
Definition |
| C0 |
Individual or team convenience; no process depends on it |
| C1 |
A business process is degraded; a workaround exists |
| C2 |
A business process stops; no workaround within the day; internal impact only |
| C3 |
Customer-facing service, regulated activity, financial control, or a security control depends on it |
Step 3 — Assign the tier
Read the tier off the intersection. Do not reason about it in prose.
|
C0 |
C1 |
C2 |
C3 |
| D0 |
Tier 4 |
Tier 4 |
Tier 3 |
Tier 2 |
| D1 |
Tier 4 |
Tier 3 |
Tier 2 |
Tier 2 |
| D2 |
Tier 3 |
Tier 2 |
Tier 2 |
Tier 1 |
| D3 |
Tier 2 |
Tier 1 |
Tier 1 |
Tier 1 |
Escalators — apply after the table. Each raises the tier by one, to a floor of
Tier 1:
- The vendor subcontracts processing to a fourth party holding the same data.
- Data leaves the jurisdictions where processing is permitted, or residency is
undetermined.
- The integration requires privileged, administrative or write access to a system
of record.
- The vendor's product makes or materially informs automated decisions about
people.
- The supplier would become a single point of failure with no substitutable
alternative.
- Regulated activity, or an activity subject to a supervisory outsourcing
notification requirement, is being outsourced.
Escalators never lower a tier. If two people reach different tiers, the higher
stands until the business owner and the risk function agree otherwise in writing.
Step 4 — Required reviews by tier
| Tier |
Required before commitment |
Approval |
Reassessment |
| Tier 1 |
Full security assessment including evidence of controls; data protection impact assessment; legal review of contract and data-processing terms; regulatory/outsourcing assessment; financial stability check; business continuity and exit plan with a tested alternative; named business owner |
Executive or committee approval per delegated authority |
Annually, and on any material change |
| Tier 2 |
Security questionnaire with evidence for material answers; data protection review; legal review of contract and data terms; financial and reference check; documented exit route |
Department head plus risk or security sign-off |
Annually |
| Tier 3 |
Lightweight security review; confirmation of data handling and retention; standard contract terms, deviations escalated; duplicate-capability check |
Department head |
At renewal |
| Tier 4 |
Duplicate-capability check; standard terms accepted; recorded in the supplier register |
Line manager within budget authority |
At renewal |
Nothing is exempt from the register. An unregistered supplier cannot be
reassessed, cannot be included in an exit plan, and will not be found during an
incident.
Procedure
- Capture the intake fields. Missing fields block; they do not default.
- Check the supplier register and application inventory for existing capability.
Close the request if the need is already licensed.
- Score the data-exposure band on what the vendor can access.
- Score the business-criticality band on the outage impact.
- Read the tier from the table, then apply escalators.
- Record the tier with the reasoning: the two bands, each escalator applied, and
the person who scored it. The record is what makes the tier auditable and
defensible later.
- Route to the reviews required for the tier, in parallel where they do not
depend on each other.
- Confirm the named business owner accepts accountability for the residual risk.
No owner, no onboarding.
- Hand to
operations-vendor-evaluation for the comparison, with the tier
attached so the evaluation weights risk criteria correctly.
- Register the supplier with its tier, owner, renewal date and reassessment date.
Content rules
- Never assert a vendor's certification, control, or compliance status without
evidence supplied by the vendor or a document you have seen. An assumed
certification is the failure mode this whole process exists to prevent.
- Never lower a tier because of deadline pressure. Record the pressure and let the
named owner accept the risk explicitly, in writing, with a date.
Data handling
Classification: Internal, moving to Confidential where the intake record
contains commercial terms, security control detail, or a description of regulated
data flows. Do not paste real personal data, customer records or account numbers
into an intake form to illustrate what would be processed — describe the data
categories instead. If such data is supplied, flag it and stop.
Boundaries
- Comparing shortlisted suppliers against weighted requirements — use
operations-vendor-evaluation, which starts where this skill ends.
- Reviewing contract clauses, liability, data-processing terms or termination
rights — use
legal-compliance-contract-review.
- Granting user access to a system already procured — use
it-access-review.
- Deploying or integrating the tool once approved — use
it-change-management.
- Whether the spend is allowable and which budget it falls to — use
finance-expense-policy-triage.
- Assessing a new regulatory obligation affecting the supplier base — use
legal-compliance-regulatory-change-impact.
