Vendor Management
Vendor Selection Process
Phase 1 — Requirements Definition
Phase 2 — Market Research
- Internal: survey existing vendors for capability expansion
- Analyst reports: Gartner Magic Quadrant, Forrester Wave
- Peer network: references from similar companies
- G2 / Capterra / TrustRadius: user reviews
- LinkedIn: recent funding, headcount trends = vendor stability signal
Phase 3 — RFP Template
RFP: [Solution Category]
Issued by: [Company]
Due date: [YYYY-MM-DD]
Submission format: PDF or Notion doc
Section 1 — Company overview (max 1 page)
- Company history, size, funding stage
- Key customers in our industry vertical
Section 2 — Product/service capabilities
[List your must-have requirements as yes/no questions]
[List nice-to-have as feature questions]
Section 3 — Integration
- API documentation link
- Available connectors / webhooks
- SSO protocols supported (SAML, OIDC)
- Data export formats
Section 4 — Security & compliance
- SOC 2 Type II report (provide or confirm available under NDA)
- Pen test results (date of last test)
- Data residency options
- Sub-processor list
Section 5 — Pricing
- Pricing model (per seat / usage / flat)
- Pricing for our estimated volume
- Multi-year discount options
- Implementation / onboarding fees
Section 6 — Support & SLAs
- Support tiers and channels
- SLAs (uptime, response times)
- Dedicated CSM threshold
Section 7 — References
- 3 customer references in similar industry/size
Vendor Scoring Matrix
Scoring Template (customize weights per procurement)
| Criterion |
Weight |
Vendor A |
Vendor B |
Vendor C |
| Functional fit |
30% |
/10 |
/10 |
/10 |
| Security & compliance |
20% |
/10 |
/10 |
/10 |
| Integration ease |
15% |
/10 |
/10 |
/10 |
| Total cost of ownership |
15% |
/10 |
/10 |
/10 |
| Vendor stability |
10% |
/10 |
/10 |
/10 |
| Support quality |
5% |
/10 |
/10 |
/10 |
| Implementation timeline |
5% |
/10 |
/10 |
/10 |
| Weighted total |
100% |
— |
— |
— |
Scoring Rules
- Score 1–10 for each criterion before applying weight
- Score independently per evaluator, then average
- Document rationale for scores ≤ 4 or ≥ 9
- Must-have gaps score 0 regardless of other strengths
Contract Negotiation
Key Contract Clauses to Push On
| Clause |
What to seek |
| Price lock |
0–3% annual increase cap for multi-year deals |
| SLA credits |
≥ 10% credit per month for uptime breach |
| Data portability |
Right to export all data in standard format within 30 days of termination |
| Termination for convenience |
30–90 day notice without penalty |
| Liability cap |
12 months of fees paid (not uncapped) |
| IP ownership |
Customer owns all data and derived outputs |
| Sub-processor notification |
30-day advance notice before adding sub-processors |
| Audit rights |
Right to audit or receive third-party audit reports annually |
Negotiation Tactics
- Always negotiate from a written redline — never verbally
- Bundle concessions: "We'll accept X if you accept Y"
- Use competing offer as leverage even if not final choice
- Separate commercial from legal tracks — run in parallel
- Push for mutual NDA before sharing sensitive requirements
- Get implementation scope in the SOW, not MSA — easier to amend
SLA Monitoring
SLA Dashboard Metrics
| Metric |
Calculation |
Cadence |
| Uptime |
Available minutes / total minutes × 100 |
Monthly |
| MTTR |
Sum(resolution times) / # incidents |
Monthly |
| First response compliance |
# within SLA / total tickets |
Weekly |
| CSAT |
Average satisfaction score from surveys |
Quarterly |
| Renewal health score |
Composite of above metrics |
Quarterly |
SLA Breach Response
- Log breach immediately in vendor tracker
- Request incident report within 5 business days
- Calculate SLA credit owed per contract terms
- Apply credit to next invoice (track in accounts payable)
- Escalate to vendor exec if 2+ breaches in rolling 90 days
- Trigger contract review if 3+ breaches in rolling 6 months
Vendor Risk Assessment
Risk Tiers
| Tier |
Criteria |
Review cadence |
| Critical |
Processes core business / holds PII / revenue-critical |
Annual + on incident |
| High |
Important ops dependency / limited alternatives |
