How to track vendor risk on Mac
RiskOS keeps every supplier you depend on — its criticality, its owner, its next review and every risk it brings — on one record you can open in a second.
Third parties are where somebody else's bad week becomes yours. A payroll provider goes dark, a logistics partner loses a depot, a supplier is bought by a rival — and every one of those lands on your register as your exposure and your board's question. What makes it manageable is knowing, before anything happens, which supplier sits behind which risk, and who is supposed to be watching them.
A vendor record does not carry a score of its own. Criticality is your judgement about how much depends on the relationship. The numbers come from the risks you link to it, each scored in the usual way.
Where vendors live
The sidebar groups the register into sections, and Vendors sits under Inventory, beside Assets. Assets are the things you are protecting. Vendors are the third parties you depend on to run them, supply them or hold your data inside them.
Choose Vendors and the list fills the middle of the window. Its subtitle counts how many vendor reviews are overdue, so the number you most need is visible before you click anything. Select a row and the panel on the right opens on that vendor: criticality, relationship owner, next review date, your notes, and every risk you have linked to it.
Record a vendor, step by step
-
Open the vendors list
Choose Vendors in the sidebar, under Inventory. Read the subtitle above the list first: it tells you how many vendor reviews are already overdue, which is usually the reason you came here.
-
Create the vendor record
Press ⌘N. In every section that shortcut creates the kind of item the section holds, so in Vendors it gives you a new supplier to fill in. Add one record per relationship you actually manage, not one per invoice you receive.
-
Name the organisation you contract with
Use the name on the contract, and use it the same way every time. Where a reseller sits between you and the company running the service, decide which of the two you are tracking and be consistent: you can only review a relationship you have a person for.
-
Set the criticality
Criticality answers one question: how much of your organisation stops or becomes indefensible if this supplier stops. Rate the whole relationship rather than the size of the invoice. The rating becomes a badge that travels with the vendor and appears wherever it is shown, including inside every risk it is attached to.
-
Name a relationship owner
Put a person in the relationship owner field, not a department. This is whoever picks up the phone when the supplier has a bad morning, chases the assurance pack that never arrived, and answers for the relationship at a review. A critical vendor with no named owner is the commonest gap in any third-party register.
-
Set the next review date
Give the vendor a date by which you intend to look again, chosen from how much depends on the supplier rather than from a company-wide default. That single field is what the list counts in its subtitle, so setting it honestly is what turns the vendors list into a worklist instead of a directory.
-
Write the notes someone else would need
Record what this supplier does for you, what of yours they hold, and what assurance you have seen and when. Write it for the colleague who inherits the relationship in eighteen months, because that is who reads it. Notes also carry the detail that fits no field: the notice period, the escalation contact, the site that matters.
-
Link the risks this vendor brings
Open a risk in Risks, open its Context section, and add the vendor there. Context is where assets and vendors attach to a risk, each shown with its criticality badge, so anyone reading the risk can see that the exposure runs through a supplier you cannot replace at short notice. Repeat for every risk the supplier is behind.
-
Read the vendor record as a whole
Go back to Vendors and select the supplier again. Every risk you linked now sits on one record — the view you want in front of you before a renewal meeting, or after a supplier tells you something unexpected. If the list is shorter than the relationship deserves, that is a finding in itself.
What a vendor record carries
The record is deliberately short: five things about the supplier, and then the risks. Each field earns its place by changing something later rather than by filling a form.
| Field | What it holds | What it changes later |
|---|---|---|
| Name | The organisation as you contract with it. | How you find it, and whether an import updates this record or creates a second one. |
| Criticality | How much depends on the relationship. | The badge shown on the vendor and inside the Context section of every risk linked to it. |
| Relationship owner | The person who answers for the supplier. | Who is asked at a review, and who is chased when nothing has been asked for a year. |
| Next review date | When you intend to look again. | The overdue count the vendors list carries in its subtitle. |
| Notes | What they do, what they hold, what assurance you have seen. | Whether the relationship survives the person who set it up leaving. |
| Linked risks | Every risk attached to this vendor. | The exposure you read before a renewal, an incident or a board question. |
Criticality is about dependence, not spend
The temptation is to rate suppliers by what they cost, and dependence often disagrees. A small service that nothing else replaces can matter more on a bad morning than the largest figure in your annual spend. Ask what would stop, how long it would stay stopped, and whether anyone outside the organisation would notice.
Connecting vendors to the risks they bring
A vendor on its own is an entry in a directory. A vendor with risks attached is part of your register — scored, treated, reviewed and reported like everything else.
