Posted on

Vendor Risk Management Guide: 5 Risks SMBs Miss in 2026

Small business team reviewing a vendor risk inventory

Vendor risk management at a 10 to 500 employee company fails for a plain reason: every published program assumes a risk team, a platform license, and a vendor list that already exists. None of those are true at your size. The work that actually reduces third party exposure is smaller and less glamorous than the enterprise version. It starts with finding out who your vendors are, sorting them by what data and system access they hold rather than what they invoice, asking for evidence you can read in an afternoon, putting four clauses in the contract, and revoking access on the day a relationship ends. Those five moves close most of the gap. This guide walks each one, in the order a small team can execute them.

The Five Misses at a Glance

Our team runs third party reviews for companies that have no risk department and no intention of hiring one. The same five gaps show up almost every time:

  • There is no vendor inventory. Not a stale one, none at all. The list lives in three heads and a credit card statement, so nothing downstream can be prioritized.
  • Vendors get sorted by spend. A forty dollar per month tool with administrative API access to the mail tenant sails through, while a sixty thousand dollar hardware reseller that touches no data gets the paperwork.
  • A security report gets treated as a badge. Somebody confirms the vendor “has a SOC 2” and files the PDF without reading its scope, its exception list, or what it carved out to a subservice provider.
  • The contract says “reasonable security.” That phrase obligates nobody. It leaves you with no notification window, no visibility into subprocessor changes, and no deletion right at exit.
  • Offboarding cancels the invoice and leaves the access. The subscription lapses while the identity assignment, the API token, and the standing integration grant keep working.

Read as a set, those describe a company that is not careless, just unstaffed. Each fix below fits inside a normal work week.

Why Third Party Risk Breaks Down Without a Program

Third party risk breaks down at smaller companies because ownership is implied rather than assigned, so the work happens only when a customer questionnaire forces it. In the field we see two versions of this. In the first, the owner or general manager quietly holds the whole thing, approves new tools by replying “fine” to a Slack message, and has no way to remember six months later what was approved. In the second, IT holds it, but only for the tools IT installed, which leaves every departmental subscription outside the fence.

There is a counterargument worth holding. A very small company does have less to manage, and the enterprise cadence of annual reassessments across four hundred suppliers would be waste. Some practitioners argue a smaller firm should skip formal vendor work and pour those hours into its own controls, since the blast radius is smaller. That holds for a firm with four vendors and no shared data. It stops holding once a vendor has a live connection into your identity provider or file storage, because then the vendor’s incident becomes yours by default. Attackers reached that conclusion first, which is why supply chain ransomware attacks and vendor risk now travel together in nearly every intrusion we investigate.

The honest middle position: run a light program with real teeth on the handful of vendors that hold access, and almost no ceremony on the rest.

Where a Vendor Risk Management Guide Should Start: The Inventory

The vendor inventory is the one deliverable that unblocks everything else, and it comes from systems you already own rather than from a questionnaire nobody returns. We build it in one sitting from three sources, then reconcile.

Pull the list from money, not from memory

Start with accounting. Recurring card charges and ACH payments over the last twelve months produce a more truthful vendor list than any interview, because somebody had to pay. Export the statements, strip out travel and office supplies, and what remains is your candidate list. This catches the departmental subscriptions that never crossed IT’s desk, which in most of our engagements is between a third and half of the tools in use.

The objection to a money-first inventory is fair: it misses anything free. Free trials, community tiers, and the browser extension somebody installed on a Tuesday do not appear on a statement, and those often hold surprisingly broad permissions. That is exactly why money is the first source and not the only one.

Reconcile against identity and mail

Second source is your identity provider. Pull the list of applications with a sign-in assignment, then compare it against the money list. Anything in identity but not in accounting is a free or trialled tool. Anything in accounting but not in identity is either shadow authentication with local passwords or a service that never needed a login, and both answers matter.

Third source is the mail and file tenant’s application consent list, which is where the quiet risk sits. Standing OAuth grants read mail, list files, and send as a user, and they persist after a password change. Firms that handle other people’s financial records feel this first, which is why we treat consent review as routine work in Microsoft 365 management for accounting firms rather than as a one-off cleanup.

Tier Vendors by Data Access, Not by Invoice Size

Tiering by data access sorts your review time toward the vendors that can actually hurt you, which is rarely the ones with the largest invoices. The sort question is not what you pay. It is what the vendor holds and what it can reach.

The three questions that set the tier

We ask three things about each vendor and let the answers decide the tier. Does it store or process regulated or client data. Does it hold administrative or API access into a system of ours. Would a full outage on its side stop us billing, delivering, or communicating within a business day. Any yes puts a vendor in the top tier and earns it a real review. Two no answers and an outage answer of “we would be annoyed” puts it in the bottom tier and earns it a name on a list.

The opposing view deserves airtime. Spend is not a meaningless signal, since a large contract usually implies operational dependence, negotiating room, and a supplier who will answer your security questions. Some teams tier by spend because it is objective and takes ten minutes. The trade is a sort order that does not match your exposure, and the cheap tool with tenant-wide access ends up unreviewed.

Regulated data pulls a vendor up a tier

Where a vendor touches health, financial, or client-confidential records, the tier goes up regardless of contract size, because the obligation follows the data rather than the money. A transcription tool at twenty dollars a seat that processes clinical notes carries more regulatory weight than most of the line items above it, a pattern we work through constantly in healthcare data management. The same logic now applies to AI tooling, where the question is not only where the data rests but whether it becomes training input, which is the first thing we test in an AI risk assessment.

