Our approach draws on the consulting background described on our expertise page. See our editorial and quality standards for how we prepare these resources.
A vendor inventory is the foundation of third-party oversight. If you cannot see the relationships, you cannot prioritize or monitor them.
Begin with what is knowable. The first version can be incomplete as long as each gap is visible and assigned for follow-up.
Working checklist
- Vendor legal and common name
- Service description and category
- Internal business owner
- Contract owner and key contacts
- Start, renewal, and termination dates
- Annual cost or financial significance
- Data types and system access
- Business criticality and available alternatives
- Risk tier and assessment status
- Evidence, issues, approval, and next review date
A practical way to approach it
1Collect existing sources
Combine accounts-payable records, expense cards, contracts, software lists, and department knowledge.
2Normalize names
Use one master record for the legal vendor even when invoices or products use different names.
3Assign ownership
Every relationship needs someone accountable for business need, performance, and renewal.
4Add exposure fields
Capture the facts needed to distinguish ordinary suppliers from higher-risk providers.
5Set a maintenance rhythm
Add new vendors at intake, reconcile periodically, and close records when relationships end.
Common mistakes to avoid
- Limiting the inventory to IT vendors
- Creating duplicate records for products from one company
- Leaving ownership blank
- Tracking contracts without risk information
- Keeping terminated vendors active forever
The best inventory is not the one with the most columns; it is the one people maintain and use to make decisions.
Sources and further reading
- NIST Cybersecurity Framework 2.0
- NIST SP 800-161 Rev. 1: Supply Chain Risk Management
- CISA Cyber Guidance for Small Businesses
- FTC Cybersecurity for Small Business
These sources inform the methodology. Inclusion does not imply endorsement, certification, or applicability to every organization. The worked examples and decision prompts are PBW’s practical guidance.
This guidance is a general business resource, not legal, insurance, cybersecurity, or regulatory-compliance advice. Adapt it to your circumstances and obtain qualified advice when appropriate.