This section captures essential identification and contractual metadata to establish the evaluation context. All fields marked mandatory must be completed to proceed with the assessment.
Supplier Legal Entity Name
Unique Supplier ID/Vendor Number
Registered Business Address
Contract ID/Purchase Order Number
Contract Title or Service Description
Contract Effective Start Date
Contract Expiration/End Date
Total Contract Value (LC)
Contract Strategic Classification
Strategic Partnership
Critical Operational
Tactical Preferred
Commodity Transactional
Emerging Vendor
Primary Spend Category
Information Technology
Professional Services
Manufacturing & Production
Logistics & Supply Chain
Facilities & Real Estate
Marketing & Communications
Human Resources
Financial Services
Raw Materials
Other
Primary Vendor Contact Name
Vendor Contact Email
Vendor Contact Phone
Internal Procurement Lead Name
Current Contract Status
Active & Performing
Active with Issues
Up for Renewal within 6 Months
Expired but Extended
Terminated/Transitioning
Is this supplier considered a critical vendor to core operations?
Describe the operational impact and contingency plans if this vendor were to fail:
Evaluate the supplier's performance against contracted Service Level Agreements (SLAs) and quality deliverables. Provide quantitative evidence where possible. Poor performance ratings will trigger mandatory remediation planning questions.
Overall SLA Performance Rating (Past 12 Months)
If overall rating is 2 stars or below, provide detailed Performance Improvement Plan:
Critical SLA Metrics Achievement Details
SLA Metric Description | Contractual Target | Actual Achievement % | Number of Breaches | Severity Rating (1-5) | ||
|---|---|---|---|---|---|---|
A | B | C | D | E | ||
1 | System Uptime Availability | 99.9% | 99.5 | 3 | ||
2 | Critical Incident Response Time | < 1 hour | 95 | 2 | ||
3 | ||||||
4 | ||||||
5 | ||||||
6 | ||||||
7 | ||||||
8 | ||||||
9 | ||||||
10 |
Were there any critical SLA breaches causing business disruption?
Detail each breach: date, impact, root cause, and vendor response effectiveness:
On-Time Delivery Rate for All Deliverables (%)
Deliverable Quality & Accuracy Score (1-5 scale)
Average Time to Resolve Issues (Hours)
Total Number of Escalations Required
Customer Satisfaction Score (1-10 scale)
Performance Trend Compared to Previous Year
Significantly Improved
Moderately Improved
Stable
Moderately Declined
Significantly Declined
Describe specific innovation or value-add contributions made by the vendor this year:
Rate the following service quality dimensions:
Poor | Below Average | Average | Good | Excellent | |
|---|---|---|---|---|---|
Technical Competency | |||||
Communication Clarity | |||||
Proactive Problem Management | |||||
Flexibility & Adaptability | |||||
Knowledge Transfer Effectiveness |
Has the vendor consistently met reporting and governance meeting obligations?
Explain reporting failures and required corrective actions:
Assess the vendor's financial health and operational resilience. This section identifies potential risks that could impact service continuity. High-risk ratings require detailed mitigation strategies.
Overall Financial Health Rating (1-5 scale)
Credit Rating Agency & Score (if applicable)
Vendor's Annual Revenue (Most Recent Fiscal Year)
Net Profit Margin (%)
Debt-to-Equity Ratio
Does the vendor maintain adequate professional liability insurance coverage?
Provide insurance certificate expiry date and coverage amount:
Explain the risk exposure and required remediation plan to obtain coverage:
Has the vendor's Business Continuity & Disaster Recovery plan been tested within the last 12 months?
Provide schedule for next test and interim risk mitigation measures:
Operational Risk Level Assessment
Low Risk - Stable Operations
Medium Risk - Minor Concerns
High Risk - Significant Concerns
Critical Risk - Immediate Action Required
If risk level is High or Critical, detail specific risks and required mitigation actions:
Does the vendor rely on critical subcontractors for primary service delivery?
List key subcontractors and describe your oversight and risk management approach:
Were there any force majeure events affecting service delivery this year?
