TPRM glossary

Vendor tiering, deciding what deserves the effort

Vendor tiering sorts suppliers into bands — typically critical, high, medium and low — by the inherent risk each represents. The tier then drives everything downstream: how deep the due diligence goes, which contract terms are non-negotiable, how often the vendor is reassessed, and whether an exit plan is required. Also called Vendor segmentation, Risk tiering.

What to tier on

Inherent risk, and nothing else: what data the vendor holds or can reach, what access it has, whether a business service stops without it, and the jurisdictional and regulatory context. All four are knowable at intake from the business owner, without waiting for the vendor to return anything.

Two proxies are used instead and both are wrong. Spend — the cheapest vendor in the estate frequently holds the most sensitive data. Questionnaire score — which makes the depth of assessment depend on the results of the assessment, and cannot be produced for a vendor that never replies. Tiering has to happen first, or it is not tiering.

What the tier should actually change

If the tier does not change the treatment, the exercise is decorative. A working model attaches four things to each band: assessment depth and format, non-negotiable contract terms such as audit rights and breach notification windows, reassessment frequency and monitoring intensity, and the seniority required to accept a residual risk at that level.

Tiers also move. An expanded scope of service, a new integration, a new data category or a consolidation that makes a supplier critical should all trigger re-tiering — on the change, not at the next annual cycle, which is likely to be eleven months late.

Common questions

How many vendor tiers should we have?
Three or four. Fewer than three cannot distinguish a critical supplier from a moderate one; more than four produces bands whose treatment is indistinguishable, and the effort of arguing which one a vendor belongs in exceeds the value of the distinction.
Should tiering be based on spend?
No. Spend correlates poorly with risk — a low-cost SaaS tool can hold your entire customer list while an expensive facilities contract holds nothing. Tier on inherent risk: data, access, dependency and jurisdiction.
When should a vendor be re-tiered?
Whenever the relationship changes materially: a new integration or data category, an expanded scope of service, a change of control at the vendor, or a consolidation that makes the supplier critical to more processes. Re-tier on the change rather than waiting for the annual cycle.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.