Skip to main content

v0.1 concept note. Full framework treatment forthcoming.

Disambiguation

Distinct from the Authorization Coverage Lifecycle, which describes this same shape for AI agents inside an organization's own tenant. This is the external version: the actor drifting is not yours, and by default you are not positioned to see it drift.

Vendor risk is authorized once, at onboarding, and rarely revisited on any schedule tied to what actually changes in the relationship. The Vendor Reassessment Lifecycle names the phases an organization moves through as the gap between its original assessment and the vendor's current posture widens, and the triggers, subprocessor changes, acquisition, incident, contract renewal, regulatory shift, that should force a review before an audit forces it instead.

Published August 2, 2026.

Published under CC BY 4.0. Free to reproduce, adapt, translate, and use commercially, including inside your own governance program, with attribution to Sougata Roy and a link to this page. Attribution is a condition of the license. Claiming authorship is not attribution. Full terms at sougataroy.com/rights

Cite this framework

Sougata Roy, "The Vendor Reassessment Lifecycle", Version 0.1, August 2, 2026, https://sougataroy.com/frameworks/vendor-governance/vendor-reassessment-lifecycle