Link from the risk's Context section
Attachment happens on the risk. Open it, open Context, and add the vendor — the same section that carries the assets the risk touches. Once attached, the vendor appears on the risk with its criticality badge, and the risk appears on the vendor's own record. One action, both views.
One vendor, several risks
Most real suppliers bring more than one exposure, and they are rarely the same shape. Resist folding them into a single row called "supplier risk": a treatment plan for a concentration problem looks nothing like a plan for an outage. Separate risks keep separate owners, controls and scores, and the vendor record gathers them back together.
The scores stay separate too, which is the point. A concentration risk such as RSK-0011 can sit at a residual of 12 while an outage risk such as RSK-0003 sits at 8, and each earns its own treatment strategy and its own review date. Collapsed into one row, the pair would be scored once, treated once and understood by nobody.
| Ref | Risk | Owner | What the supplier decides for you |
|---|---|---|---|
| RSK-0011 | Supplier concentration in a single logistics partner | S. Ramirez | Whether volume can move elsewhere when one partner stops. |
| RSK-0003 | Payroll provider suffers a prolonged outage | S. Ramirez | Whether people are paid on the day they expect to be. |
| RSK-0012 | Legacy authentication service reaches end of support | J. Whitfield | When support ends, and how long you have to replace it. |
Give third-party risk its own category
Set the category on those risks to Third-Party / Vendor and a second route through the register opens. Search in Risks covers a risk's category as well as its title, reference, owner, detail and tags, so searching for the category name gathers them. Sort the table by residual score and you can read supplier exposure across every owner and business unit at once — including the risks written up by people who never think of themselves as doing vendor management.
Keep that arrangement if it is one you return to. Right-click the table header to show, hide and reorder columns, and RiskOS remembers how you leave it, so the owner and review columns that matter for third-party work stay where you put them.
Hold suppliers to a tighter appetite
Appetite is the highest residual score you tolerate, and any category can carry its own threshold with the reasoning behind it, set in Settings ▸ Appetite. If risk handed to someone else deserves less tolerance than risk you run yourself, say so there. Every third-party risk above that threshold is then flagged wherever it appears, and your rationale is on the record for whoever asks why the bar is lower here.
Link the controls that reduce supplier risk
Supplier risks take controls like any other: a second source, a notice period you actually monitor, a tested fallback. Link them in the risk's Controls section and the residual score follows the effectiveness of what is genuinely operating. A planned control reduces nothing yet, which is the honesty you want when the mitigation is a secondary supplier nobody has placed an order with.
Keeping vendor reviews on schedule
Third-party risk decays quietly. Nothing fails, so nobody looks, and two years later the assurance pack on file describes a service that has been rebuilt twice. A date on every record and one number counting the misses is most of the discipline.
Work from the overdue count
The vendors list keeps the overdue total in its subtitle, so how far behind you are is always on screen rather than something you assemble. Treat it the way you treat overdue risk reviews: clear it down, and set the next date as you close each one rather than leaving it blank.
Let an indicator count the misses
Where vendor assurance is a standing obligation, make it a measured number instead of a memory. An indicator in Indicators records a value on a cadence with a warning threshold and a breach threshold, and you tell RiskOS which direction is bad. Vendor assurance reviews overdue, recorded monthly, turns the backlog into something with a trend and a history. Link it to the oversight risk it watches and the risk's Intelligence section shows its live status beside the rating.
Record it when a supplier actually fails
When a vendor does let you down, log it in Events with the date it occurred, the date you detected it, the severity as experienced and what it cost, and link it to the risk it came from. Detection delay is often the most useful field on a third-party event: hearing about an outage from a customer rather than from the supplier is itself a finding. Where a risk materialises more often than its rating implies, RiskOS says so and suggests what the observed frequency would justify.
Bringing in suppliers you already list
A long supplier inventory does not have to be typed one record at a time. Choose Import & Export and import vendors from CSV. A template for the format ships in the Examples folder inside RiskOS, so you can shape a list of suppliers to match before you bring it in.
Every import shows a preview first, and nothing is written until you accept it. The preview goes line by line: what will be created, what will be updated, what will be skipped, any problems found and any columns ignored. A vendor name matching an existing record updates that record rather than adding a second one, which is what makes a re-import safe as your list grows. Out-of-scale values are clamped, unknown values fall back, and every problem is named rather than swallowed.
Once the inventory is in, protect it. RiskOS writes everything to a single file wherever you choose through File ▸ Back Up RiskOS… (⇧⌘B) — risks, history, controls, actions, assets, vendors, frameworks, indicators, events and settings together, so a restore brings back the relationships as well as the register.
