Vendor tiering, deciding what deserves the effort
Vendor tiering sorts suppliers into bands — typically critical, high, medium and low — by the inherent risk each represents. The tier then drives everything downstream: how deep the due diligence goes, which contract terms are non-negotiable, how often the vendor is reassessed, and whether an exit plan is required. Also called Vendor segmentation, Risk tiering.
What to tier on
Inherent risk, and nothing else: what data the vendor holds or can reach, what access it has, whether a business service stops without it, and the jurisdictional and regulatory context. All four are knowable at intake from the business owner, without waiting for the vendor to return anything.
Two proxies are used instead and both are wrong. Spend — the cheapest vendor in the estate frequently holds the most sensitive data. Questionnaire score — which makes the depth of assessment depend on the results of the assessment, and cannot be produced for a vendor that never replies. Tiering has to happen first, or it is not tiering.
What the tier should actually change
If the tier does not change the treatment, the exercise is decorative. A working model attaches four things to each band: assessment depth and format, non-negotiable contract terms such as audit rights and breach notification windows, reassessment frequency and monitoring intensity, and the seniority required to accept a residual risk at that level.
Tiers also move. An expanded scope of service, a new integration, a new data category or a consolidation that makes a supplier critical should all trigger re-tiering — on the change, not at the next annual cycle, which is likely to be eleven months late.
Common questions
How many vendor tiers should we have?
Should tiering be based on spend?
When should a vendor be re-tiered?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.