I feel that going by a percentage could limit or exceed the an organizations need for additional vendor management activities. There are characteristic such as revenue loss, impact to the other operations and reputation (future revenue) that should drive the quantity.
Example: High Risk vendor because they have access governed data for billing and collections. If there is an operational impact such as a site outage, it may be a delay in revenue or alternative collection channels. However, a High Risk vendor that delivers the SaaS solution to process those activities having an outage could have an operational impact if that repository is used for other customer activities such as sales. Then the ability to sell or collect revenue are unavailable and the ability to make up days of sales may not be realistic (depending on your business).
Original Message:
Sent: 10-03-2019 10:27 AM
From: Branan Cooper
Subject: Polling the audience, so to speak
What percentage of your vendors do you consider to be Critical vendors (i.e., from a Business Impact perspective)? Please feel free to answer anonymously, if you need to / prefer to....