Vendors
Vendor management, simplified.
Every third-party vendor in one record. Contracts and renewal dates, risk scored against the factors you define, required documents, and a warning before anything comes due.
The Vendor Record
One record holds the whole relationship. General information, the contracts and their dates, the risk assessment, the contacts, the notes, and the documents each sit on their own tab.
Notices appear beside a vendor's name when something is outstanding. An expired contract, a missing primary contact, a review date that has passed. Select the notice and it lists what needs attention.
- Deposit and loan balances on record
- Vendors who bank with you flagged
- Custom fields for your own data
- Search name, service, ID, or contact
- Star a vendor to pin it to Home
- Every change kept in a log
Find the Vendors That Need Attention
The vendor list narrows to whatever question is being asked. Contracts expiring in the next ninety days, contracts that auto-renew in the next thirty, vendors past their review date, vendors with no risk rating at all. Choose the filter and the list is the answer.
Filters work alongside the search box and the responsible user dropdown, so one officer can pull up their own vendors with expired contracts. Whatever the list shows can be exported, or printed as a detail sheet for each vendor, a summary of the list, or a risk summary.
- Filter and search at the same time
- Narrow to one responsible user
- Export the filtered list
- Detail sheets for each vendor
- A printed summary of the list
- A printed risk summary
Contracts
Each contract on a vendor records the date it starts, the date it expires, and the date it renews on its own if nobody acts. Month-to-month agreements are marked as such, and a vendor can hold as many contracts as it has.
Contracts inside ninety days of expiring, contracts that auto-renew inside thirty days, and contracts already expired each raise a notice on the vendor and have their own filter on the list.
- Start, expiration, and renewal dates
- Month-to-month marked separately
- Several contracts on one vendor
- Comments kept with each contract
- 90- and 30-day warnings
- Expired contracts flagged
Risk Ratings
Risk is scored against factors you write. Access to customer information, mission criticality, SOC audits, financial statements, compliance, reputation, strategy, operations, cybersecurity. Every factor has a range and a written definition of what each score in that range means, so two people rating the same vendor land in the same place.
Set each factor with the slider or type the value. The scores add to a total, the total falls into one of your threshold levels, and that level shows on the Risk tab and beside the vendor's name everywhere else it appears.
Risk mitigation comments record what is being done about the rating. A finished assessment can be copied onto another vendor as a starting point.
- Factors and ranges you define
- A written definition per score
- Slider or typed value
- Total scored into a named level
- Room for mitigation comments
- Copy ratings to another vendor
Risk Factors and Thresholds
Risk factors are set up once and apply to every vendor. Give a factor a name, a description, and a minimum and maximum rating, then drag it into the order the assessment should follow. Adding a factor adds it to every vendor at the same time.
Thresholds turn the total into a level. Name the levels the way your policy names them, give each one a color and the score it begins at, and every vendor is re-rated the moment the thresholds are saved.
A factor can also have an auto-high risk value. Rate any vendor at or above it on that one factor and the vendor takes the highest level regardless of what its total comes to.
- Named factors with their own ranges
- Descriptions that explain each score
- Drag factors into order
- Threshold levels named and colored
- Auto-high risk on a single factor
- Re-rates every vendor on save
One record for every vendor, and a warning before anything comes due.
The Risk Summary
The Risk Summary scores every active vendor against every risk factor at once, with the assigned score for each factor, the total, and the risk level all together for each vendor. A count of vendors at each risk level comes with the summary.
Sort by any factor, the total, or the risk level, select a vendor's name to open that vendor, and print the same summary from the vendor list when it is needed on paper. Vendors that have not been rated yet are counted as unassigned rather than scored as zero.
- Every active vendor scored at once
- Every risk factor included
- Total score and level per vendor
- Counts for each risk level
- Unassigned vendors counted apart
- Select a name to open the vendor
Documents
Documents are stored on the vendor. Contracts, SOC reports, financial statements, certificates of insurance, business continuity plans. You define the types and decide which dates each type has to track, whether that is an effective date, an expiration date, a retention date, a review date, or all four.
Types can be marked required on a vendor, and a required document that has not been supplied is reported as missing. Required document settings can be copied from one vendor to another. The Documents section lists every document across every vendor in one table, filtered by type, by expiration, by review date, or by whether the document is actually in the file, and exported to CSV.
- Document types you define
- Effective, expiration, review dates
- Retention dates where they apply
- Required documents per vendor
- Missing and expired reported
- One table across every vendor
Contacts and Notes
Contacts hold the people at the vendor. Name, title, email, work phone and extension, cell phone, website, and the method they prefer to be reached by. One contact is marked primary, and that is the one shown on the vendor record and on the printed detail sheet.
Notes record what was said and what was agreed. A note can have a follow-up date, and until that follow-up is marked complete the vendor appears on the pending follow-up filter and in the notification email. A vendor with no contacts, or with contacts but no primary, is reported the same way.
- Phone, cell, email, and website
- One contact marked primary
- Preferred contact method recorded
- Notes with follow-up dates
- Open follow-ups reported
- Missing contacts flagged
Who Sees Which Vendors
Access is granted one vendor at a time. Users and groups are given edit or read-only rights to a vendor, and the Vendor Management administration permission covers every vendor at once.
The responsible user for a vendor is chosen from the people who already have permission to it, so nobody is made accountable for a record they cannot open. The Permissions summary lists every vendor on one page with its edit users, its read-only users, its groups, its responsible user, and its current risk level.
- Edit or read-only, per vendor
- Granted to users or to groups
- Administrators see every vendor
- Responsible user from those permitted
- One page for the whole grant list
- Risk level shown alongside
Notifications
Notifications go out daily or weekly and name the vendors that need attention, with a link straight to each one.
They reach the Vendor Management administrators and the users with permission to the vendor, and every user chooses in their own profile which of these they want to hear about.
- Contracts already expired
- Contracts expiring within 90 days
- Contracts auto-renewing in 30 days
- Review dates past due
- Follow-up notes past due
- No risk ratings assigned
- Required documents missing
- Documents expired
- Documents past their review date
- Documents not in the file
- No contacts on the vendor
- No primary contact assigned
Risk You Can Explain
Every level traces back to a named factor, a written definition, and a score, so the rating on a vendor can be walked through line by line.
Nothing Renews Quietly
Contracts, reviews, and documents all have dates, and the ones coming due arrive by email before they pass rather than after.
The File in One Place
The contract, the audit report, the insurance certificate, and the notes about them all sit on the vendor instead of across shared drives and inboxes.
Are you ready for a demo?
See BNControl for yourself. We'll show you the modules you're interested in and answer questions along the way.