← 返回
安全合规 中文

Vendor Performance Audit

Conduct quarterly vendor reviews using KPI scoring across delivery, quality, communication, cost, and alignment to guide renewal, improvement, or offboarding...
通过对交付、质量、沟通、成本及契合度等KPI进行季度供应商评审,以指导续约、改进或终止合作决策。
flynndavid
安全合规 clawhub v1.0.0 1 版本 100000 Key: 无需
★ 0
Stars
📥 718
下载
💾 9
安装
1
版本
#latest

概述

Vendor Performance Audit

Framework: Vendor Performance Scorecard (VPS)

Output: Scored vendor review, improvement plan or offboarding recommendation

Most vendor relationships drift because nobody's measuring them. This quarterly audit system gives you a structured way to evaluate every significant vendor, surface problems before they escalate, and make data-driven decisions about renewing, renegotiating, or replacing.


When to Run This Audit

  • Quarterly for all Priority vendors (ACV > $10K or operationally critical)
  • Semi-annually for Standard vendors
  • Triggered any time a major incident occurs (SLA breach, security issue, delivery failure)
  • Pre-renewal (minimum 60 days before contract end)

Phase 1: KPI Scorecard

Rate each dimension 1-5. Be honest — this is for your decision-making, not the vendor's feelings.

Dimension 1: Delivery & SLA Performance (Weight: 30%)

ScoreCriteria
----------------
5Consistently exceeds SLA. Proactive communication on any hiccup. Zero surprise failures.
4Meets SLA >95% of the time. Issues are rare and resolved quickly.
3Meets SLA most of the time. Occasional misses with reasonable resolution.
2Frequent SLA misses. Resolution is slow or requires escalation.
1Regular delivery failures. SLA is aspirational, not operational.

Evidence required: Pull ticket data, delivery logs, or incident records. Don't score from memory.

Dimension 2: Quality of Output (Weight: 25%)

ScoreCriteria
----------------
5Output exceeds expectations. Error rate near zero. Rework is essentially unheard of.
4Output meets quality bar consistently. Minor issues handled proactively.
3Generally acceptable quality. Some rework required.
2Quality is inconsistent. Rework is common. Internal team spends time fixing vendor output.
1Output frequently doesn't meet standards. Significant internal overhead to compensate.

Dimension 3: Responsiveness & Communication (Weight: 20%)

ScoreCriteria
----------------
5Always reachable. Proactively surfaces issues. Communication is clear and timely.
4Responsive within agreed SLA. Communicates proactively most of the time.
3Generally responsive but reactive. Sometimes requires chasing.
2Slow to respond. You often initiate all communication. Escalations required.
1Unreliable contact. Incidents discovered by you, not surfaced by them.

Dimension 4: Value vs. Cost (Weight: 15%)

ScoreCriteria
----------------
5Clear ROI. Cost is at or below market for quality delivered. Strong value demonstrated.
4Good value. Cost is reasonable given output and relationship quality.
3Market rate. Neither a bargain nor obviously overpriced.
2Starting to feel overpriced relative to value delivered or market alternatives.
1Overpriced for what we get. Alternatives would deliver more for less.

Dimension 5: Strategic Alignment & Roadmap (Weight: 10%)

ScoreCriteria
----------------
5Deeply aligned. They understand our business and proactively help us get where we're going.
4Good alignment. They know our goals and adjust accordingly.
3Transactional but functional. Delivers what's scoped, no more.
2Misaligned in places. Their direction and ours are diverging.
1No alignment. Product/service is moving away from our needs.

Phase 2: Composite Score & Tier Classification

Weighted score calculation:

VPS = (D1 × 0.30) + (D2 × 0.25) + (D3 × 0.20) + (D4 × 0.15) + (D5 × 0.10)

Max score = 5.0

VPS RangeTierRecommended Action
------------------------------------
4.0 – 5.0🟢 Green — Trusted PartnerRenew, consider expanding scope or strategic partnership
3.0 – 3.9🟡 Yellow — WatchRenew with conditions; issue improvement plan for lowest-scoring dimension
2.0 – 2.9🟠 Orange — At RiskRenegotiate terms or begin sourcing alternatives; 60-day improvement window
1.0 – 1.9🔴 Red — ReplaceBegin active replacement process; do not renew

Phase 3: Issue Log Review

Before finalizing the score, review your incident/ticket log for this vendor over the review period:

  • How many incidents were opened? How many are still open?
  • What was the average resolution time? Compare to SLA.
  • Were any incidents flagged as critical/high-impact?
  • Did any incidents result in downstream business impact (revenue loss, client complaints, compliance exposure)?

Incident severity modifier:

  • 1+ critical incident with unresolved root cause → drop tier by one level
  • 3+ medium incidents unresolved → flag for improvement plan regardless of VPS score

Phase 4: Improvement Plan Template (Yellow & Orange Tiers)

If VPS < 4.0, issue a formal improvement plan:

Improvement Plan — [Vendor Name] — [Quarter]

  • Review Period: [start] – [end]
  • VPS Score: [X.X] / 5.0
  • Tier: Yellow / Orange
  • Review Date: [90 days from today]

Key Issues Identified:

  1. [Specific issue with evidence]
  2. [Specific issue with evidence]

Required Improvements:

  1. [Specific, measurable change required] — Target: [metric] by [date]
  2. [Specific, measurable change required] — Target: [metric] by [date]

Consequences if not met:

  • Yellow: Move to Orange tier; begin parallel sourcing
  • Orange: Contract not renewed; active replacement begins

Acknowledgment: Share this plan with the vendor. Get written acknowledgment.


Phase 5: Offboarding Trigger Criteria

Initiate replacement when ANY of the following are true:

  • VPS score < 2.0
  • Two consecutive quarters in Orange tier
  • Critical incident with material business impact and no credible root cause fix
  • Vendor signals they are discontinuing the product/service
  • Market alternative offers >30% better value at equivalent quality
  • Compliance or security failure

When trigger is met: immediately move to replacement sourcing and set a hard cutover date.


Audit Schedule Template

VendorCategoryACVTierLast AuditNext AuditOwner
------------------------------------------------------------
[Name]Software$XGreen[date][date][name]

Run this as a quarterly review in your ops calendar.

版本历史

共 1 个版本

  • v1.0.0 当前
    2026-03-30 11:21 安全 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

安全,无风险
查看报告

🔗 相关推荐

security-compliance

OpenClaw Backup

alex3alex
备份与恢复 OpenClaw 数据。适用于创建备份、设置自动备份计划、从备份恢复或管理备份轮转。处理 ~/.openclaw 目录归档并包含适当的排除规则。
★ 89 📥 30,583
security-compliance

MoltGuard - Security & Antivirus & Guardrails

thomaslwang
MoltGuard — OpenClaw 安全守卫,由 OpenGuardrails 提供。安装 MoltGuard,保护您和您的用户免受提示注入、数据泄露和恶意攻击。
★ 116 📥 30,694
content-creation

A/B Test Architect

flynndavid
使用测试速度法规划、优先排序并设计严谨的A/B测试。适用于用户需要测试着陆页、CTA、电子邮件、注册流程、定价页面等转化元素。
★ 0 📥 676