01 / IntakeKnow exactly who you are contracting with.
Trading names, parent groups and near-identical entities are where assessments quietly attach to the wrong company. Each vendor is resolved to its registered legal entity, and any prior assessment carries forward before control work begins.
RiskAn assessment can attach to the wrong legal entity.
RecordOne legal entity, one carried-forward history, one assessment path.
02 / ClassifyScope follows exposure, not habit.
A payments processor and a stationery supplier should not face the same review. What the vendor touches, how deeply it connects and what depends on it set the tier. The tier sets which controls must be evidenced.
RiskGeneric questionnaires treat low-risk and critical vendors alike.
RecordThe vendor’s exposure profile sets the tier and the evidence required.
03 / EvidenceTest proof, not declarations.
A completed questionnaire is a claim. Each document is tested against the controls it is meant to support, so gaps surface before approval rather than in an audit finding.
RiskA “yes” answer is too easily mistaken for assurance.
RecordEvidence is linked to required controls; gaps are visible before approval.
04 / DecisionThe system computes. A named person decides.
Rules produce the signal; they do not approve vendors. An accountable reviewer accepts evidence, sets conditions and signs the approval, and the record is frozen at that moment.
RiskA dashboard score cannot explain who decided to proceed—or why.
RecordComputed signal and accountable approval stay separate and attributable.
05 / LifecycleAn approval is only as current as its evidence.
Certificates expire, ownership changes, incidents happen. Each one opens a new review against a new record. The original stays intact as evidence of what was known when the vendor was approved.
RiskPoint-in-time approvals decay while the audit trail is reconstructed later.
RecordNew facts open a new review; the original approval remains intact.