A vendor management program involves many different interconnected activities designed to accomplish goals specific to an organization. Senior management and the board are required to stay informed of these activities, and this is where a vendor management policy comes into play.
The policy is the first document that should be created and will identify the roles, responsibilities, regulations and overall purpose of a vendor management program. It also provides a broad outline on the areas of due diligence, risk assessments, contract management and establishes how the board and senior management will stay informed of vendor management activities. When used alongside other governance document, such as a program and procedures documents, a policy will help build the foundation of a well-organized vendor management program. In this blog, we’ll cover some tips on how to write the policy, who should be involved and how to implement it within your organization.
Remember these five tips when writing the policy:
Typically, the policy is also one of the first documents provided to examiners or auditors during a review of the vendor risk management practices, so be sure to spend adequate time on the development of your policy.
It’s important to obtain the input of various subject matter experts (SMEs) when creating the policy, but the document should ultimately be written by a single author. This ensures that the tone, language and content are consistent. The policy will likely need to go through several rounds of revisions, but this is an important step to establish accuracy and the right framework for your organization.
Once written and finalized, take the time to educate the board of directors and executive leadership on it and ensure they understand their vital role in its success. Remember that the board should be approving the policy annually. Track this approval by date stamping the document and recording it in the board meeting minutes. The policy should also be updated and reapproved if regulatory guidance changes.
Consistent with the manner in which you introduce other compliance and risk policies to your broader organization, the vendor risk management policy should be shared with anyone involved in vendor management. Consider holding education sessions or "did you know?" luncheons with key members of the staff. Provide feedback and encourage input – after all, everyone has a role in compliance and risk management.
Following these guidelines should help greatly in the development of a comprehensive vendor management policy that supports your program.