Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.
vendor-management
Security Scan Summary
Status: Safe
Source: Syntic Skills registry
Automated security scan completed with no high-risk patterns detected. Manual review is still required.
About This Skill
Use when scoring or auditing third-party SaaS/vendor relationships: vendor scorecards, SLA compliance tracking with credit-claim flags, third-party risk classification (TPRM), tier-1 renewal review.
Downloadable SKILL.md
Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.
---
name: vendor-management
description: Use when scoring or auditing third-party SaaS/vendor relationships: vendor scorecards, SLA compliance tracking with credit-claim flags, third-party risk classification (TPRM), tier-1 renewal review.
category: Business Operations
version: 1.0.0
tools: []
---
# Vendor Management — Operational Third-Party Performance
Run ongoing vendor performance review, not initial selection or contract drafting (BizOps / IT / Vendor Management Office scope). Score vendors on multi-dimensional criteria, track SLA compliance against contractual targets, classify third-party risk, and recommend KEEP / REVIEW / REPLACE actions.
## Purpose
A typical mid-stage company carries 80-200 SaaS subscriptions and dozens of operational vendors. Most are reviewed only at renewal — too late. Enable quarterly or rolling vendor performance reviews with deterministic scoring (not LLM-flavored opinions) so the renewal decision is already half-made before the contract comes due.
## When to use
The VMO/IT director needs a quarterly vendor scorecard for leadership; a tier-1 vendor (identity provider, data warehouse) has had recurring incidents and the SLA gap needs quantifying; the CISO needs a third-party risk classification of the SaaS portfolio for an audit; a renewal is 60-90 days out and needs a defensible KEEP/REVIEW/REPLACE call; post-acquisition, vendor coverage needs deduplicating across two organizations.
## When NOT to use
Negotiating contract terms → general-counsel-advisor. Outbound proposals/RFP responses → contract-and-proposal-writer. Categorizing spend or finding duplicate SaaS → sibling procurement-optimizer. Internal system SLOs/error budgets → slo-architect.
## Workflow
### Step 1 — Intake the vendor catalog
Required fields per vendor: name, category, annual_spend (USD), contract_end_date (ISO 8601), criticality (tier-1 = business-stops-if-down, tier-2 = important-but-workaround-exists, tier-3 = nice-to-have), uptime_pct (trailing 12 months), support_response_hours_p90, incident_count_last_12m, security_certs (from SOC2, SOC2-Type-II, ISO27001, HIPAA, PCI-DSS, FedRAMP, GDPR-DPA, CCPA), and renewal_terms (auto-renew, manual-renew, evergreen, fixed-term).
### Step 2 — Score each vendor 0-100
Weight 5 dimensions per industry profile:
| Dimension | SaaS | Fintech | Healthcare | Enterprise |
|---|---|---|---|---|
| Reliability (uptime + incidents) | 30% | 25% | 25% | 25% |
| Support (response P90) | 15% | 15% | 15% | 20% |
| Security (certs) | 25% | 30% | 35% | 25% |
| Commercial (renewal flexibility) | 15% | 15% | 10% | 15% |
| Strategic fit (criticality vs spend) | 15% | 15% | 15% | 15% |
Produce a ranked scorecard with per-dimension breakdown and a verdict: KEEP (≥75, routine renewal), REVIEW (50-74, schedule a quarterly business review before renewing), REPLACE (<50, start an alternatives search now; do not auto-renew).
### Step 3 — Measure SLA compliance
For each SLA record {vendor, sla_metric, target, actual_last_month, actual_last_quarter, breach_count_12m}, compute compliance % vs target (last month, last quarter) and a trend (improving/stable/degrading) from the month-vs-quarter delta. Flag credit-claim eligibility when breach_count_12m ≥ 2 OR actual_last_quarter misses target by more than 0.5 percentage points.
### Step 4 — Classify third-party risk
Classify each vendor Critical/High/Medium/Low across 4 risk vectors (Shared Assessments SIG-Lite-style): data sensitivity (PII/PHI/cardholder/source-code access), financial exposure (annual spend × tier multiplier), operational dependency (tier-1 with no break-glass = Critical), regulatory exposure (profile-weighted — e.g. healthcare HIPAA without a BAA = Critical). Attach a mitigation recommendation per vendor (e.g. "Tier-1 with no SOC2 → require attestation before next renewal").
### Step 5 — Synthesize recommendations
One digest: top 3 KEEP wins, top 3 REVIEW conversations (schedule a QBR), top 3 REPLACE candidates, all SLA credits eligible to claim with a dollar estimate where possible, and all Critical-risk vendors with no current mitigation.
