When we categorize our vendors, we typically base it on whether or not we share NPI data with a vendor or not. If we do share NPI data, they are put in a critical or high-risk category.
As an insurance company, we work with hundreds of law firms and independent agencies. Since we do share NPI data of our customers with these types of vendors, they are listed as high-risk and we send them a short questionnaire to complete each year.
I'm curious if anyone else is in this same scenario and how they handle this type of ongoing monitoring with so many vendors. We are thinking re-categorizing them and only having those vendors that score on the lower end of the spectrum be assessed each year, while the others on an every other year basis.
Thank you in advance for your input on this matter.