Troubleshooting
The list says reviews are overdue and I cannot see which
The subtitle counts them; the date itself sits on each record. Open the vendors in turn and read the next review date in the panel: the ones already in the past are the ones being counted. If a vendor you believe is late is not among them, its next review date is probably empty rather than past — an empty date cannot be overdue, so give every record a date before you lean on the count.
A vendor I added shows no risks
Risks attach from the risk, not from the vendor. Open the risk in Risks, open its Context section and add the vendor there; it then appears on both records. A vendor with no linked risks is showing you the truth — nobody has yet written down what this supplier could do to you.
My import created new vendors instead of updating the ones I had
Matching is by name, and the name has to match what is already recorded. A stray suffix, different spacing or an abbreviation expanded is enough for the preview to treat a row as a new supplier. The preview exists for this: read the created and updated counts before you accept it, adjust the names in your file, and run it again.
Searching the register for a supplier's name finds nothing
Search in Risks looks across a risk's title, reference, category, owner, detail and tags. If the supplier's name appears only on the vendor record, that search has nothing to match. Name the supplier in the risk's description, or tag the risk with it, and the register finds the exposure as readily as the vendors list finds the relationship.
A critical vendor's risks do not look critical
That combination is legitimate and worth reading carefully. Criticality describes dependence on the relationship; the score describes one exposure once controls are taken into account. A supplier you cannot do without, whose failure modes are well covered, looks exactly like this. What deserves a second look is the opposite: low scores on a critical supplier with nothing linked in the risk's Controls section.
A working routine for third-party risk
- Start from what you would miss. Record the suppliers whose failure would be felt outside your team this week, and let the long tail arrive by import afterwards.
- Give every critical relationship a person. A criticality rating with no relationship owner is a label. The owner is what makes the review happen.
- Write the risk, not the supplier. "Payroll provider suffers a prolonged outage" can be scored, treated and reviewed. "Payroll supplier" cannot.
- Date every record. Set the next review date the moment you finish a review, so the overdue count stays honest without anyone having to remember.
- Read the category view monthly. Search the risk table for Third-Party / Vendor, sort by residual, and look at the top of it even in a quiet month.
- Log the small failures. A missed service level that cost an afternoon is worth an event. Two in a year change what the register may say about likelihood.
- Borrow a starting point. The Risk Library carries worked third-party examples with a suggested rating, a typical treatment and controls to consider; entries arrive as drafts for you to re-rate.
Frequently asked questions
How do I track third-party risk on a Mac?
Record each supplier under Vendors in RiskOS with its criticality, a named relationship owner, a next review date and notes. Then attach the risks that supplier brings from each risk's Context section. The vendor record gathers them in one place, and the vendors list counts how many reviews have fallen overdue.
What does vendor criticality mean?
It is your judgement of how much depends on the relationship — what would stop, for how long, and whether anyone outside the organisation would notice. It is not a risk score and it is not the contract value. RiskOS shows it as a badge on the vendor and inside every risk the vendor is linked to.
How do I link a vendor to a risk?
Open the risk, open its Context section, and add the vendor there. Context is where assets and vendors attach to a risk, each with its criticality badge. The link works both ways once made: the vendor appears on the risk, and the risk appears on the vendor's own record without any further step.
Can I import a list of vendors I already keep?
Yes. Import vendors from CSV in Import & Export, using the template that ships in the Examples folder. A preview shows line by line what will be created, updated or skipped, along with any problems and any columns ignored. Names matching existing records update them, so a re-import will not duplicate your inventory.
How do I know which vendor reviews are overdue?
The vendors list carries the overdue count in its subtitle, visible as soon as you open the section, and the dates themselves sit on the records. A vendor with an empty next review date is never counted as overdue, which is why putting a date on every relationship matters more than choosing the perfect interval.
Should each supplier have its own risk?
Write risks by failure mode rather than by supplier. One vendor often brings several: an outage, a concentration, a data exposure, a contract lapse. Each needs its own owner, controls and score, and each attaches to the same vendor record — which lets you read the whole relationship in one view without collapsing it into one row.
Does a vendor's criticality change a risk score?
No. A score comes from the inherent likelihood and impact you rate and the effectiveness of the controls you link. Criticality is context: it tells the reader that the exposure runs through a supplier you depend on. Where third-party risk warrants less tolerance, set a tighter appetite threshold for the category in Settings instead.
Does my supplier information leave my Mac?
No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine except when you export or back it up yourself. Vendor names, notes and linked risks are held with the rest of the register, and the only network use is Apple's App Store, for purchases.