V0.1 CONCEPT NOTE COLLECTION
Vendor Governance Concept Notes
Five concept notes on vendor and third-party risk governance.
Topics in this research area
v0.1 concept note. Full framework treatment forthcoming.
This is a collection of version 0.1 concept notes on vendor and third-party risk governance. It is a separate collection from the fifteen-framework library at /frameworks, which holds version 1.0 material with full primary-source treatment.
The notes here are early concept definitions, published to establish a dated public record. Full framework treatment is forthcoming, and none of these notes yet carries the primary-source depth of the Authorization Layer library.
Published August 2, 2026.
Free to read and cite with attribution to Sougata Roy and sougataroy.com. Do not republish, rebrand, or claim authorship of any framework, term, or model as your own.
In this collection
Five concept notes
v0.1 concept note
The Vendor Reassessment Lifecycle
Vendor risk is authorized once, at onboarding, and rarely revisited on any schedule tied to what actually changes in the relationship. The Vendor Reassessment Lifecycle names the phases an organization moves through as the gap between its original assessment and the vendor's current posture widens, and the triggers, subprocessor changes, acquisition, incident, contract renewal, regulatory shift, that should force a review before an audit forces it instead.
Read the concept note ->v0.1 concept note
The Subprocessor Drift Map
A method for surfacing what has changed beneath a vendor relationship since the original assessment, specifically the subprocessors, fourth parties, and fifth parties added, removed, or replaced without a corresponding review of what that changes about your organization's exposure.
Read the concept note ->v0.1 concept note
The Fourth-Party Disposition Protocol
What an organization does once drift is found: the decision path from a detected change to a formal disposition, re-authorize at an amended scope, restrict, or terminate, with a named owner and a recorded rationale.
Read the concept note ->v0.1 concept note
The Vendor Authorization Record
A governance artifact, not an analytical framework: named owner, authorized scope, review date, and trigger list, for a specific vendor relationship, in one document. The record a vendor risk committee should be able to produce on demand, and the record most TPRM programs currently cannot.
Read the concept note ->v0.1 concept note
The Organizational Vendor-Governance Maturity Model
A diagnostic for where an organization's actual vendor reassessment discipline sits, as distinct from where its TPRM policy documents claim it sits. Scores the gap between vendor count and vendor relationships under active, scheduled review.
Read the concept note ->