Hand-offs
- Receives from:
it-service-desk-triage (requests arriving as a tool ask),
finance-expense-policy-triage (spend caught without a supplier record), and
business teams directly.
- Routes to:
operations-vendor-evaluation (with the tier attached),
legal-compliance-contract-review (Tier 1–3), it-access-review and
it-change-management (post-approval), and
executive-board-pack-preparation where a Tier 1 supplier needs governance
approval.
1---2name: procurement-intake-and-risk-tiering3description: Handles a vendor or purchase request at the front door: capture the underlying need rather than the named product, classify data exposure and business criticality into a risk tier using a fixed table, and list the reviews each tier requires before any evaluation or commercial conversation begins. Use when someone asks to buy, trial, renew or expand a third-party product or service, and when a request has already reached legal or security without being triaged. Trigger on 'we want to buy X', 'can we get a licence for X', 'vendor request', 'someone started a trial of X', 'does this need a security review', 'what checks does this supplier need', 'renewal is coming up'. Not for comparing shortlisted suppliers against weighted criteria (use operations-vendor-evaluation), not for reviewing the contract terms once a supplier is chosen (use legal-compliance-contract-review), and not for granting access to a system already procured (use it-access-review).4---56# Vendor intake and risk tiering78## Purpose910Requests arrive as a product name and a deadline. What is missing is the need11behind the name, and the two facts that determine how much diligence is required:12what data the vendor will hold and what breaks if the vendor stops. Without a13tiering step at the front door, every request gets either the full review — so the14queue jams and people buy on a card instead — or none, so a supplier holding15regulated data is onboarded on a click-through agreement. This skill is the intake16and the tiering rule, applied before evaluation starts.1718## Prerequisites1920- **Inputs:** the requester and their business unit, the problem being solved, the21 data the third party would process, the users and geographies affected, the22 indicative spend and term, and the required date.23- **Access:** the existing supplier register and application inventory, to check24 whether the capability is already licensed. This check kills a meaningful share25 of requests and must come before any external contact.2627If the request names a product but cannot state the problem, stop and get the28problem. A product-shaped request produces a single-option evaluation, which is not29an evaluation.3031## Step 1 — Intake capture3233Record all of these. A field left blank blocks tiering; it does not default.3435| Field | Why it decides something |36| --- | --- |37| Business need and current workaround | Determines whether anything needs buying |38| Requester and accountable business owner | The owner signs off the risk, not the requester |39| Data types processed by the vendor | Drives the data-exposure axis |40| Data volume, subjects and geographies | Drives cross-border and regulatory review |41| Users affected and whether external parties are exposed | Drives criticality |42| Business process supported, and the impact of a 24-hour outage | Drives the criticality axis |43| Integration required (system access, API scopes, SSO, data feeds) | Drives security and access review |44| Whether AI or automated decision-making is involved, and on what data | Drives model, disclosure and regulatory review |45| Spend, term, renewal and exit terms | Drives approval authority and lock-in risk |46| Alternatives considered, including existing licensed tools | Prevents duplicate spend |47| Required date and what drives it | Distinguishes real urgency from a trial that already started |4849**Already-running trials:** if the product is already in use, record it as an50in-flight exception, tier it immediately, and route it at its tier. Do not let51prior use lower the tier — an unreviewed supplier already holding data is a higher52priority, not a lower one.5354## Step 2 — Score the two axes5556**Data exposure** — the highest applicable band, based on what the vendor can57access, not what the requester intends to send:5859| Band | Definition |60| --- | --- |61| D0 | No organisational data; public information only |62| D1 | Internal non-personal data (documents, aggregate operational data) |63| D2 | Personal data of staff or customers, or commercially sensitive data |64| D3 | Special-category personal data, financial account or payment data, credentials, client positions, or data under a specific regulatory retention or residency obligation |6566**Business criticality** — the impact of the vendor failing or being unavailable:6768| Band | Definition |69| --- | --- |70| C0 | Individual or team convenience; no process depends on it |71| C1 | A business process is degraded; a workaround exists |72| C2 | A business process stops; no workaround within the day; internal impact only |73| C3 | Customer-facing service, regulated activity, financial control, or a security control depends on it |7475## Step 3 — Assign the tier7677Read the tier off the intersection. Do not reason about it in prose.7879| | C0 | C1 | C2 | C3 |80| --- | --- | --- | --- | --- |81| **D0** | Tier 4 | Tier 