officeagent

TO: YOUR OFFICE · FROM: OFFICEAGENT · RE: VENDOR MANAGEMENT PROCESS

Vendor Management Process: Steps, Flow, Best Practices, and Checklist

The full vendor management lifecycle for US companies, from planning a purchase through due diligence, contract, ongoing monitoring, and termination. What happens at each stage, who owns it, how to tier vendors so the effort lands where the risk is, and how to score performance without building a bureaucracy nobody maintains.

5 stages the third-party lifecycle the Federal Reserve, FDIC, and OCC define: planning, due diligence and selection, contract negotiation, ongoing monitoring, termination Tier first a small number of vendors carry most of the risk and spend; running one process for all of them is the usual failure At signing when renewal and notice dates should be diarized, because an auto-renewal window passes without sending anyone a reminder
How it works

In one answer

The vendor management process is the end-to-end cycle for handling a supplier relationship: plan the need, run due diligence and select the vendor, negotiate and sign the contract, onboard and pay them, monitor performance and risk while the relationship runs, and terminate cleanly when it ends. Federal banking regulators define the same five stages as planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. The stage almost every company underinvests in is ongoing monitoring, because it is the only one with no deadline forcing it to happen.

Human approval on every send · 14-day money-back guarantee

Try it on a real task

Routing slip · Officeagent

Status: Ready

Action requested

Pick a task above and press RUN IT. Officeagent handles it end to end; you approve the send.

Reading page /

☐ Approve  ·  nothing sends without you

In the product you edit the draft right here; the agent learns your correction.

Officeagent drafted, you approved, it executed.

Sample data · Officeagent always waits for your approval before anything is sent

What the vendor management process is

Vendor management is how a company handles the suppliers it pays, across the whole life of each relationship rather than at the moment of purchase. The vendor management process is that work written down: a repeatable sequence covering how a vendor gets selected, what has to be true before money moves, what gets checked while the relationship runs, and how it ends. Some organizations call it supplier management, and the terms are interchangeable in practice. "Supplier" is more common in manufacturing and procurement functions, "vendor" in services and general purchasing, but the stages do not change.

It helps to separate this from procurement, because the two get used as synonyms and are not. Procurement is the buying: identifying a need, sourcing options, negotiating price, raising the purchase order. Vendor management is the relationship that exists before and long after that transaction, including the diligence that decides whether you buy from this company at all, the contract terms you will live under for three years, the performance you get in month fourteen, and the exit. Procurement is an event. Vendor management is a lifecycle, and the second one is where the money quietly leaks.

The reason it deserves a written process rather than being handled by whoever knows the vendor is that the failures are delayed and expensive. Nobody notices a mediocre vendor in week one. They notice in year two, after a contract auto-renewed because the notice window passed unremarked, at a price nobody rebenchmarked, with a service level nobody measured, held together by one employee who has since left and took the account contact with them.

The vendor management lifecycle: the five stages

There is a well-defined answer to what the stages are, and it comes from a stronger source than the average vendor blog. In the Interagency Guidance on Third-Party Relationships: Risk Management, issued June 6, 2023 by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, and the Office of the Comptroller of the Currency, the agencies describe guidance that "covers risk management practices for the stages in the life cycle of third-party relationships: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination."

That guidance is written for banking organizations, and if you are not a bank you are not supervised against it. It is still the most useful public framework available for the rest of us, for two reasons: it is a primary supervisory document rather than marketing, and the five stages it names are exactly the five that matter whether you are a national bank or a twelve-person agency buying a payroll service. Take the structure, scale the intensity to what you actually are.

1. Planning. Decide what the vendor is for, what it would cost, what could go wrong, and whether an existing supplier already covers it. This stage is about the decision to enter the relationship at all, and it is the cheapest place to say no. It is also where you decide how much diligence the purchase warrants, which depends on the tiering described in the next section.

2. Due diligence and vendor selection. Confirm the vendor can do the work and is a real, solvent, appropriately insured business. Compare more than one option where the spend justifies it. Check references you sourced yourself rather than the three the salesperson supplied. The depth here should be proportionate: a critical vendor with access to your customer data earns a security review, and a stationery supplier does not.

3. Contract negotiation. Get scope, pricing, service levels, term, renewal mechanics, notice period, data handling, and exit terms in writing before signature, because after signature you are negotiating from zero leverage. The renewal and termination clauses matter more than most buyers treat them as mattering, and they are covered separately below.

