Definition
Vendor risk management is the practice of identifying, assessing, and mitigating the risks a third-party vendor introduces to an organisation.
VRM spans security, compliance, financial stability, and operational dependency. The most overlooked dimension is concentration risk - how hard and expensive it would be to replace the vendor if they failed, raised prices, or were acquired.
Go deeperVendor due diligence checklistRelated terms
From definition to deal
Benchside turns vendor risk management into the exact questions, exclusions, and lock-in math for your specific vendor - your first project is free.