V0.1 CONCEPT NOTE
The Vendor Reassessment Lifecycle
Version 0.1 concept note on vendor and third-party risk governance.
Topics in this research area
v0.1 concept note. Full framework treatment forthcoming.
Disambiguation
Distinct from the Authorization Coverage Lifecycle, which describes this same shape for AI agents inside an organization's own tenant. This is the external version: the actor drifting is not yours, and by default you are not positioned to see it drift.
Vendor risk is authorized once, at onboarding, and rarely revisited on any schedule tied to what actually changes in the relationship. The Vendor Reassessment Lifecycle names the phases an organization moves through as the gap between its original assessment and the vendor's current posture widens, and the triggers, subprocessor changes, acquisition, incident, contract renewal, regulatory shift, that should force a review before an audit forces it instead.
Published August 2, 2026.
Free to read and cite with attribution to Sougata Roy and sougataroy.com. Do not republish, rebrand, or claim authorship of any framework, term, or model as your own.