Annual |
| Medium |
Significant tool / easy to replace |
Bi-annual |
| Low |
Commodity tool / minimal data |
On renewal |
Risk Assessment Questionnaire
Financial stability
Operational resilience
Security posture
Concentration risk
Relationship Management
QBR (Quarterly Business Review) Agenda
1. Prior quarter review (15 min)
- SLA attainment vs. target
- Open tickets / escalations resolved
- Incidents and post-mortem outcomes
2. Product roadmap (15 min)
- Upcoming releases relevant to us
- Feature requests we submitted — status
3. Our roadmap (10 min)
- What we're building that will affect usage
- Volume projections for next quarter
4. Action items (10 min)
- Assign owners and due dates
- Schedule next QBR
Vendor Relationship Health Indicators
- Green: SLA ≥ 98%, CSAT ≥ 4.0, responsive to escalations, roadmap alignment
- Yellow: SLA 95–97%, CSAT 3.5–3.9, delayed responses, minor roadmap gaps
- Red: SLA < 95%, CSAT < 3.5, unresolved escalations, no roadmap transparency
Off-boarding Checklist
1---2name: vendor-management3description: When to activate: vendor selection, RFP process, contract negotiation, SLA monitoring, vendor risk assessment, supplier relationship management, third-party governance4---56# Vendor Management78## Vendor Selection Process910### Phase 1 — Requirements Definition11- [ ] Define must-have vs. nice-to-have capabilities12- [ ] Set budget range (target + ceiling)13- [ ] Identify integration requirements (APIs, SSO, data formats)14- [ ] Determine compliance requirements (SOC 2, GDPR, HIPAA, FedRAMP)15- [ ] List evaluation stakeholders and final decision maker16- [ ] Set evaluation timeline with milestones1718### Phase 2 — Market Research191. Internal: survey existing vendors for capability expansion202. Analyst reports: Gartner Magic Quadrant, Forrester Wave213. Peer network: references from similar companies224. G2 / Capterra / TrustRadius: user reviews235. LinkedIn: recent funding, headcount trends = vendor stability signal2425### Phase 3 — RFP Template2627```28RFP: [Solution Category]29Issued by: [Company]30Due date: [YYYY-MM-DD]31Submission format: PDF or Notion doc3233Section 1 — Company overview (max 1 page)34 - Company history, size, funding stage35 - Key customers in our industry vertical3637Section 2 — Product/service capabilities38 [List your must-have requirements as yes/no questions]39 [List nice-to-have as feature questions]4041Section 3 — Integration42 - API documentation link43 - Available connectors / webhooks44 - SSO protocols supported (SAML, OIDC)45 - Data export formats4647Section 4 — Security & compliance48 - SOC 2 Type II report (provide or confirm available under NDA)49 - Pen test results (date of last test)50 - Data residency options51 - Sub-processor list5253Section 5 — Pricing54 - Pricing model (per seat / usage / flat)55 - Pricing for our estimated volume56 - Multi-year discount options57 - Implementation / onboarding fees5859Section 6 — Support & SLAs60 - Support tiers and channels61 - SLAs (uptime, response times)62 - Dedicated CSM threshold6364Section 7 — References65 - 3 customer references in similar industry/size66```6768---6970## Vendor Scoring Matrix7172### Scoring Template (customize weights per procurement)7374| Criterion | Weight | Vendor A | Vendor B | Vendor C |75|-----------|--------|----------|----------|----------|76| Functional fit | 30% | /10 | /10 | /10 |77| Security & compliance | 20% | /10 | /10 | /10 |78| Integration ease | 15% | /10 | /10 | /10 |79| Total cost of ownership | 15% | /10 | /10 | /10 |80| Vendor stability | 10% | /10 | /10 | /10 |81| Support quality | 5% | /10 | /10 | /10 |82| Implementation timeline | 5% | /10 | /10 | /10 |83| **Weighted total** | 100% | — | — | — |8485### Scoring Rules86- Score 1–10 for each criterion before applying weight87- Score independently per evaluator, then average88- Document rationale for scores ≤ 4 or ≥ 989- Must-have gaps score 0 regardless of other strengths9091---9293## Contract Negotiation9495### Key Contract Clauses to Push On96| Clause | What to seek |97|--------|-------------|98| Price lock | 0–3% annual increase