{"version":"0.2.0","built_at":"2026-10-10T20:58:14.188Z","license":"CC BY 4.0 © Mike Reams","canonical":"https://catalog.mikereams.com","capability":{"id":"BC-640.40","name":"Supplier Risk","level":2,"parent_id":"BC-640","l1_id":"BC-640","industry":"cross-industry","macro_id":"MC-60","path":["Supplier & Contract Management","Supplier Risk"],"description":"See which suppliers could hurt the business if they failed, were breached or behaved badly, watch those signals continuously and have a plan for the ones that matter most.","aliases":["Third-Party Risk Management","Vendor Risk"],"in_scope":["Risk tiering by criticality and spend","Monitoring of financial and cyber and geographic and ethical risk","Mitigation and exit plans for critical suppliers"],"out_of_scope":["Enterprise risk framework and appetite (see BC-130)","Security assessment of a supplier's technology (see BC-760)"],"csdm_note":null,"status":"active","successor_id":null,"child_ids":["BC-640.40.10","BC-640.40.20","BC-640.40.30"]},"crosswalk":{"realized_by":[],"used_in":[{"vs_id":"VS-30","vs":"Procure-to-Pay","stage_id":"VS-30.20","stage":"Source & Select Supplier","order":2,"via":null}],"patterns":[],"stacks":[],"books":[]},"ancestors":[{"id":"BC-640","name":"Supplier & Contract Management","level":1}],"children":[{"id":"BC-640.40.10","name":"Supplier Risk Tiering","level":3,"child_count":0},{"id":"BC-640.40.20","name":"Continuous Risk Monitoring","level":3,"child_count":0},{"id":"BC-640.40.30","name":"Supplier Contingency Planning","level":3,"child_count":0}]}