Business Consultancy
Vendor risk management at scale: why a spreadsheet stops working past a certain size
14 August 2026
Nearly every organisation starts vendor tracking the same way: a spreadsheet, one row per supplier, updated by whoever onboarded them. It works fine at twenty vendors. Past a hundred - which most growing organisations pass without anyone deciding to - it quietly stops working, and nobody notices until a renewal is missed or an auditor asks for evidence nobody can produce.
The failure mode is always the same: ownership of the spreadsheet is unclear, updates depend on someone remembering to make them, and there's no active alerting when a contract's notice period is closing or a vendor's compliance documentation has lapsed. The information technically exists somewhere in the organisation; practically, nobody can answer "which of our critical vendors don't have a current NDA?" without a multi-day manual audit.
This is precisely the class of problem that needs a system with active state, not a passive document: a vendor register that tracks compliance flags (NDA signed, ISO 27001 status, cyber assessment completed) per vendor, contracts with real end dates and notice periods, and automatic urgency flagging as those dates approach - not a column someone has to remember to eyeball.
We help organisations design this as part of vendor and contract management advisory, and we built exactly this capability into our Business Operations Platform's VendorHub module for organisations that want the governance built into their own systems rather than tracked externally.
The advisory and the software are deliberately separable - we'll design the governance model and vendor risk framework regardless of what system, ours or otherwise, ends up running it day to day.
Frequently asked questions
At what number of vendors does a spreadsheet actually stop working?
There's no hard threshold, but in practice organisations we work with start losing reliable visibility somewhere between fifty and a hundred active vendors, especially once more than one person is responsible for updates.
What's the minimum viable vendor governance model?
A single system of record per vendor with compliance status, contract dates and an owner, plus active alerting on approaching renewal or notice-period dates - the alerting is what most spreadsheet-based approaches are missing, not the data itself.
Do you only recommend your own software for this?
No - the vendor governance framework and risk model we design is independent of the underlying system. We'll implement it in your existing tooling, ours, or a third party's, based on what actually fits.
Want to talk this through?
Happy to go into more detail, or look at how it applies to your own setup.
Speak with us