4. Ongoing monitoring. Track whether the vendor is actually delivering, whether the risk profile has changed, whether the insurance is still in force, and whether the price is still competitive. This is the stage with no forcing function, which is why it is the one that gets skipped.

5. Termination. End the relationship cleanly: notice served inside the contractual window, data returned or destroyed, access revoked, final invoices settled, and the vendor record closed rather than left active in your accounting system.

Between stages three and four sits the operational work of getting the vendor set up and payable, which is detailed enough to have its own page. Our vendor onboarding checklist covers the paperwork, the W-9, insurance certificates, and the bank detail verification that belongs at that point in the flow.

The vendor management process flow, stage by stage

People search for a vendor management process flow chart because they want to see the sequence and the decision points. Here it is in text, which is easier to adapt than a diagram someone else drew for a different company.

A need is identified, and the first decision point is whether an existing approved vendor can meet it. If yes, the flow short-circuits straight to raising a purchase order against that vendor. If no, the request goes for spend approval. Approved requests are tiered, and the tier sets how much diligence follows. Diligence runs, references and financials are checked at the depth the tier requires, and a vendor is selected or the process loops back to sourcing.

Contract negotiation follows selection, and signature is the gate: nothing is ordered before it. Onboarding then runs in parallel workstreams, tax paperwork and insurance on one side, banking and system setup on the other, converging on an active vendor record. Ordering and delivery begin. Invoices arrive and enter the accounts payable process, where three-way matching against the purchase order and receipt decides whether they get paid.

From there the flow becomes a loop rather than a line. Performance is reviewed on a cadence set by tier. Insurance certificates and certifications are re-checked at expiry. The renewal date arrives and forces a decision: renew, renegotiate, or exit. Renew and the loop continues. Exit and the flow moves to termination, where notice, data return, access revocation, and final settlement close it out.

The two decision points that do the most work are the duplicate-vendor check at the start and the renewal decision at the end. The first prevents the sprawl that makes every later stage harder. The second is the only moment you have leverage with an incumbent, and it expires quietly.

Tier your vendors before you design anything

The most common way a vendor management process fails is not neglect, it is uniformity. A company writes a thorough process, applies it to every supplier including the one that delivers coffee, discovers it cannot sustain the workload, and abandons the whole thing. The fix is to sort vendors by what they could cost you if they failed, then run a different intensity of process for each group.

Three tiers are enough for most companies. Critical vendors could stop your business or expose your data: the payroll processor, the systems your operation runs on, anyone holding customer records, a sole-source supplier with no substitute. Important vendors would hurt and disrupt but not stop you, and could be replaced in weeks. Routine vendors are commodity purchases with easy substitutes, where the only real risk is overpaying.

Tier by consequence of failure, not by invoice size. This is where most tiering exercises go wrong. A $400-a-month vendor that holds every customer record you have is a critical vendor. A $90,000 furniture order is a large purchase and a routine relationship, because if the supplier vanished tomorrow you would place the order elsewhere and be mildly annoyed. Spend is a poor proxy for risk, and sorting by spend is how the genuinely dangerous small vendors end up with no oversight at all.

What the tier buys you is a defensible allocation of effort. Critical vendors get full diligence, a security review, negotiated service levels, quarterly performance reviews, and a documented exit plan. Important vendors get standard diligence, an annual review, and renewal dates that are actually diarized. Routine vendors get identity and tax paperwork, verified bank details, and nothing else until something goes wrong. Write the tier onto the vendor record at onboarding, because a tier assigned later never gets assigned.

  • Critical: could stop the business or expose data; full diligence, quarterly review, exit plan
  • Important: disruptive but replaceable in weeks; standard diligence, annual review
  • Routine: commodity purchase, easy substitute; paperwork and banking checks only
  • Tier by consequence of failure, never by invoice size
  • Record the tier on the vendor record during onboarding, not afterward

Due diligence: what to actually check before you sign

Due diligence has a reputation for being a questionnaire exercise, and for routine vendors that is roughly what it should be. For anything above routine, a handful of checks carry most of the value.

Confirm the company is real and independently verifiable: state entity registration, a physical address that is not a mail drop, a working business phone, and a website with history. Confirm it can survive the term of your contract, which for a material commitment means asking about financial stability rather than assuming. Ask for references and then contact one you found yourself, because a supplied reference list is a curated artifact.

