# Vendor compliance you can see, not just assume.

XGRC® enables organisations to onboard, vet, and monitor suppliers and contractors through a structured process. Every vendor document, expiry date, and risk score is tracked in one place, so third-party compliance status is always known.

**Frameworks:** ISO 9001, ISO 27001, ISO 37301, ISO 37001, Third-Party Risk, Supplier Compliance, Contractor Compliance

## Unmonitored vendors create risk that surfaces at the worst time.

When vendor documents are tracked by email and expiry dates are missed, a non-compliant contractor can be on site — or in your supply chain — long before anyone notices.

- Vendor documents tracked by email with no central repository
- Certificates and insurance lapse without anyone noticing
- Vetting applied inconsistently depending on who onboards the vendor
- No real-time view of which vendors are actually compliant today

## A structured, repeatable vendor management process.

- Onboard vendors through a structured registration process
- Vet vendors consistently against defined risk criteria
- Set compliance requirements by vendor category
- Track document expiry with automated renewal reminders
- Score and monitor vendor risk on an ongoing basis
- Report on compliance status across the full vendor base

## How it works

- Structured vendor onboarding and vetting workflows
- Central document repository per vendor
- Automated expiry tracking and renewal alerts
- Configurable risk scoring by vendor category
- Real-time dashboards on vendor compliance status

## On the platform

**One live view of every vendor** — XGRC Compliance Hub gives suppliers and contractors a portal to upload and maintain their own documentation, while internal teams validate submissions, track expiry dates, and monitor risk scores in real time — across the entire vendor base.

## The same vendor process, without the manual chasing.

| Manual approach | With XGRC® |
| --- | --- |
| Documents tracked by email | Portal-based document management |
| Expiry dates missed until an incident happens | Automated expiry tracking and alerts |
| Inconsistent vetting standards | Consistent, risk-based vetting |
| No consolidated compliance view | Real-time compliance dashboards across all vendors |

## One platform across every third-party relationship.

- Supplier onboarding and vetting
- Contractor compliance management
- Third-party risk scoring
- Ongoing document and expiry management

## Frequently asked questions

### What is vendor management software?

Vendor management software onboards, vets and monitors suppliers and contractors in one place, tracking documents, expiry dates and risk scores so third-party compliance status is known at any moment rather than assumed.

### Does XGRC® flag expiring vendor certificates automatically?

Yes. Document expiry is tracked with automated renewal reminders, so a lapsed insurance certificate or expired vendor certification is flagged before it becomes a compliance gap.

### Can vendor risk scoring differ by category?

Yes. Risk criteria and vetting requirements are configurable by vendor category, so a high-risk contractor and a low-risk supplier are not assessed against the same checklist.

### Which standards does vendor management align to?

Vendor management aligns to ISO 9001, ISO 27001 and ISO 37301, alongside third-party risk and supplier and contractor compliance practice more broadly.

## Related solution

- [XGRC® Compliance Hub](https://xgrcsoftware.com/compliance-hub)

---

Source: https://xgrcsoftware.com/use-cases/vendor-management
