SportsFirst

Vendor and third-party risk review due-date monitor

Workflow automationWorkflow application4-6 week first releaseMonitor

Problem

Vendor security reviews and data processing agreements get tracked in whichever spreadsheet the person who ran the onboarding happened to use. A reassessment date gets set a year out, the tab gets buried under newer ones, and the contract renews automatically before anyone checks whether the vendor's access controls or data handling terms still hold. The person who owns that relationship changes jobs and the tracking dies with them. Nobody can currently answer, without an afternoon of searching, which of the organisation's third-party suppliers are overdue for review, which hold sensitive data without a current agreement in place, or which have access nobody has looked at since the contract was signed. The gap surfaces only when an auditor or a new client asks for evidence, by which point half the answers require chasing people who have left.

Product idea

A live board listing every vendor with a review due date, the sensitivity of what they hold or access, and a status of current, due soon or overdue. Each vendor has a named internal owner, usually the person who requested the relationship, and the board escalates automatically as a deadline approaches: a reminder to the owner first, then a copy to the information security officer if nothing has happened by the deadline, then a block on renewal sign-off if it lapses entirely. It deliberately does not run the review itself; there is no questionnaire builder or scoring model inside it. It tracks whether the review happened and who is late, not how good the vendor's answers were.

Who it is for

Information security officers, Heads of IT and data managers who own third-party risk, plus the service desk lead who fields the renewal and access requests that this list would otherwise miss.

Possible first version

A single spreadsheet or CSV import of the current vendor list, review dates and named owners, rendered as one status board with current, due soon and overdue states. Automated email reminders to the owner as a deadline approaches, and a copy to the information security officer once a review is overdue. Manual mark-as-reviewed with a date and a free-text note stands in for evidence upload. Out of scope for version one: any integration with procurement or contract systems, automatic renewal blocking, and a built-in questionnaire; those stay in whatever process already produces the review itself.

Build classification
Workflow application
Rough effort
4-6 week first release
Roles involved
Information security officer, Head of IT, Data manager
Relevant to
Professional club, League office, Federation / governing body, Venue & stadium operator
Systems in play
Spreadsheets, Document management and intranets, Service desk and ticketing tools
Product framing
Monitor

Questions we get asked

What do we need to have ready before this is useful?

A list of current vendors, a review or renewal date for each, and a named internal owner. Most organisations have the first two somewhere and are missing the third: a vendor with no assigned owner is exactly the gap this is built to surface, so an unowned row on day one is a useful finding rather than a blocker. The sensitivity of the data or access each vendor holds is worth adding if you have it, but the board works without it; it will just escalate every vendor equally until that detail exists.

Does this replace the spreadsheet we already use to track vendor risk?

It replaces the tracking, not the assessment. If your current spreadsheet is genuinely kept up to date and everyone checks it, the honest answer is that you may not need this yet. Where it earns its place is in organisations where the spreadsheet exists but nobody opens it until an audit is announced. The board adds the part a spreadsheet cannot do on its own: it notices a deadline for you and pushes an escalation rather than waiting to be asked.

Our vendor owners already ignore renewal emails from procurement. Why would this be different?

It might not be, on its own. The difference is the escalation step: a single reminder that nobody reads behaves exactly like the ones you already send, but a second reminder that copies the information security officer by name changes who is accountable for the silence. Whether that is enough depends on whether anyone is willing to act on the overdue list it produces. A monitor that nobody follows up on becomes a longer list of ignored deadlines, which is worse than no list at all.

Who keeps the vendor list and owner assignments accurate once this is running?

Usually the information security officer owns the board itself, but keeping it accurate depends on whoever signs off a new vendor adding them to the list at onboarding, which is a process change rather than a feature of the tool. If new vendors keep arriving off the list, the board will look healthier than the real vendor estate actually is. That is worth naming honestly before this goes live rather than discovering it at the next audit.

Is this your workflow?

Tell us one sports workflow that still runs on paper, spreadsheets, WhatsApp or an outdated system. We will map it and show you what a simpler product looks like.

Tell us about it

More in IT, data, compliance & knowledge