Most operations teams evaluate vendors on features and price. This checklist covers the five risk categories they miss: financial stability, data portability, SLA exposure, compliance obligations, and concentration risk.
Periodic vendor assessments score a relationship at one point in time. These eight KPIs create a continuous signal layer between formal reviews — so relationship degradation surfaces as a trend, not a crisis.

Most vendor risk programs are built around two events: the initial assessment before a contract is signed and the periodic review at renewal time. Between those events — which can span a year or more for multi-year agreements — the relationship is largely unmonitored. There's no systematic signal for whether a vendor is performing at the level the contract describes, whether the relationship is healthy, or whether early indicators of failure are accumulating.
This gap is where most vendor risk actually materializes. A vendor doesn't fail overnight. It deteriorates: SLA attainment slips incrementally, response times lengthen, invoice errors begin appearing, escalation requests multiply. Each individual data point looks like a one-off. The pattern is only visible if someone is tracking.
The vendor risk management checklist addresses the structured assessment — what to evaluate when you're deciding whether to renew or expand a relationship. That's the right tool for a point-in-time decision. What COOs also need is the continuous monitoring layer: a small set of leading risk indicators that run every month, create a trend line for each critical vendor, and flag yellow before a red condition develops.
The eight KPIs below are organized into four categories that map to the most common failure modes: delivery performance, relationship health, financial discipline, and compliance posture. Together they form the core of a monthly vendor scorecard that keeps risk current without requiring a dedicated procurement team to maintain it.
Delivery performance KPIs measure whether the vendor is doing what the contract says — at the level the contract specifies. Three metrics matter most here.
SLA attainment rate. The percentage of contractually defined service-level targets met in a given period. The absolute number matters less than the trend: a vendor holding steady at 96% is performing differently from one that has slipped from 99% to 96% to 93% over three months, even if the current number looks acceptable in isolation. Track as a rolling three-month average, not just the most recent month, so you see direction of travel rather than a snapshot that can be distorted by a single outlier.
Issue resolution time. The average time between a problem being reported and a confirmed resolution. This metric surfaces operational responsiveness — a distinct dimension from SLA compliance, which measures whether failures occur. A vendor can technically meet SLA commitments while taking twice as long to resolve issues as they did six months ago. Lengthening resolution times are an early indicator that internal capacity or prioritization is changing before it shows up in formal SLA breaches.
On-time delivery rate. For vendors providing goods, deliverables, or scheduled outputs: the percentage delivered by the committed date. The threshold trigger for escalation on all three delivery KPIs is a consistent two-month decline — not a single-month deviation. One missed month is noise; two consecutive months declining is a pattern that warrants a direct conversation with the vendor's account manager, not a wait-and-see approach.
Relationship health KPIs measure the quality of the working relationship rather than the technical output of the contract. These metrics often deteriorate before formal performance metrics do — they're the leading indicators that a delivery problem is developing.
First contact response time. How long it takes the vendor to acknowledge a contact — not resolve it, just confirm receipt and ownership. Lengthening response times indicate that your account is receiving less prioritization. A vendor that historically acknowledged contacts within a few hours and is now taking two days to respond is showing you something about how they're allocating capacity before their SLA numbers reflect it.
Escalation frequency. How often routine matters require escalation to a manager or senior contact to get resolved. A healthy vendor relationship handles most operational issues at the account manager level. When routine requests increasingly require going up the chain, it signals either that the account team lacks the authority or capacity to handle normal work, or that the relationship has developed friction that's making standard interactions harder than they should be.
Proactive issue notification rate. When a vendor knows a problem is developing — a delivery delay, an upcoming capacity constraint, a personnel change on your account — do they tell you before you find out, or do you discover it? Tracking the ratio of proactive notifications to reactive discoveries over time tells you whether the vendor treats you as a partner or as a transaction. Vendors who consistently fail to notify proactively tend to escalate manageable situations into crises because the response window closes before the COO knows a problem exists.
Financial KPIs in vendor management aren't about auditing the vendor's finances — they're about monitoring the discipline and accuracy of the commercial relationship.
