Template
Vendor Continuous Monitoring Checklist
A seven-step programme across five sections, for signal coverage, 24-hour triage, vendor incidents and triggered re-assessment.
An editable 15-page monitoring programme for the period between assessments. Every step names its goal, the actions, the common mistake to avoid, and the evidence that closes it.
What’s inside
- A readiness page capturing vendor or programme name, business owner, TPRM analyst, monitoring period, start date, primary tool, triage channel and review cadence
- A seven-step workflow from mapping signal sources per tier through rating tooling, news and regulatory feeds, triage rules and the incident runbook to the quarterly review pack and triggered re-assessments
- A signal-source matrix setting ten sources against Critical, High, Medium and Low tiers, with a setup record for tool, threshold, owner and last tested
- A monitoring register, one row per vendor, and a quarterly Critical-vendor review pack covering posture, findings, material events, concentration exposure and the DORA Critical ICT flag
- A 24-hour triage rubric across four severity levels, a six-question vendor-incident questionnaire, the response runbook, and the red-flag and re-assessment logs
The tiering is what keeps it workable: Critical vendors take most signals daily while Low vendors take a breach notice and an annual news check, so Critical signals are not buried in Low-tier noise. Escalation is time-bound throughout — a confirmed breach or a four-hour outage on a Critical service pages the CISO, business owner and Legal within the hour.