For any vendor touching your systems or data, ask what they hold, where it lives, who at their end can see it, what happens to it at termination, and whether they carry a current security attestation. If they cannot answer those five questions clearly, that is the finding. Ask for the certificate of insurance at this stage rather than after signature, with the coverages and limits your contract will require, and read the expiry date rather than filing it unread.

The output of diligence should be a written recommendation with the risks named, not a folder of PDFs. A folder is evidence that work happened. A short memo saying "recommend proceeding, two concerns, here is how the contract handles them" is the thing that is useful in eighteen months when someone asks why this vendor was chosen.

Contracts, renewals, and the auto-renewal trap

The contract is where most of the leverage in the entire relationship sits, and it is spent at signature. A few terms are worth the argument: what exactly is in scope, what the service level is and what happens when it is missed, how price changes at renewal, what notice each side must give, who owns the data and what happens to it at exit, and whether the vendor can subcontract the work.

Then there is the auto-renewal clause, which deserves its own paragraph because of how reliably it costs companies money. A great many B2B contracts renew automatically unless you give notice inside a defined window, often 30, 60, or 90 days before the term ends. The window is not a reminder. Nobody emails you when it opens. It passes, the contract renews for another full term at whatever the escalation clause allows, and the next chance to renegotiate is a year away.

The countermeasure is unglamorous and works: at signature, before the contract is filed, write two dates into a shared calendar. The renewal date, and the date the notice window opens, which is the one that actually matters. Put an owner on each. Do this at signing rather than "when we set up the tracker," because the tracker gets set up in three months and these contracts are the ones signed this week. Every contract you sign is one more date, and the only thing that keeps it manageable is that the entry takes ninety seconds if you do it immediately. Keeping recurring commitments like this from slipping is exactly what a task management system is for.

One more contract-stage habit worth building: record where the executed copy lives, in the vendor record, at the moment it is signed. A contract nobody can find is functionally a contract you do not have, and the request to produce it always arrives on a day when the person who signed it is unavailable.

Ongoing monitoring: vendor performance scorecards and reviews

Ongoing monitoring is the stage that separates a real vendor management process from a filing system. It is also the one with no deadline, no invoice, and nobody chasing it, which is precisely why it does not happen by itself.

Vendor performance management works best when it is embarrassingly simple. Pick three to five measures per vendor that you can actually get numbers for without a project, and that reflect what you are buying. For most vendors that means: did they deliver on time, was the quality right first time, were invoices accurate, and how did they handle the last problem. A vendor performance scorecard is those measures with a score and a trend, reviewed on the cadence the tier calls for. It does not need to be a dashboard. A shared sheet with one row per vendor and one column per quarter outperforms most software, because it gets filled in. Our walkthrough of how to run a vendor performance evaluation covers the measures to pick, how to weight them, and what to do with a score that comes back weak.

The measure people skip is responsiveness under failure, and it is often the most predictive one. Every vendor looks competent when nothing has gone wrong. How they behaved during the outage, the late delivery, or the billing dispute tells you more about the next three years than any of the on-time percentages. Write down what happened while it is fresh.

Run the review as a conversation with the vendor, not a report about them. Share the scorecard, ask what is making their side harder, and agree on what changes before the next review. A vendor that hears about a problem for the first time in a termination notice never had a chance to fix it, and you never got the benefit of them fixing it. Most of the value in this stage comes from the meeting happening at all, which means the calendar entry matters more than the template. Send the agenda in advance, capture what was agreed, and circulate it; our meeting agenda template covers the format if you want one.

Vendor risk management through the lifecycle

Vendor risk is not a stage, it is a thread running through all five. The useful framing is that risk is assessed in planning, verified in diligence, allocated in the contract, monitored while the relationship runs, and closed out at termination. Where companies get this wrong is treating it as a one-time gate at the start, after which the vendor is permanently approved.

Risk profiles change, and the changes are what you are watching for. The vendor gets acquired and the service degrades. It moves work offshore. It adds a subcontractor you never assessed. Its insurance lapses. Its certification expires. It starts holding a category of your data it did not hold when you signed. None of these generate an alert. They surface if someone re-checks, and not otherwise.

The highest-value control in the entire process costs about four minutes and sits at the payment end: verifying bank details, and any later change to them, by calling the vendor on a number you looked up independently rather than one supplied in the email. Business email compromise targeting accounts payable is the fraud that most reliably succeeds against companies with otherwise decent controls, and a change of banking details on a long-standing vendor is the exact scenario attackers engineer. The full procedure is on the vendor onboarding checklist.

