Vendor lifecycle management, from first contact to verified deletion
Vendor lifecycle management is the management of a supplier relationship across its whole span — identification, due diligence, contracting, onboarding, ongoing monitoring, renewal and offboarding. Treating it as a lifecycle rather than a procurement event is what stops assurance ending on the day the contract is signed. Also called VLM.
The stages, and where programmes fail
Identify and select. Assess before contract. Negotiate terms that reflect the inherent risk. Onboard with the access and data actually needed. Monitor continuously. Reassess on change or schedule. Renew or exit deliberately. Offboard completely.
Effort is almost always front-loaded onto the first three, because that is where procurement's attention naturally sits and where the deal is done. The relationship then runs for six years with a single annual questionnaire, and the two stages that carry the most unmanaged risk — ongoing monitoring and offboarding — get the least attention of any point in the lifecycle.
The stage everyone skips
Offboarding is where risk persists after the relationship ends: credentials and API keys still valid, integrations still connected, SSO grants still live, and data still held long past the deletion date the contract specified. None of it appears on a register that has already marked the vendor as terminated.
A complete exit has four parts — revoke access, disconnect integrations, obtain confirmation of data destruction, and close out the contractual obligationsthat survive termination. The third is the one most often skipped, because it requires the vendor to do something at the point they have least incentive to respond; at RiskXchange it is a named step in NOVA's offboarding work rather than an assumed one.
Common questions
What are the stages of the vendor lifecycle?
What is the difference between vendor lifecycle management and vendor risk management?
What should happen at vendor offboarding?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.