Skip to content
Vendors and third-party risk

Criticality and classification

Your criticality tiers are yours — your names, your order, your reassessment cadence. Here is how to set them up so the rest of the product does useful work.

Updated

Every vendor sits in one of your organization’s criticality tiers. New organizations start with four — critical, high, medium and low — but these are a starting point, not a fixed ladder.

You can rename tiers, reorder them, change their colour, add new ones and retire ones you do not use. If your risk policy already speaks of “Tier 1 / Tier 2 / Tier 3”, or of “systemic / material / routine”, use those words. People classify far more consistently in the vocabulary they already argue about in meetings.

Retiring a tier does not break the vendors already classified into it: it disappears from the picker while existing records keep resolving. That is what makes it safe to reorganise your bands after you have loaded a few hundred suppliers.

Each tier carries a reassessment cadence — monthly, quarterly, semi-annually, annually, or none — which says how often a vendor in that band should be reassessed.

This is the setting that turns your tiers from labels into a schedule. Cadence belongs to the tier rather than to a global preference precisely because that is how policies are actually written: nobody has a single reassessment frequency, they have one per band.

Setting “none” is a legitimate answer for your lowest band, and an honest one. A cadence you will not keep is worse than no cadence, because it produces a permanent overdue list that everyone learns to ignore.

Classification drifts when it is a judgement call made alone. Two things help:

  • Write the test down in each tier’s description — what has to be true for a supplier to land here. The description is shown where people classify.
  • Classify by impact, not by spend. The cheapest line item in your estate can be the one that stops payments. Spend is easy to sort by and it is not the question being asked.