For vendors holding data or connected to your systems, add access to the monitoring list. Vendor accounts in your systems follow the same rule employee accounts do: they should be inventoried, reviewed, and revoked when the relationship ends. The mechanics are the same ones covered in our offboarding process, and vendor access is the category most often left standing for years after the contract closed.

Termination: ending a vendor relationship cleanly

Exits get improvised more than any other stage, usually because they arrive alongside frustration or a budget cut and everyone wants them over with. A clean termination has five parts, and skipping any of them creates a problem that surfaces later.

Serve notice inside the contractual window, in the form the contract requires, which is sometimes registered mail rather than email. Get your data back, in a usable format, before access ends rather than after; this is the one that becomes unrecoverable. Confirm in writing what the vendor will delete and when. Revoke every access the vendor had, including the integration nobody remembers connecting. Settle final invoices and close the vendor record in your accounting system rather than leaving it active, because an open record is a payable waiting to be created by mistake.

If the vendor is being replaced rather than dropped, run the transition as an overlap rather than a handoff. The new vendor should be onboarded and working before the old one goes dark, and the exit plan you wrote for critical vendors at diligence stage is the document you use. This is the moment that plan justifies itself, which is a good argument for writing it when nobody is under pressure.

Vendor management best practices

Distilled from everything above, these are the practices that make the difference between a process on paper and one that survives contact with a busy quarter.

One more, which is less a practice than an admission: the process you will actually run is smaller than the process you would design. A two-page vendor management procedure that gets followed beats a twenty-page one that gets referenced during audits and ignored the rest of the year. Start with tiering, renewal dates, and bank verification. Those three carry most of the value. Add performance reviews once the first three are habitual, and write the rest down as you discover you need it. The recurring paperwork chase is the part most worth systematizing, since it is repetitive, deadline-driven, and the first thing dropped when the week gets busy; that is what our automated follow-ups exist to handle.

  • Keep one vendor list of record, and check it for duplicates before adding anything
  • Tier every vendor by consequence of failure, and match process intensity to tier
  • Diarize the notice window, not just the renewal date, at the moment of signature
  • Verify bank details and every later change by callback to an independently sourced number
  • Separate the person who can change bank details from the person who approves payment
  • Re-check insurance certificates and certifications at expiry, not at renewal
  • Review performance on a cadence, with the vendor in the room, using three to five real measures
  • Write an exit plan for critical vendors while the relationship is healthy
  • Store contracts, certificates, and tax forms against the vendor record, never in an inbox

Who runs this, and what software you actually need

In a large organization vendor management is a function, with a vendor manager, a procurement team, and a third-party risk group. In the companies most of this page is written for, it is a part of somebody's job: an office manager, an operations lead, a controller, or the owner. That constraint should shape the process rather than be treated as a reason the process cannot exist.

You do not need a vendor management system to run this well. A vendor list with tier, owner, renewal date, and notice date; a folder per vendor holding the contract, W-9, and certificate; and calendar entries for the dates will handle a few dozen vendors comfortably. Dedicated vendor management or third-party risk platforms earn their cost when you have hundreds of vendors, regulatory obligations that require evidence of monitoring, or a formal audit to satisfy. Below that, they mostly add a system to maintain.

To be direct about what we are: Officeagent is not a vendor management system. It does not hold your contracts of record, score vendors, or run a third-party risk program, and this page is a process guide rather than a pitch for one. What it does is the administrative layer around the process, which is the part that actually slips. It chases the missing W-9 and the expiring certificate of insurance, keeps the renewal and notice dates from passing unremarked, files the returned documents where the next person can find them instead of in one inbox, and drafts the follow-up nobody got around to sending. The process still has to be yours. The chasing does not have to be.

If you are setting this up from scratch, the sequence that works is: build the vendor list, tier it, backfill the renewal and notice dates for every active contract, then fix onboarding so new vendors enter the list correctly. Backfilling the dates first is deliberate, because that is where the money is, and it is a task with an end.

