Skip to content
Vendors and third-party risk

Adding a vendor

The fields that matter on day one, the ones that can wait, and the one people skip and regret.

Updated

Add a vendor from the vendor register. Only a name is required to create the row — but a vendor with only a name cannot be classified, assessed or reported on, so it is worth spending another two minutes.

  • Name, as it appears on the contract rather than as people say it. “AWS” is a nickname; the counterparty is a specific legal entity.
  • Country of registration. It drives concentration and geographic analysis, and it is a reported field in a DORA register.
  • Legal identifier — the LEI, or your national company number. This is the field people skip and it is the one that hurts later: registers are reconciled on identifiers, not names, and finding forty of them the week before a submission is a genuinely miserable week.
  • Criticality tier. Your own banding — see Criticality and classification.
  • Owner. The person accountable for the relationship.

Contacts, addresses, tags and notes enrich the record but constrain nothing. Add them when you have a reason.

The import wizard's column-mapping step

The import wizard’s mapping step. Your spreadsheet’s own column names stay as they are — you match them to fields once, and see a sample value from each before anything is written.

A new vendor is not yet a managed one. Two things usually follow:

  1. A contract, which is what most regulatory obligations actually attach to. Under DORA it is the arrangement, not the supplier, that carries the Article 30 terms.
  2. An assessment, sized to the criticality tier you just set.

If a supplier is already in your register as a fourth party — because it appeared in someone else’s subprocessor chain — do not create a second row for it. Find the existing row and record your direct relationship there. Two rows for one legal entity will quietly understate your concentration to that provider, which is the single figure the whole exercise exists to produce.