Invoice accuracy rate. The percentage of invoices received without errors requiring correction or resubmission. A vendor with a high invoice error rate creates an operational cost beyond the invoice amount: someone on your team must identify the error, document it, and manage the correction cycle. More importantly, invoice errors often correlate with broader operational stress at the vendor: internal process breakdowns, staffing changes, or system transitions that are affecting their accuracy across clients. An accuracy rate falling below 90% in a given month, or a consistent downward trend, warrants a direct conversation.
Cost variance from contract. The difference between contracted spend and actual invoiced amounts over a rolling period. Small variances are normal. Systematic overage — consistent billing above contracted rates or unauthorized scope additions — signals either poor controls at the vendor or a pattern of incremental scope creep that will compound if not addressed. Track both the absolute variance and the direction: a vendor whose actual costs are consistently 8% above contract is a different risk from one where costs were stable for a year and have recently started drifting up.
For vendors with access to your data, systems, or sensitive operational information, compliance KPIs track the hygiene of that access over time.
Access review completion rate and timeliness. The percentage of periodic access reviews completed on schedule — confirming that personnel with access to your systems are current, appropriately scoped, and still in the role that warranted access. Access review completion is a discipline indicator: a vendor who completes reviews on time is demonstrating control maturity. One who consistently delays or misses them is signaling that access management isn't being actively maintained, which carries risk independent of whether an incident has occurred.
Incident disclosure timeliness. When a security incident, breach, or policy violation occurs that affects your data or systems, how quickly does the vendor notify you? Most contracts specify a disclosure window; the actual window in practice is often longer. Tracking disclosure timeliness for any incidents that occur builds a record of whether reporting behavior matches contractual obligations. A vendor who is slow to disclose incidents across multiple events is demonstrating a disclosure culture that creates compounding risk as AI-embedded vendor tools and data access expand — and this pattern should directly inform the renewal assessment when the contract renewal decision arrives.
The eight KPIs above are most useful when consolidated into a single view per vendor, reviewed on a consistent cadence, and scored with explicit thresholds that define when a yellow condition becomes a formal review trigger.
A practical scorecard structure uses a three-tier RAG (red/amber/green) status for each KPI, with thresholds defined for your vendor context:
Not every vendor needs to be tracked on all eight KPIs. Apply the full scorecard to critical and high-concentration vendors — those whose failure would materially disrupt operations or who have significant data access. For lower-risk vendors, three or four KPIs focused on delivery performance and invoice accuracy are sufficient.
The monthly scorecard review doesn't require significant overhead if the tracking is built into your operational system. Vendor performance tasks — SLA reviews, invoice checks, access reviews — can be structured as recurring obligations with named owners, so data collection is embedded in normal operations rather than treated as a separate reporting project. When it's set up this way, the scorecard becomes a byproduct of work that's already happening, not additional overhead layered on top.
The Sintris platform structures vendor-related obligations, task ownership, and recurring deadline tracking in exactly the form that makes this scorecard maintainable at low overhead. If you're building out vendor oversight infrastructure, see what's included or talk to the team about how organizations at your scale typically structure this.
The goal isn't a comprehensive vendor management system — it's a reliable early-warning layer. Eight KPIs, tracked monthly, reviewed against consistent thresholds, with a clear escalation protocol. That's enough to catch drift before it becomes a service failure or a renegotiation you weren't prepared for.
More from the Sintris blog.
Most operations teams evaluate vendors on features and price. This checklist covers the five risk categories they miss: financial stability, data portability, SLA exposure, compliance obligations, and concentration risk.
The contracts your company has signed carry renewal dates, notice windows, and auto-renewal clauses that no external body will remind you about. A guide to auditing your contract inventory, assigning ownership, and using AI to surface renewal risk before the window closes.
Most operations teams measure outcomes — tasks completed, deadlines hit. But by the time those numbers appear, the risk has already materialized. Key risk indicators catch the signals before they become results.
New on operational intelligence, knowledge, and risk — Monday, Wednesday, and Friday.