## Canon
Gartner, Shared Assessments, ISO 27036, NIST 800-161, Forrester, ISACA, Vendr industry reports (vendor management); Google SRE Workbook's SLI/SLO/SLA distinction, Atlassian, ITIL v4, Gartner SLA research, hyperscaler SLA patterns (SLA design); SolarWinds, Target/HVAC, NotPetya/M.E.Doc, Capital One, Verkada, Okta 2022, log4j breach post-mortems (risk anti-patterns).
## Assumptions
1. The user has a vendor catalog, or can build one from procurement records, a SaaS management tool (Vendr/Tropic/Zylo), or a spend export.
2. SLA records come from the vendor's status page, the support ticketing system, or internal monitoring — never invented.
3. Security weighting dials up for healthcare/fintech or down for non-regulated B2B SaaS via the profile.
4. Output artifacts are inputs to a human decision, not the decision itself.
## Anti-patterns
Treating all vendors at the same tier (a logo monitoring tool and the identity provider don't deserve equal scrutiny); assuming annual review is enough (tier-1 needs quarterly, tier-2 semi-annual, tier-3 at renewal); trusting a security questionnaire without verification (ask for the SOC2 report, not a SIG checkbox); no break-glass plan for a tier-1 vendor; forgetting offboarding — run data-deletion and access-revocation when a vendor is replaced or acquired (SolarWinds and Okta both illustrate why); scoring by gut feel instead of the deterministic dimensions above, so two operators score the same catalog the same way.
## Distinct from
contract-and-proposal-writer is outbound proposals to win customers, not scoring inbound vendors already being paid. general-counsel-advisor is contract law (indemnity, liquidated damages, IP), not operational performance against an existing contract. procurement-optimizer (sibling) is spend categorization, supplier rationalization, and finding duplicate SaaS — deciding which vendors to keep; this skill scores performance of vendors already kept. slo-architect is internal SLO/error-budget discipline for systems operated in-house, versus contractual SLA tracking for systems a vendor operates.
## Forcing-question library
Walk one at a time, depth-first — lock questions 1-3 before opening 4-6, never bundled. Recommended answer + canon citation per question.
1. "What's your tier-1 criticality threshold — by spend ($X/year) or by operational dependency (revenue-blocking if the vendor fails)?" Recommended: operational dependency. Canon: Gartner TPRM research; the Target/HVAC breach shows spend-only tiering misses critical low-spend vendors.
2. "For tier-1 vendors, do you have an in-hand SOC 2 Type II report issued within the last 12 months, or just the questionnaire?" Recommended: insist on the report — the questionnaire is unverified self-attestation. Canon: NIST SP 800-161, Shared Assessments SIG framework.
3. "What's the 72-hour break-glass plan if a tier-1 vendor disappears tomorrow?" Recommended: documented contingency per vendor, tested annually. Canon: NotPetya/M.E.Doc, log4j response patterns.
4. "When was the last time the SLA was actually invoked (a credit claim filed)?" Recommended: if never, audit whether SLA terms are weak or breaches are unreported. Canon: Atlassian SLA best practices, ITIL v4 service level management.
5. "Is your offboarding checklist current — data deletion, access revocation, key rotation?" Recommended: rehearse it on one vendor per quarter. Canon: SolarWinds and Okta 2022 breach lessons.
6. "What's the regulatory blast-radius — HIPAA / GDPR / SOX / PCI?" Recommended: surface it explicitly; it drives security weighting up via the industry profile. Canon: ISO/IEC 27036.
Bundle Download
Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.
Install Targets
Syntic App
- 1. Create a dedicated folder for this skill in your local skills library.
- 2. Place SKILL.md into that folder.
- 3. Restart Syntic and invoke this skill on matching tasks.
Syntic Code (CLI)
- 1. Save SKILL.md in your local Syntic Code skills directory.
- 2. Keep related files in the same skill folder.
- 3. Run in a safe environment and validate outputs.
Source
https://github.com/alirezarezvani/claude-skills/blob/main/business-operations/skills/vendor-management/SKILL.md
Open Source LinkRelated Skills
business-operations-skills
Use when diagnosing or designing internal business operations: process bottlenecks, vendor SLAs, capacity...
Business Operationscapacity-planner
Use when sizing an ops team (Support, CX, BizOps, IT, Finance ops) handling queued work — headcount planning...
Business Operationsinternal-comms
Use when drafting or sequencing an internal change-management announcement — a re-org, tool rollout, policy...
Business Operationsknowledge-ops
Use when authoring or auditing company SOPs, runbooks, or a wiki/knowledge base: 5W2H completeness...