How to schedule a vendor review on Mac
A supplier only gets looked at again if something brings them back. In RiskOS, the risk register for macOS, that something is a date on the vendor and a count in the list.
Third parties change quietly. A supplier is acquired, moves a service to a new region, loses the engineer who knew your account, quietly drops a certification — and none of it arrives as a message you can act on. The register's answer is unglamorous and it works: put a date on the relationship, put a name beside it, and let the list keep score of which dates have passed.
A vendor's review date is yours to set and yours to move. The list counts overdue reviews in its subtitle, so the backlog is visible before you open a single supplier.
Where vendor reviews live
Choose Vendors in the sidebar, under Inventory. The list holds every third party you have recorded, and its subtitle carries the number that matters most: how many of them are overdue for a review. Select one and the panel on the right shows the whole relationship — its criticality, its relationship owner, the next review date, your notes, and every risk that supplier brings, gathered in one place rather than scattered across the register.
That last part is what makes a vendor review possible at all. A supplier is rarely one risk. A payment provider might carry an outage risk, a data-handling risk and a concentration risk, each with its own owner, controls and residual score. Taken one at a time from the register they tell you little; gathered on the vendor, they are the review.
Two other sections matter while you work. Risks is where a vendor is attached to the exposure it creates, in the risk's Context section. Actions is where the promises made at the last review are still sitting, grouped by whether they are overdue, due soon or later.
Schedule a vendor review, step by step
-
Open the Vendors list
Choose Vendors in the sidebar. Read the subtitle before anything else: it counts the reviews that have already fallen past their date. If that number is not zero, you have a backlog to clear before you schedule anything new, and clearing it is the same work described below.
-
Create the vendor, or find the one you have
Press ⌘N to record a new third party, or search the list for a supplier you already hold. Give it the name your colleagues actually use for it rather than the full legal entity, because the name is what everyone will search for a year from now.
-
Set the criticality
Criticality answers one question: how much of the organisation rests on this relationship. It travels with the relationship, showing as a criticality badge beside the vendor on every risk that names it, and it is the honest basis for how often the supplier comes back for a look. Set it from what would happen if the relationship stopped tomorrow, not from what you spend.
-
Name the relationship owner
Record the person who actually holds the relationship — who takes the call, who reads the contract, who would chase an incident. A review with no name against it does not happen. If the owner has left, replace the name now rather than at the review, because an empty owner is the most common reason a date slides past unnoticed.
-
Link the risks the vendor brings
Open each risk this supplier touches in Risks, go to its Context section and add the vendor there. Assets and vendors both live in that section with their criticality shown, so the risk says plainly what it threatens and who else is involved. The link then reads from both ends: the vendor's panel lists every risk it carries.
-
Set the next review date
Put a real date in the vendor's next review date field — the day you intend to do the work, not the last day it would still be defensible. This is the field the overdue count is measured against, so a date chosen honestly is what makes that count worth reading.
-
Write what the review must cover into the notes
Use the vendor's notes to say what this particular review has to establish: the certification that expires in March, the sub-processor they added last year, the restore evidence you were promised and never received. A date tells the next person when; the notes tell them what, and they are usually a different person.
-
Move the date forward when the review is done
When the review has happened, set the next review date to the following interval before you leave the vendor. The overdue count in the list subtitle drops as you do it, which is the only confirmation the work has been recorded. Re-score any risk whose rating the review changed, so the register and the relationship agree.
Choosing an interval that will hold
The interval you can sustain beats the interval you would like. A register promising quarterly reviews of forty suppliers and delivering none is worse than one promising annual reviews and meeting every one, because the second tells the truth about what is being watched. Set intervals by criticality, and let the small suppliers have long ones.