Once tiers exist, the review calendar writes itself: top tier annually and at renewal, bottom tier by exception only. If you want an outside read on where your own tiers should sit, an IT risk assessment produces that map, and our short risk assessment survey is a reasonable starting point.

Read the Evidence Instead of Filing It

Vendor security evidence is useful only when somebody reads the scope and the exceptions, and a report on file with nobody’s notes attached tells you nothing. A SOC 2 Type II report is strong evidence, and we ask for one from every top tier vendor. What it is not is a pass or fail stamp.

Three passes through a report, thirty minutes total

First pass, the scope section. Confirm the report covers the product you actually use, in the region you use it, over a period that has not gone stale. Vendors with several products routinely produce a report that covers a different one.

Second pass, the exception list. Every honest report has findings. Read what the auditor flagged, what management said in response, and whether the response is a fix with a date or a paragraph of comfort. A vendor with three documented exceptions and dated remediation is often safer than one with none, because the first is being audited seriously.

Third pass, the carve-outs. Note which functions were pushed to a subservice provider and excluded, because that is where your data goes without appearing anywhere in the report you were handed.

What to do when the vendor has no report

Smaller vendors frequently have no audit at all, and refusing to work with them is not always available. We ask four plain questions instead: who is your named security contact, is multi-factor authentication enforced on your administrative accounts, where does our data live, and what is your notification commitment once you confirm an incident. Written answers from an accountable human, kept in the vendor file, beat a report nobody read. Document the gap, note the compensating control on your side, and move on.

Four Contract Clauses That Beat “Reasonable Security”

Contract language protects you only when it names a behavior and a clock, which is why “vendor will maintain reasonable security” belongs nowhere in an agreement you sign. Four clauses do the work.

  • A notification window in hours. Ask for notice within twenty-four or forty-eight hours of the vendor confirming an incident that touches your data. “Promptly” is unenforceable and always resolves in the vendor’s favor.
  • Subprocessor change notice. You want to be told before the vendor moves your data to a new fourth party, with a right to object. Without it, your assessed vendor quietly becomes an unassessed chain.
  • Deletion and return on exit. Name the format, the deadline, and a written confirmation that copies and backups are gone. This is the clause that makes offboarding provable.
  • A named security contact and cooperation duty. During an incident you need a person who must respond, not a support queue. Add an obligation to cooperate with your investigation and share findings.

Two of those often get pushback from larger vendors who will not vary standard terms, and that is a real limit on this advice. When a vendor genuinely will not move, the fallback is to record the gap in the vendor file, tighten what you control on your side, and factor it into renewal. Manufacturing clients hit this constantly with platform vendors, which is one reason we push access hardening in Microsoft 365 management for manufacturers rather than waiting on contract concessions.

Offboard by Revoking Access, Not by Cancelling the Invoice

Vendor offboarding is finished when the access is dead, not when the subscription lapses, and the gap between those two events is where most lingering third party exposure lives. A cancelled card stops the billing. It does nothing to the identity assignment, the personal access token in a script, the standing integration grant on the mail tenant, or the company data sitting on a contractor’s phone.

The exit checklist we actually run

Remove the application assignment in the identity provider and confirm sign-in now fails. Revoke API tokens and service credentials, including the ones in automation scripts, then check whether anything broke, because a token nobody can find is still a live door. Withdraw the OAuth consent grant on the mail and file tenant. Wipe or unenroll any device the vendor held, which is one of the reasons mobile device management earns its cost at exit rather than at rollout. Remove shared drive and repository permissions, and finally send the deletion request the contract entitles you to, with a date and a reply you keep on file.

There is a reasonable argument for moving slower, since a same-day cut can break an integration or strand data you have not exported. Sequence it: export first, cut second, verify third, inside one week. What does not work is treating the invoice as the finish line.

Frequently Asked Questions

How many vendors should a small business formally review?

Only the top tier, which for most 50 to 250 person companies is between five and fifteen vendors out of an inventory of eighty or more. Formal review means evidence requested, contract clauses checked, and a dated file. Everything else stays on the inventory and gets looked at by exception.

Is a SOC 2 report enough for vendor due diligence?

A SOC 2 Type II report is strong evidence, not a verdict. It answers your question only if the scope covers the product you use, the period is current, and you have read the exception list and the subservice carve-outs. Absent that reading, having the report on file adds no protection.

How often should vendor risk reviews happen?

Top tier vendors on an annual cycle plus every renewal and every material change on their side, such as an acquisition, a new subprocessor, or a public breach. Lower tiers do not need a calendar entry. The inventory itself should be refreshed against accounting and identity data twice a year, because that is what drifts.

What is the fastest way to reduce third party risk this quarter?

Build the inventory, then review standing OAuth grants and administrative API access on your mail and file tenant. Those grants are the shortest path from a vendor’s compromise into your data, and revoking the unused ones takes hours rather than weeks.

Who should own vendor risk when there is no risk team?

One named person with authority to say no to a new tool, supported by whoever manages identity. Ownership matters more than seniority. The failure mode is not the wrong owner, it is a program everybody assumes somebody else is running.

Make Vendor Risk an Operating Rhythm

The companies that handle third party risk well at this size are not the ones with the most documentation. They made it a rhythm: the inventory gets refreshed twice a year against accounting and identity, new vendors get tiered at purchase rather than at audit time, top tier evidence gets read rather than filed, four clauses go into every agreement, and access dies on the last day of the relationship. None of that needs a platform license or a new hire, only an owner and a calendar that survives a busy quarter.

If you would rather not build the first inventory and tier map alone, our team does this with SMB leadership every week, and we will tell you plainly which vendors deserve a real review and which just need a name on a list. Book a free strategy call and we will start with the inventory you do not have yet.

Related Posts

Matt Rosenthal