ciso.diy
Vendor Risk Operations Kit preview
Vendor Risk vendor riskTPRMDORARegister of Information

Vendor Risk Operations Kit

The programme is designed — this is how you run it, vendor by vendor, and what you hand the examiner. The dossier, a quarterly scorecard whose rating has consequences, an annual review that ends in a decision, the incident playbook, a tested exit plan, an AI overlay with hard stops, and a Register of Information builder with ten quality checks aimed at the failures supervisors actually flag.

What this actually gives you

  • In the ESA dry run, 93% of firms failed data-quality checks — and the failures were mechanical, not conceptual: missing LEIs, critical functions with no exit reference, contracts not linked to functions, subcontractor chains that stop halfway.
  • The Register of Information builder carries ten automatic quality checks aimed at exactly those failures. It tells you which rows would be rejected before a supervisor does.
  • It is a working model, not the xBRL-CSV submission template, and it files nothing. The column map to the ESA technical package is a planned v1.1.
  • The annual review produces a computed indicated decision that must then be recorded as an actual decision with conditions — a review that ends in a filed document rather than a decision is the most common failure in this discipline.

TPRM-01 designs the programme — policy, tiering, questionnaires, clauses, cadence. This runs it, vendor by vendor. The seam between them is clean: the first answers how do we manage vendor risk here, this one answers what is the state of this vendor right now.

That distinction matters because the second question is the one supervisors have started asking, and it is not answerable from a policy document.

07 Register of Information Builder (XLSX) is the piece with the most pull right now. In the ESA dry run, 93% of firms failed data-quality checks — and the failures were not conceptual, they were mechanical: missing LEIs, critical functions with no exit reference, contracts not linked to functions, subcontractor chains that stop halfway. The builder carries DORA-aligned working tables for entity, contracts, providers, functions and subcontracting, plus ten automatic quality checks aimed at exactly those failure modes, including Art. 28(7) and 30 flags, chain depth and renewals.

It is a working model, not the xBRL-CSV submission template. It will not file anything for you, and the licence says so. What it will do is tell you which rows would be rejected before a supervisor does. The column map to the ESA technical package is a planned v1.1.

01 Vendor File Template (DOCX) — one dossier per Tier 1–2 vendor: profile, what they actually do for you, contract, assessment history, evidence index, sub-processors, findings, incidents, performance, exit readiness and the record of decisions.

02 Vendor Scorecard & Portfolio View (XLSX) — 14 metrics across three dimensions and four quarters with trend, and a PREFERRED / WATCH / AT RISK rule that has consequences attached rather than a colour. The portfolio view surfaces overdue QBRs, which is usually where a programme quietly stops running.

03 Annual Vendor Review Pack (XLSX) — 14 review items with evidence and Pass/Partial/Fail, producing a computed indicated decision that then has to be recorded as an actual decision with conditions. An annual review that ends in a filed document rather than a decision is the most common failure in this discipline.

04 Vendor Incident Playbook (DOCX) — six triggers, the first-24-hours sequence, days 2–30, the inquiry template you send them, and variants for a bad update, an outage and a corporate event. Plus the closure checklist.

05 Exit & Transition Plan Template (DOCX) — triggers, dependency map, alternatives with time and cost, a phased transition, data-portability tests, stressed-exit provisions and a test schedule. DORA Art. 28(8) wants the exit plan tested, not merely written.

06 AI Vendor Due-Diligence Addendum (XLSX) — 20 AI-specific questions mapped to NIST AI RMF, ISO 42001 and the EU AI Act, weighted, with three hard stops. Standard questionnaires do not ask these, and the answers change whether you should sign.

08 Vendor QBR Deck (PPTX) — four slides: scorecard, security and compliance, findings and incidents, roadmap and contract actions.

09 Operations Guide (PDF) — programme versus operations, what changed in 2026, each artefact, the cadence, staffing, the failure patterns and an FAQ.

Cadence. Monthly portfolio view; quarterly scorecards, QBRs and register update; annual review per tier ending in a decision; the incident playbook on trigger; an exit test each year for Tier 1; and the register quality checks before any submission.

TPRM-01 is effectively required. This kit assumes tiers exist, questionnaires have been sent and contracts carry the clauses — all of which TPRM-01 produces. Buying this alone gives you the operating layer with nothing underneath it. The Vendor Risk Complete bundle is the pair.

Pairs with I've Been Breached for when the vendor's incident becomes yours, and with the NYDFS Part 500 Kit for §500.11.

Not legal advice.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-03
Pages 9