| What the supplier carries | An interval that tends to hold | What that review has to produce |
|---|---|---|
| Customer or regulated data, or a service you could not operate without for a day | Quarterly | Evidence the controls you rely on are still operating, and a re-score of every risk the supplier carries. |
| Something important, where a week of disruption would be absorbed | Twice a year | A look at the linked risks and their open actions, and anything that has changed in the arrangement. |
| Useful and replaceable, with nothing sensitive passing through | Annually | Confirmation that nothing has changed enough to move the criticality up. |
| A new relationship, in its first year | Quarterly until it settles | The things onboarding missed — who else they subcontract to, and what happens when they fail. |
| A supplier you are exiting | Monthly until the data is gone | What they still hold, and the date it is returned or destroyed. |
Stagger the dates deliberately
If every supplier was recorded on the same afternoon, every review will fall due on the same afternoon a year later, and that week will not happen. Spread the dates across the quarter as you set them. Four suppliers a month for a year is a routine; forty-eight in one week is a wish.
What to read before you move the date
A vendor review is not a meeting about a supplier. It is a decision about whether the risks you have already written down are still rated correctly. Everything you need for that is in the register, and most of it takes a minute to read.
| Where to look | What it tells you |
|---|---|
| The vendor's own list of risks | The residual score and the over-appetite flag on everything this supplier carries, in one place. |
| The controls linked to those risks | Whether what you rely on is implemented or operating, or still only planned — and a planned control reduces nothing yet. |
| Actions | What was promised at the last review and never finished. Overdue rows carry a badge and name their parent risk. |
| Indicators | Whether a number you measure has drifted into warning or breach since you last looked. |
| Events | Whether this supplier has actually failed you, how severe it was, and how long it took you to notice. |
| A risk's History section | Every earlier assessment, with the reason behind it and the score it produced. |
Let the register contradict you
Two of those rows are capable of arguing back. If the supplier has failed more often than the likelihood rating implies, RiskOS says so on the risk and suggests what the observed frequency would justify — it needs at least two events across a full year before it will make that claim. And an indicator such as Vendor assurance reviews overdue, sitting at three against a warning threshold, is a statement about your own discipline rather than the supplier's.
Watch for concentration
The risk a supplier brings is not always the supplier failing. Supplier concentration in a single logistics partner is a risk about you: the exposure is that there is no second option, and the treatment is usually a control such as a secondary partner rather than anything the incumbent can do. Reviews are where concentration becomes visible, because you are looking at one relationship and counting what depends on it.
How the overdue count works
The subtitle of the Vendors list counts the suppliers whose next review date has passed. It is a plain count of dates, which is exactly what makes it trustworthy: nothing is inferred, nothing is weighted, and the only way to change it is to do the review and move the date.
Nothing moves the date for you
A risk carries a review cadence, so confirming a risk schedules its next review automatically. A vendor does not work that way: its date is a single field you own. That is deliberate, and it is worth knowing rather than discovering. If you set a date and never return to it, the count keeps rising, and it is telling you the truth.
An overdue vendor is usually a stale rating
The reason to clear the count is not tidiness. Behind every unreviewed relationship sit risks last rated when someone still believed the supplier's arrangements were as described. Review in RiskOS walks you through the risks themselves, worst first, but it works from the risks' own dates. The vendor list is the other half of the same question, and the two backlogs grow together.
Setting up many suppliers at once
If you are starting from an existing list of suppliers, bring them in rather than typing them. Import & Export imports vendors from CSV, with the same mandatory preview every import uses: it shows line by line what will be created, updated or skipped, names any problem it found, and lists any columns it ignored. Nothing is written until you confirm. A vendor whose name matches one you already hold updates that entry rather than making a second copy of it.
Imported suppliers arrive without dates. Work down the list once, setting a criticality and a date on each and staggering them as you go, and the routine is established. Everything RiskOS holds — vendors, risks, controls, actions, indicators, events and settings — goes into one file from File ▸ Back Up RiskOS…, so an afternoon spent setting dates is never an afternoon you can lose.
Troubleshooting
The overdue count will not go down
Moving a date on the risks a supplier carries does not change anything on the vendor. The count reads the vendor's own next review date and nothing else, so open the supplier and set that field forward. If the number drops by fewer than you expected, more than one vendor was past its date.