Describe event impact, vendor response, and your business continuity activation:
Describe any material changes in vendor ownership, leadership, or organizational structure:
Number of active contracts with this vendor across enterprise
Verify adherence to contractual compliance obligations and cybersecurity standards. Non-compliance findings must be accompanied by corrective action plans and timelines. This section is critical for data protection and regulatory adherence.
Select all applicable certifications the vendor currently holds (provide evidence):
ISO 9001 (Quality Management)
ISO 27001 (Information Security)
ISO 27701 (Privacy Management)
SOC 2 Type II
PCI DSS (Payment Card Industry)
HIPAA Compliance (if applicable)
GDPR/CCPA Privacy Compliance
None of the Above
Are all claimed certifications current and verified by independent audit?
Identify expired or unverified certifications and required remediation timeline:
Has a comprehensive Data Processing Agreement (DPA) been executed and is it current?
Explain the gap and urgent actions required to execute DPA:
Were there any cybersecurity incidents, data breaches, or unauthorized access events in the past 12 months?
For each incident, provide: date, nature of incident, data affected, root cause, and resolution effectiveness:
Has the vendor conducted independent penetration testing or security audits this year?
Provide schedule for next security assessment and interim security measures:
Overall Security & Compliance Audit Result
Pass - No Findings
Pass - Minor Findings Addressed
Conditional Pass - Major Findings Remediation Required
Fail - Critical Non-Compliance
If conditional pass or fail, detail all findings and vendor's remediation plan with deadlines:
Rate the maturity of the following cybersecurity controls (1=Basic, 5=Advanced):
Access Control & Identity Management | |
Data Encryption (At Rest & In Transit) | |
Network Security & Segmentation | |
Vulnerability & Patch Management | |
Incident Response & Recovery | |
Security Awareness Training | |
Third-Party Risk Management | |
Logging & Monitoring |
Which data protection measures are contractually required and confirmed implemented?
Data Residency Controls
Encryption Standards (AES-256)
Multi-Factor Authentication
Regular Backups with Testing
Data Retention & Disposal Policies
Privileged Access Management
Security Information & Event Management (SIEM)
Data Loss Prevention (DLP)
Has the vendor complied with all applicable regulatory and industry-specific requirements?
Identify specific regulatory gaps and corrective actions:
Are there any outstanding compliance violations, fines, or legal disputes?
Describe each issue, potential liability, and resolution status:
Overall Compliance & Cybersecurity Maturity Score (1-5)
Upload latest compliance certificates, audit reports, and security assessments (zip multiple files if needed):
Final assessment consolidation, stakeholder feedback, and formal sign-off. This section captures the overall recommendation and accountability for the evaluation outcomes.
Internal Stakeholder Satisfaction Ratings (1-5 stars):
Business Unit Satisfaction | |
IT/Tech Team Satisfaction | |
Finance Team Satisfaction | |
Legal & Compliance Satisfaction | |
End-User Satisfaction |
Vendor Self-Assessment Score (as provided by vendor)
Key Strengths and Competitive Advantages of this Vendor:
Critical Risks, Concerns, or Red Flags Identified:
Final Recommendation for Contract Status
Retain & Extend - High Performer
Retain with Conditions - Improvement Plan Required
Place on Probation - 90 Day Review
Do Not Renew - Transition to Alternative Vendor
Immediate Termination - Critical Failure
If 'Retain with Conditions' or 'Probation', specify detailed conditions and measurable improvement targets:
Recommend contract renewal or extension?
Provide alternative sourcing strategy and transition timeline:
Recommended Contract Duration (Months) if Renewing
Procurement Lead Summary Comments & Justification for Recommendation:
Vendor Executive Acknowledgement & Comments (to be completed by vendor):
Procurement Lead Signature & Approval
Vendor Executive Signature (Acknowledgement)
Evaluation Completion Date
Attach supporting documentation: performance reports, audit findings, risk assessments, and correspondence:
To configure an element, select it on the form.