Vendor and third-party risk review due-date monitor
Problem
Vendor security reviews and data processing agreements get tracked in whichever spreadsheet the person who ran the onboarding happened to use. A reassessment date gets set a year out, the tab gets buried under newer ones, and the contract renews automatically before anyone checks whether the vendor's access controls or data handling terms still hold. The person who owns that relationship changes jobs and the tracking dies with them. Nobody can currently answer, without an afternoon of searching, which of the organisation's third-party suppliers are overdue for review, which hold sensitive data without a current agreement in place, or which have access nobody has looked at since the contract was signed. The gap surfaces only when an auditor or a new client asks for evidence, by which point half the answers require chasing people who have left.
Product idea
A live board listing every vendor with a review due date, the sensitivity of what they hold or access, and a status of current, due soon or overdue. Each vendor has a named internal owner, usually the person who requested the relationship, and the board escalates automatically as a deadline approaches: a reminder to the owner first, then a copy to the information security officer if nothing has happened by the deadline, then a block on renewal sign-off if it lapses entirely. It deliberately does not run the review itself; there is no questionnaire builder or scoring model inside it. It tracks whether the review happened and who is late, not how good the vendor's answers were.
Who it is for
Information security officers, Heads of IT and data managers who own third-party risk, plus the service desk lead who fields the renewal and access requests that this list would otherwise miss.
Possible first version
A single spreadsheet or CSV import of the current vendor list, review dates and named owners, rendered as one status board with current, due soon and overdue states. Automated email reminders to the owner as a deadline approaches, and a copy to the information security officer once a review is overdue. Manual mark-as-reviewed with a date and a free-text note stands in for evidence upload. Out of scope for version one: any integration with procurement or contract systems, automatic renewal blocking, and a built-in questionnaire; those stay in whatever process already produces the review itself.
- Build classification
- Workflow application
- Rough effort
- 4-6 week first release
- Roles involved
- Information security officer, Head of IT, Data manager
- Relevant to
- Professional club, League office, Federation / governing body, Venue & stadium operator
- Systems in play
- Spreadsheets, Document management and intranets, Service desk and ticketing tools
- Product framing
- Monitor
Questions we get asked
What do we need to have ready before this is useful?
A list of current vendors, a review or renewal date for each, and a named internal owner. Most organisations have the first two somewhere and are missing the third: a vendor with no assigned owner is exactly the gap this is built to surface, so an unowned row on day one is a useful finding rather than a blocker. The sensitivity of the data or access each vendor holds is worth adding if you have it, but the board works without it; it will just escalate every vendor equally until that detail exists.
Does this replace the spreadsheet we already use to track vendor risk?
It replaces the tracking, not the assessment. If your current spreadsheet is genuinely kept up to date and everyone checks it, the honest answer is that you may not need this yet. Where it earns its place is in organisations where the spreadsheet exists but nobody opens it until an audit is announced. The board adds the part a spreadsheet cannot do on its own: it notices a deadline for you and pushes an escalation rather than waiting to be asked.
Our vendor owners already ignore renewal emails from procurement. Why would this be different?
It might not be, on its own. The difference is the escalation step: a single reminder that nobody reads behaves exactly like the ones you already send, but a second reminder that copies the information security officer by name changes who is accountable for the silence. Whether that is enough depends on whether anyone is willing to act on the overdue list it produces. A monitor that nobody follows up on becomes a longer list of ignored deadlines, which is worse than no list at all.
Who keeps the vendor list and owner assignments accurate once this is running?
Usually the information security officer owns the board itself, but keeping it accurate depends on whoever signs off a new vendor adding them to the list at onboarding, which is a process change rather than a feature of the tool. If new vendors keep arriving off the list, the board will look healthier than the real vendor estate actually is. That is worth naming honestly before this goes live rather than discovering it at the next audit.
Is this your workflow?
Tell us one sports workflow that still runs on paper, spreadsheets, WhatsApp or an outdated system. We will map it and show you what a simpler product looks like.
Tell us about itMore in IT, data, compliance & knowledge
- Certificate and domain renewal obligation registerA register of every TLS certificate and domain name renewal date across the technology estate, with a named owner and escalation before one lapses and takes a service down.
- Data retention and deletion obligation registerA register that tracks retention deadlines for datasets holding personal data across the technology estate and escalates to a named owner before deletion or review falls overdue.
- Integration heartbeat monitor and owner escalation boardA live board of every integration's last successful run that escalates to a named owner before a missed sync turns into a bad report or an angry ticket.