I cannot see which risks a supplier brings
The link is made on the risk, in its Context section, not on the vendor. If the vendor's panel shows nothing, the risks have not been attached yet. Open each risk that involves the supplier, add the vendor in Context, and the list on the vendor fills in as you go.
A review date keeps slipping and nobody notices
Make the backlog a number somebody has to look at. Create an indicator in Indicators for overdue assurance reviews, set a warning and a breach threshold, say which direction is bad, and record a reading on a cadence. Linked to the risks your suppliers carry, it sits in their Intelligence section with a live status, which is harder to ignore than a subtitle.
The supplier changed but the risk rating did not
Reviewing a relationship does not re-score anything on its own. If the review found that a control you were relying on is no longer operating, change that control's status — every risk deriving from it re-scores immediately. If the exposure itself changed, open the risk and set the inherent ratings, and the assessment is recorded with your reason.
Two entries look like the same company
This happens when a supplier is recorded once under a trading name and once under its legal entity. Search the list for both spellings, decide which name your colleagues would look for, and move the risks onto that one from each risk's Context section.
A routine that keeps third-party risk current
- Read the subtitle first. A glance at the overdue count in Vendors tells you whether this section needs an hour this week.
- Review from the vendor, not the risk. Working from the supplier shows you everything it carries at once, which is the only view in which concentration is obvious.
- Set the next date before you close the panel. The review is not finished when the conversation ends. It is finished when the date has moved.
- Re-score what the review changed. A finding that does not reach a rating, a control status or an action has not reached the register at all.
- Give every supplier a named owner. Unowned relationships are the ones that go stale, and the fix costs one field.
- Stagger new suppliers across the quarter. Dates set in a batch come back in a batch, and a batch never gets done.
- Log the failures as events. An outage recorded with its date, severity, cost and detection delay turns next year's review from an opinion into a measurement.
- Back up before a big tidy-up. ⇧⌘B writes everything to one file, wherever you choose to keep it.
Frequently asked questions
How often should a vendor be reviewed?
Set the interval from criticality. A supplier holding customer or regulated data, or one you could not operate without for a day, is worth a quarterly look. Something important but survivable suits twice a year, and a replaceable supplier suits annually. Choose an interval you will actually keep, because a promised review that never happens is worse than a longer one you meet.
What does the number in the Vendors list mean?
It is the count of suppliers whose next review date has passed. RiskOS puts it in the list's subtitle so the backlog is visible before you open anything. It is a plain count of dates, nothing weighted or inferred, and the only way to reduce it is to review a supplier and move its date forward.
Can I set a review cadence on a vendor?
A cadence — monthly, quarterly, annually — lives on a risk, where confirming a review schedules the next one for you. A vendor carries a single next review date instead, and you set it. When a review is finished, move that date to the interval you have chosen for that supplier before leaving the panel.
How do I see every risk one supplier brings?
Select the supplier in Vendors. The panel lists every risk linked to it in one place, alongside the criticality, the relationship owner, the review date and your notes. The links themselves are made on each risk, in its Context section, where assets and vendors sit together with their criticality shown.
What should a vendor review actually cover?
Whether the risks you have written down are still rated correctly. Read the supplier's linked risks and their residual scores, check whether the controls you rely on are operating rather than planned, look for actions promised last time and never finished, and check any indicator or event that has moved since. Then re-score what changed.
Can I import a list of suppliers?
Yes. Vendors import from CSV in Import & Export, with a mandatory preview showing line by line what will be created, updated or skipped, any problems found and any columns ignored. Nothing is written until you confirm, and a name matching an entry you already hold updates it rather than creating a duplicate.
Why is my supplier risk still scored the same after a review?
Because a review records attention, not a rating. If the review found a control no longer operating, change that control's status and every risk deriving from it re-scores at once. If the exposure itself has changed, set the inherent likelihood and impact on the risk, and the new assessment is kept with the reason you gave.
Do vendor details leave my Mac?
No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine unless you export or back it up yourself. Supplier names, notes and review dates are held with the rest of the register, and the only network use is Apple's App Store, for purchases.