The vendor management lifecycle: each stage, its owner, what done looks like, and the failure that recurs

Stage Typical owner Done when Common failure
1. Planning Requesting manager Need, budget, and tier agreed; no existing vendor covers it A duplicate record for a supplier already under contract
2. Due diligence and selection Operations or procurement Business verified, references checked, risks written down Diligence depth set by invoice size instead of by risk
3. Contract negotiation Owner or manager, with counsel Scope, term, notice window, and exit terms signed Renewal and notice dates never diarized
4. Onboarding and setup AP or office manager W-9, insurance, verified bank details, vendor record live Payment released before the file is complete
5. Ongoing monitoring Relationship owner Performance reviewed on cadence, certificates re-checked Nothing forces it, so it silently stops happening
6. Termination Relationship owner and AP Notice served, data returned, access revoked, record closed Vendor access left standing long after the contract ended

Pricing

Assistant $149/mo · Office $399/mo · Enterprise from $1,500/mo

Office covers the whole team, up to 10 people, with the follow-up engine and CRM sync. Full limits on the AI assistant pricing page.

Questions on this

What is vendor management?

Vendor management is how a company handles the suppliers it pays across the whole life of each relationship: deciding which vendors to use, checking they are capable and legitimate, negotiating and holding them to contracts, monitoring performance and risk while the relationship runs, and ending it cleanly. It is broader than procurement, which covers only the buying transaction itself.

What is the vendor management process?

The vendor management process is the repeatable sequence a company follows for every supplier: plan the need, run due diligence and select the vendor, negotiate and sign the contract, onboard them so they can be paid, monitor performance and risk while the relationship runs, and terminate cleanly at the end. Writing it down is what makes it survive staff turnover.

What are the steps in the vendor management process?

Six operational steps: planning and internal approval, due diligence and vendor selection, contract negotiation and signature, onboarding and system setup, ongoing performance and risk monitoring, and termination. The first five each unblock the next, and monitoring loops until the relationship ends. Payment sits inside onboarding and ordering, deliberately after the paperwork is complete.

What is the vendor management lifecycle?

The Federal Reserve, FDIC, and OCC define the third-party relationship lifecycle as five stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. That framing comes from the Interagency Guidance on Third-Party Relationships issued June 6, 2023. It is written for banks, but the five stages apply to any company buying from suppliers.

Why is vendor management important?

Because the expensive failures are delayed. Contracts auto-renew at prices nobody rebenchmarked, insurance lapses unnoticed, a supplier with access to your data gets acquired, and payment fraud succeeds against companies without a verification step. A written process turns those from surprises into scheduled checks, and it keeps the knowledge in the company when the person who managed the vendor leaves.

What is the difference between vendor management and procurement?

Procurement is the buying: sourcing options, negotiating price, raising the purchase order. Vendor management is the relationship around that transaction, including the diligence before it, the contract you live under afterward, the performance you get over the term, and the exit. Procurement is an event; vendor management is a lifecycle that contains many such events.

How do you manage vendor performance?

Pick three to five measures per vendor you can actually get numbers for, such as on-time delivery, first-time quality, invoice accuracy, and how they handled the last problem. Record them on a simple scorecard, review on a cadence set by the vendor tier, and hold the review with the vendor rather than about them. Responsiveness under failure is the most predictive measure and the one most often left out.

How do you manage vendor risk?

Assess risk in planning, verify it in due diligence, allocate it in the contract, monitor it during the relationship, and close it out at termination. Watch for changes rather than treating approval as permanent: acquisitions, new subcontractors, lapsed insurance, expired certifications, and new categories of your data. At the payment end, verify all bank details and changes by callback to an independently sourced number.

What is a vendor management system?

A vendor management system is software that holds vendor records, contracts, documents, and performance or risk data in one place. It earns its cost when you have hundreds of vendors, regulatory obligations requiring evidence of monitoring, or formal audits to satisfy. Below that, a vendor list with tiers and renewal dates, a folder per vendor, and calendar entries handle the job without adding a system to maintain.

What is the difference between vendor management and supplier management?

In practice they describe the same process. "Supplier" is used more often in manufacturing and procurement functions and "vendor" more often for services and general purchasing, but the lifecycle stages, the diligence, the contract terms, and the monitoring are identical. Use whichever term your organization already uses and stay consistent.

How often should you review vendors?

Set the cadence by tier rather than reviewing everyone equally. Critical vendors that could stop your business or hold your data warrant a quarterly review. Important but replaceable vendors warrant an annual one. Routine commodity suppliers need no scheduled review at all, only a check that the paperwork is current. Every vendor, regardless of tier, needs its renewal and notice dates diarized.

Also on the routing slip

FROM: OFFICEAGENT · RE: YOUR BACK OFFICE

Your office admin, off your plate by Monday

Connect your calendar, inbox and drive. Officeagent drafts the work, you hit approve, and the busywork leaves your desk for good.

14-day money-back guarantee · Cancel anytime