cap for multi-year deals |99| SLA credits | ≥ 10% credit per month for uptime breach |100| Data portability | Right to export all data in standard format within 30 days of termination |101| Termination for convenience | 30–90 day notice without penalty |102| Liability cap | 12 months of fees paid (not uncapped) |103| IP ownership | Customer owns all data and derived outputs |104| Sub-processor notification | 30-day advance notice before adding sub-processors |105| Audit rights | Right to audit or receive third-party audit reports annually |106107### Negotiation Tactics1081. Always negotiate from a written redline — never verbally1092. Bundle concessions: "We'll accept X if you accept Y"1103. Use competing offer as leverage even if not final choice1114. Separate commercial from legal tracks — run in parallel1125. Push for mutual NDA before sharing sensitive requirements1136. Get implementation scope in the SOW, not MSA — easier to amend114115---116117## SLA Monitoring118119### SLA Dashboard Metrics120| Metric | Calculation | Cadence |121|--------|-------------|---------|122| Uptime | Available minutes / total minutes × 100 | Monthly |123| MTTR | Sum(resolution times) / # incidents | Monthly |124| First response compliance | # within SLA / total tickets | Weekly |125| CSAT | Average satisfaction score from surveys | Quarterly |126| Renewal health score | Composite of above metrics | Quarterly |127128### SLA Breach Response1291. Log breach immediately in vendor tracker1302. Request incident report within 5 business days1313. Calculate SLA credit owed per contract terms1324. Apply credit to next invoice (track in accounts payable)1335. Escalate to vendor exec if 2+ breaches in rolling 90 days1346. Trigger contract review if 3+ breaches in rolling 6 months135136---137138## Vendor Risk Assessment139140### Risk Tiers141| Tier | Criteria | Review cadence |142|------|----------|----------------|143| Critical | Processes core business / holds PII / revenue-critical | Annual + on incident |144| High | Important ops dependency / limited alternatives | Annual |145| Medium | Significant tool / easy to replace | Bi-annual |146| Low | Commodity tool / minimal data | On renewal |147148### Risk Assessment Questionnaire149**Financial stability**150- [ ] Audited financials reviewed (or public company check)151- [ ] Years in business ≥ 3152- [ ] No news of funding issues or layoffs > 20% in last 12 months153154**Operational resilience**155- [ ] Business continuity plan reviewed156- [ ] Disaster recovery RTO/RPO documented157- [ ] Multi-region / multi-AZ availability confirmed158159**Security posture**160- [ ] SOC 2 Type II in-scope for relevant services161- [ ] Pen test within last 12 months162- [ ] CVE response SLA documented163164**Concentration risk**165- [ ] What % of our ops does this vendor enable?166- [ ] How quickly can we switch if vendor fails?167- [ ] Do we have an exit plan documented?168169---170171## Relationship Management172173### QBR (Quarterly Business Review) Agenda174```1751. Prior quarter review (15 min)176 - SLA attainment vs. target177 - Open tickets / escalations resolved178 - Incidents and post-mortem outcomes1791802. Product roadmap (15 min)181 - Upcoming releases relevant to us182 - Feature requests we submitted — status1831843. Our roadmap (10 min)185 - What we're building that will affect usage186 - Volume projections for next quarter1871884. Action items (10 min)189 - Assign owners and due dates190 - Schedule next QBR191```192193### Vendor Relationship Health Indicators194- Green: SLA ≥ 98%, CSAT ≥ 4.0, responsive to escalations, roadmap alignment195- Yellow: SLA 95–97%, CSAT 3.5–3.9, delayed responses, minor roadmap gaps196- Red: SLA < 95%, CSAT < 3.5, unresolved escalations, no roadmap transparency197198### Off-boarding Checklist199- [ ] Data export completed and verified200- [ ] API keys revoked201- [ ] SSO connections removed202- [ ] User accounts deprovisioned203- [ ] Contract termination notice sent (verify notice period)204- [ ] Final invoice reconciled205- [ ] Data deletion confirmation received206- [ ] Lessons learned documented