This message was posted by a user wishing to remain anonymous
In our Vendor Management policy, our definition of "vendor" specifically excludes vendors that we cannot influence (such as utilities), that are immaterial to our organization (such as coffee delivery), that require independence (such as external auditors or legal counsel), etc.
It might be overkill, but with few exceptions, all of our vendors have contracts and are risk rated.
If this isn't the type of answer you're looking for, please do elaborate . . .