# Vendor Management

> When to activate: vendor selection, RFP process, contract negotiation, SLA monitoring, vendor risk assessment, supplier relationship management, third-party governance

- Skill: `mattakushi432/vendor-management` (Agent Skill)
- Install (CLI): `npx skillmds@latest add mattakushi432/vendor-management`
- Raw SKILL.md: https://api.skillmd.com/api/skills/mattakushi432/vendor-management/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: Mattakushi432 (https://skillmd.com/u/mattakushi432)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/mattakushi432/vendor-management

---


# Vendor Management

## Vendor Selection Process

### Phase 1 — Requirements Definition
- [ ] Define must-have vs. nice-to-have capabilities
- [ ] Set budget range (target + ceiling)
- [ ] Identify integration requirements (APIs, SSO, data formats)
- [ ] Determine compliance requirements (SOC 2, GDPR, HIPAA, FedRAMP)
- [ ] List evaluation stakeholders and final decision maker
- [ ] Set evaluation timeline with milestones

### Phase 2 — Market Research
1. Internal: survey existing vendors for capability expansion
2. Analyst reports: Gartner Magic Quadrant, Forrester Wave
3. Peer network: references from similar companies
4. G2 / Capterra / TrustRadius: user reviews
5. LinkedIn: recent funding, headcount trends = vendor stability signal

### Phase 3 — RFP Template

```
RFP: [Solution Category]
Issued by: [Company]
Due date: [YYYY-MM-DD]
Submission format: PDF or Notion doc

Section 1 — Company overview (max 1 page)
  - Company history, size, funding stage
  - Key customers in our industry vertical

Section 2 — Product/service capabilities
  [List your must-have requirements as yes/no questions]
  [List nice-to-have as feature questions]

Section 3 — Integration
  - API documentation link
  - Available connectors / webhooks
  - SSO protocols supported (SAML, OIDC)
  - Data export formats

Section 4 — Security & compliance
  - SOC 2 Type II report (provide or confirm available under NDA)
  - Pen test results (date of last test)
  - Data residency options
  - Sub-processor list

Section 5 — Pricing
  - Pricing model (per seat / usage / flat)
  - Pricing for our estimated volume
  - Multi-year discount options
  - Implementation / onboarding fees

Section 6 — Support & SLAs
  - Support tiers and channels
  - SLAs (uptime, response times)
  - Dedicated CSM threshold

Section 7 — References
  - 3 customer references in similar industry/size
```

---

## Vendor Scoring Matrix

### Scoring Template (customize weights per procurement)

| Criterion | Weight | Vendor A | Vendor B | Vendor C |
|-----------|--------|----------|----------|----------|
| Functional fit | 30% | /10 | /10 | /10 |
| Security & compliance | 20% | /10 | /10 | /10 |
| Integration ease | 15% | /10 | /10 | /10 |
| Total cost of ownership | 15% | /10 | /10 | /10 |
| Vendor stability | 10% | /10 | /10 | /10 |
| Support quality | 5% | /10 | /10 | /10 |
| Implementation timeline | 5% | /10 | /10 | /10 |
| **Weighted total** | 100% | — | — | — |

### Scoring Rules
- Score 1–10 for each criterion before applying weight
- Score independently per evaluator, then average
- Document rationale for scores ≤ 4 or ≥ 9
- Must-have gaps score 0 regardless of other strengths

---

## Contract Negotiation

### Key Contract Clauses to Push On
| Clause | What to seek |
|--------|-------------|
| Price lock | 0–3% annual increase cap for multi-year deals |
| SLA credits | ≥ 10% credit per month for uptime breach |
| Data portability | Right to export all data in standard format within 30 days of termination |
| Termination for convenience | 30–90 day notice without penalty |
| Liability cap | 12 months of fees paid (not uncapped) |
| IP ownership | Customer owns all data and derived outputs |
| Sub-processor notification | 30-day advance notice before adding sub-processors |
| Audit rights | Right to audit or receive third-party audit reports annually |

### Negotiation Tactics
1. Always negotiate from a written redline — never verbally
2. Bundle concessions: "We'll accept X if you accept Y"
3. Use competing offer as leverage even if not final choice
4. Separate commercial from legal tracks — run in parallel
5. Push for mutual NDA before sharing sensitive requirements
6. Get implementation scope in the SOW, not MSA — easier to amend

---

## SLA Monitoring

### SLA Dashboard Metrics
| Metric | Calculation | Cadence |
|--------|-------------|---------|
| Uptime | Available minutes / total minutes × 100 | Monthly |
| MTTR | Sum(resolution times) / # incidents | Monthly |
| First response compliance | # within SLA / total tickets | Weekly |
| CSAT | Average satisfaction score from surveys | Quarterly |
| Renewal health score | Composite of above metrics | Quarterly |

### SLA Breach Response
1. Log breach immediately in vendor tracker
2. Request incident report within 5 business days
3. Calculate SLA credit owed per contract terms
4. Apply credit to next invoice (track in accounts payable)
5. Escalate to vendor exec if 2+ breaches in rolling 90 days
6. Trigger contract review if 3+ breaches in rolling 6 months

---

## Vendor Risk Assessment

### Risk Tiers
| Tier | Criteria | Review cadence |
|------|----------|----------------|
| Critical | Processes core business / holds PII / revenue-critical | Annual + on incident |
| High | Important ops dependency / limited alternatives | Annual |
| Medium | Significant tool / easy to replace | Bi-annual |
| Low | Commodity tool / minimal data | On renewal |

### Risk Assessment Questionnaire
**Financial stability**
- [ ] Audited financials reviewed (or public company check)
- [ ] Years in business ≥ 3
- [ ] No news of funding issues or layoffs > 20% in last 12 months

**Operational resilience**
- [ ] Business continuity plan reviewed
- [ ] Disaster recovery RTO/RPO documented
- [ ] Multi-region / multi-AZ availability confirmed

**Security posture**
- [ ] SOC 2 Type II in-scope for relevant services
- [ ] Pen test within last 12 months
- [ ] CVE response SLA documented

**Concentration risk**
- [ ] What % of our ops does this vendor enable?
- [ ] How quickly can we switch if vendor fails?
- [ ] Do we have an exit plan documented?

---

## Relationship Management

### QBR (Quarterly Business Review) Agenda
```
1. Prior quarter review (15 min)
   - SLA attainment vs. target
   - Open tickets / escalations resolved
   - Incidents and post-mortem outcomes

2. Product roadmap (15 min)
   - Upcoming releases relevant to us
   - Feature requests we submitted — status

3. Our roadmap (10 min)
   - What we're building that will affect usage
   - Volume projections for next quarter

4. Action items (10 min)
   - Assign owners and due dates
   - Schedule next QBR
```

### Vendor Relationship Health Indicators
- Green: SLA ≥ 98%, CSAT ≥ 4.0, responsive to escalations, roadmap alignment
- Yellow: SLA 95–97%, CSAT 3.5–3.9, delayed responses, minor roadmap gaps
- Red: SLA < 95%, CSAT < 3.5, unresolved escalations, no roadmap transparency

### Off-boarding Checklist
- [ ] Data export completed and verified
- [ ] API keys revoked
- [ ] SSO connections removed
- [ ] User accounts deprovisioned
- [ ] Contract termination notice sent (verify notice period)
- [ ] Final invoice reconciled
- [ ] Data deletion confirmation received
- [ ] Lessons learned documented

