TPRM glossary

Vendor lifecycle management, from first contact to verified deletion

Vendor lifecycle management is the management of a supplier relationship across its whole span — identification, due diligence, contracting, onboarding, ongoing monitoring, renewal and offboarding. Treating it as a lifecycle rather than a procurement event is what stops assurance ending on the day the contract is signed. Also called VLM.

The stages, and where programmes fail

Identify and select. Assess before contract. Negotiate terms that reflect the inherent risk. Onboard with the access and data actually needed. Monitor continuously. Reassess on change or schedule. Renew or exit deliberately. Offboard completely.

Effort is almost always front-loaded onto the first three, because that is where procurement's attention naturally sits and where the deal is done. The relationship then runs for six years with a single annual questionnaire, and the two stages that carry the most unmanaged risk — ongoing monitoring and offboarding — get the least attention of any point in the lifecycle.

The stage everyone skips

Offboarding is where risk persists after the relationship ends: credentials and API keys still valid, integrations still connected, SSO grants still live, and data still held long past the deletion date the contract specified. None of it appears on a register that has already marked the vendor as terminated.

A complete exit has four parts — revoke access, disconnect integrations, obtain confirmation of data destruction, and close out the contractual obligationsthat survive termination. The third is the one most often skipped, because it requires the vendor to do something at the point they have least incentive to respond; at RiskXchange it is a named step in NOVA's offboarding work rather than an assumed one.

Common questions

What are the stages of the vendor lifecycle?
Identification and selection, due diligence, contracting, onboarding, ongoing monitoring, reassessment, renewal or exit decision, and offboarding. The risk profile changes at each stage, which is why assurance carried out only at the contracting stage describes a relationship that no longer exists.
What is the difference between vendor lifecycle management and vendor risk management?
Lifecycle management covers the whole relationship including commercial performance, contract administration and renewal. Vendor risk management is the risk-focused thread running through it — what the relationship exposes you to at each stage and what is being done about it.
What should happen at vendor offboarding?
Revoke credentials and access, disconnect integrations and API keys, obtain written confirmation that data has been destroyed or returned as the contract requires, and close out surviving obligations such as confidentiality and audit rights. Marking the vendor inactive in a register does none of these.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.