Vendor risk management is the discipline of knowing what each supplier can reach of yours and whether they can be trusted with it. It sits inside the broader field of third-party risk management, but narrows the lens to the suppliers you actually pay. This guide defines VRM, separates it cleanly from TPRM, and shows how to size the effort to a vendor's real exposure.
Vendor risk management (VRM) is the practice of identifying, assessing, and controlling the risk that paid suppliers pose to your organization — across cyber, operational, financial, compliance, and reputational dimensions — over the full life of each relationship.
Every supplier you onboard is a decision to trust someone outside your walls with something inside them — data, a network connection, a set of drawings, a person on your floor. Vendor risk management is how you make that decision deliberately rather than by default. It is the ongoing work of cataloguing your suppliers, judging what each one can reach, gathering evidence that they protect it, and acting when the picture changes.
VRM is not only a security exercise. A supplier can fail financially, breach a regulation, miss an SLA, or damage your brand without a single packet crossing the wire. A serious program treats cyber, operational, financial, compliance, and reputational risk as one connected view — and runs it across the whole relationship, not just at the point of signature. For the step-by-step mechanics of evaluating a single supplier, see our guide to the vendor risk assessment.
What changed is where the risk lives. A decade ago most of what mattered sat inside your own perimeter; today it sits with outsiders — the cloud platform that runs your operations, the processor that handles your payroll, the contractor with a badge to your plant. Managing vendor risk well is now, in large part, simply managing your actual risk.
The terms VRM and TPRM are often used interchangeably, and in casual use that's harmless. But the distinction is worth holding precisely, because it changes what falls inside your program.
Put simply: every vendor is a third party, but not every third party is a vendor you pay. TPRM is the superset; VRM is the paid-supplier subset most programs start with and spend most of their time on. The mechanics — inventory, tiering, due diligence, monitoring, offboarding — are largely shared, which is why the two are so easy to conflate.
Which term you use matters less than being consistent about scope. If your register only tracks paid suppliers, you're running VRM whatever you call it — and the unpaid parties with access, from auditors to integration partners, can fall through the gap. Decide what is in scope, then name the program honestly.
A VRM program is not a one-time review. It runs across the life of each supplier relationship, and the stages hold even when the tooling differs:
The most consequential choice in a VRM program is how you tier suppliers, because tier decides how hard you look. Get it wrong and you either bury every supplier under the same maximal questionnaire or, more often, ration real scrutiny to a shortlist you already suspected — and miss the quiet vendor that becomes next year's incident.
Two common proxies mislead. Spend is a poor stand-in for risk: your most dangerous supplier may be cheap. An external security rating — a grade derived from internet scanning — measures what a vendor exposes to the public internet, which has little to do with what they hold of yours. A contractor with a copy of your plant drawings presents no attack surface a scanner can see.
The defensible approach tiers by your own exposure — what a given supplier holds, reaches, or touches across six access vectors: data, network, facilities, designs, people, and supply. Score a vendor across these and the tier falls out of it. Depth follows exposure, not vendor count and not spend. This is the inside-out model Polestead is built on.
A concrete case makes the difference obvious. A global logistics contract and a two-person firm that holds your CAD drawings might sit at opposite ends of a spend-ranked list — yet the small firm, with your designs on its laptops, may be the one that should keep you up at night. Exposure-based tiering surfaces that vendor; spend-based tiering buries it.
It ingests your full vendor master, classifies every supplier by your exposure across six access vectors, and scopes assessment depth to the vendors that actually hold something of yours.
How inside-out classification works →The practice of identifying, assessing, and controlling the risk that paid suppliers pose — across cyber, operational, financial, compliance, and reputational dimensions — over the full life of each relationship.
Vendor risk management covers suppliers you pay for goods or services; third-party risk management is broader, covering any external party with access or influence, paid or not. TPRM is the wider discipline, and VRM is the paid-supplier subset. See our TPRM guide.
By exposure — what a vendor holds, reaches, or touches of yours across data, network, facilities, designs, people, and supply — rather than by spend or by an external score. Tier then sets assessment depth.
No. A vendor can fail financially, breach a regulation, miss an SLA, or damage your reputation with no cyber event at all. A complete program treats cyber, operational, financial, compliance, and reputational risk as one picture.