Person signing a contract on a desk

Vendors · 21 June 2026

Vendor registers that survive an audit conversation

An auditor who asks “show me your vendor register” is not asking for a zip file of questionnaires. They are asking whether you know who touches personal information, food contact surfaces, or fatigue-critical subcontracting — and whether anyone updates that knowledge when a contract renews.

The Vendor Risk Mapping Intensive at Siteflowbase is two days because most registers fail for social reasons, not software reasons. The person who built the spreadsheet left. The clauses you “monitor” cannot be observed. The questionnaire is three years old and the vendor changed processors twice.

Collect less

If a data point never changes a decision, stop collecting it. Insurance certificates matter when you would actually call the broker. SOC reports matter when you have someone who can read them. A hundred columns of “cyber maturity scores” copied from a vendor’s marketing site do not matter. They age into embarrassment.

Name a deputy

Every critical vendor row needs an owner and a deputy. The deputy is not honorary. They must know where the contract lives and what evidence is due. In regional logistics this is often the difference between a clean conversation and a week of forwarded emails while someone is on leave.

Questionnaires are not controls

A completed form is evidence that a form was completed. A control is something you can watch: access logs, delivery temperature records, licence expiry dates, a right-to-audit you have practised. If you cannot describe the observation, do not list the questionnaire as a mitigator in a residual-risk note.

Privacy Act reforms in Australia have made processor change more visible in conversations. That does not mean every small operator needs an enterprise GRC platform. It means the register should record where personal information goes, who approved it, and the review date. The planning method is the same one we use on the planning desk.