4 | Tier 3 | Tier 2 |82| **D1** | Tier 4 | Tier 3 | Tier 2 | Tier 2 |83| **D2** | Tier 3 | Tier 2 | Tier 2 | Tier 1 |84| **D3** | Tier 2 | Tier 1 | Tier 1 | Tier 1 |8586**Escalators — apply after the table. Each raises the tier by one, to a floor of87Tier 1:**8889- The vendor subcontracts processing to a fourth party holding the same data.90- Data leaves the jurisdictions where processing is permitted, or residency is91 undetermined.92- The integration requires privileged, administrative or write access to a system93 of record.94- The vendor's product makes or materially informs automated decisions about95 people.96- The supplier would become a single point of failure with no substitutable97 alternative.98- Regulated activity, or an activity subject to a supervisory outsourcing99 notification requirement, is being outsourced.100101Escalators never lower a tier. If two people reach different tiers, the higher102stands until the business owner and the risk function agree otherwise in writing.103104## Step 4 — Required reviews by tier105106| Tier | Required before commitment | Approval | Reassessment |107| --- | --- | --- | --- |108| **Tier 1** | Full security assessment including evidence of controls; data protection impact assessment; legal review of contract and data-processing terms; regulatory/outsourcing assessment; financial stability check; business continuity and exit plan with a tested alternative; named business owner | Executive or committee approval per delegated authority | Annually, and on any material change |109| **Tier 2** | Security questionnaire with evidence for material answers; data protection review; legal review of contract and data terms; financial and reference check; documented exit route | Department head plus risk or security sign-off | Annually |110| **Tier 3** | Lightweight security review; confirmation of data handling and retention; standard contract terms, deviations escalated; duplicate-capability check | Department head | At renewal |111| **Tier 4** | Duplicate-capability check; standard terms accepted; recorded in the supplier register | Line manager within budget authority | At renewal |112113Nothing is exempt from the register. An unregistered supplier cannot be114reassessed, cannot be included in an exit plan, and will not be found during an115incident.116117## Procedure1181191. Capture the intake fields. Missing fields block; they do not default.1202. Check the supplier register and application inventory for existing capability.121 Close the request if the need is already licensed.1223. Score the data-exposure band on what the vendor *can* access.1234. Score the business-criticality band on the outage impact.1245. Read the tier from the table, then apply escalators.1256. Record the tier with the reasoning: the two bands, each escalator applied, and126 the person who scored it. The record is what makes the tier auditable and127 defensible later.1287. Route to the reviews required for the tier, in parallel where they do not129 depend on each other.1308. Confirm the named business owner accepts accountability for the residual risk.131 No owner, no onboarding.1329. Hand to `operations-vendor-evaluation` for the comparison, with the tier133 attached so the evaluation weights risk criteria correctly.13410. Register the supplier with its tier, owner, renewal date and reassessment date.135136## Content rules137138- Never assert a vendor's certification, control, or compliance status without139 evidence supplied by the vendor or a document you have seen. An assumed140 certification is the failure mode this whole process exists to prevent.141- Never lower a tier because of deadline pressure. Record the pressure and let the142 named owner accept the risk explicitly, in writing, with a date.143144## Data handling145146Classification: **Internal**, moving to **Confidential** where the intake record147contains commercial terms, security control detail, or a description of regulated148data flows. Do not paste real personal data, customer records or account numbers149into an intake form to illustrate what would be processed — describe the data150categories instead. If such data is supplied, flag it and stop.151152## Boundaries153154- Comparing shortlisted suppliers against weighted requirements — use155 `operations-vendor-evaluation`, which starts where this skill ends.156- Reviewing contract clauses, liability, data-processing terms or termination157 rights — use `legal-compliance-contract-review`.158- Granting user access to a system already procured — use `it-access-review`.159- Deploying or integrating the tool once approved — use `it-change-management`.160- Whether the spend is allowable and which budget it falls to — use161 `finance-expense-policy-triage`.162- Assessing a new regulatory obligation affecting the supplier base — use163 `legal-compliance-regulatory-change-impact`.164165## Hand-offs166167- **Receives from:** `it-service-desk-triage` (requests arriving as a tool ask),168 `finance-expense-policy-triage` (spend caught without a supplier record), and169 business teams directly.170- **Routes to:** `operations-vendor-evaluation` (with the tier attached),171 `legal-compliance-contract-review` (Tier 1–3), `it-access-review` and172 `it-change-management` (post-approval), and173 `executive-board-pack-preparation` where a Tier 1 supplier needs governance174 approval.