Skip to main content
Category: Monitoring and Performance

Performance Monitoring

Simply put

Performance monitoring is the ongoing process of tracking and measuring how well something is doing against defined goals, typically using key performance indicators (KPIs). It helps an organization see whether expected results are being achieved and where they fall short. The evidence provided describes the concept generically, spanning uses from IT systems to broader organizational objectives.

Formal definition

Performance monitoring is the systematic, ongoing process of collecting, measuring, and analyzing indicators against defined objectives to determine whether goals and expected outcomes are being met. Depending on the domain, it may track KPIs, service levels, or operational metrics; the evidence provided reflects generic and IT/application-centric usage (for example, collecting metrics, traces, and logs to assess the state of applications and infrastructure) rather than a third-party or supply chain risk-specific definition. As typically applied in vendor and supplier programs, it addresses continuous or periodic observation of contracted performance and is distinct from point-in-time due diligence at onboarding; note, however, that the sources available here do not establish a TPRM- or SCRM-specific scope, and performance monitoring alone does not necessarily cover financial, information security, geopolitical, or ESG risk unless those dimensions are explicitly incorporated into the monitored indicators.

Why it matters

In third-party and supply chain programs, the risk profile of a supplier is not fixed at the moment of contract signature. A vendor that passed onboarding due diligence can degrade over time as service levels slip, staffing changes, financial pressure mounts, or operational commitments go unmet. Performance monitoring exists to close the gap between a point-in-time onboarding assessment and the reality of an ongoing relationship, giving an organization a way to see whether contracted or expected outcomes are actually being delivered rather than assuming they are.

Because performance monitoring tracks indicators against defined objectives on a continuous or periodic basis, it can surface early signals of trouble before they escalate into missed deliverables, service disruption, or breach of contract. Its value depends heavily on how well the monitored indicators are chosen: monitoring that captures delivery timeliness or system availability may say nothing about a supplier's financial health, information security posture, geopolitical exposure, or ESG conduct unless those dimensions are deliberately built into the measured set. Treating performance monitoring as a proxy for full risk coverage is a common error, since it addresses whether goals are being met, not necessarily why performance is changing or what risks lie beyond the first tier.

The available evidence describes performance monitoring generically and in IT- or application-centric terms rather than defining a third-party or supply chain risk-specific practice. Organizations applying the concept in vendor programs should therefore treat it as a discipline they must scope and configure themselves, deciding which indicators matter, how frequently to observe them, and how monitoring outputs connect to escalation and remediation. Absent that deliberate design, performance data can accumulate without translating into risk-informed action.

Who it's relevant to

Third-Party Risk and Vendor Management Teams
These teams use performance monitoring to extend oversight beyond onboarding into the life of the relationship, tracking whether suppliers continue to meet expected outcomes. They should be clear that performance monitoring against operational or service indicators does not automatically cover financial, information security, geopolitical, or ESG risk unless those dimensions are explicitly incorporated into the monitored set.
Procurement and Contract Owners
For those managing supplier contracts, performance monitoring provides the evidence base for assessing whether contracted commitments are being delivered and for informing renewal, remediation, or escalation decisions. Its usefulness depends on defining measurable objectives up front so that shortfalls against them can be identified rather than merely suspected.
Operations and Resilience Functions
Operational and resilience teams rely on ongoing measurement to detect degradation in service delivery before it disrupts business processes. Because monitoring reflects whether goals are being met rather than always explaining why, these functions typically pair it with further investigation when indicators trend adverse.
IT and Service Assurance Teams
In the application- and infrastructure-centric usage reflected in the evidence, IT teams collect metrics, traces, and logs to understand the state of systems and hosted services. Where such systems are delivered by or depend on external providers, this monitoring can contribute to third-party oversight, though it addresses technical performance and not the full range of supplier risks.

Inside Performance Monitoring

Key Performance Indicators (KPIs)
Quantitative measures used to track whether a third party is delivering against agreed service and quality expectations. KPIs typically address dimensions such as delivery timeliness, defect or error rates, availability, and responsiveness, and are most useful when tied to specific, measurable thresholds defined at onboarding.
Service Level Agreements (SLAs)
Contractually defined performance commitments against which actual delivery is measured. Performance monitoring assesses conformance to SLA targets and typically references any remedies, credits, or escalation paths triggered by breaches. SLAs address contracted service levels and do not by themselves cover broader financial, security, or geopolitical risk.
Ongoing (Continuous) Monitoring
The recurring collection and review of performance data over the life of the relationship, distinct from point-in-time onboarding due diligence. The cadence and depth typically vary by risk tier, with higher-criticality relationships monitored more frequently.
Data Sources and Inputs
The evidence used to evaluate performance, which may include vendor self-reported metrics, the buyer's own operational records, customer or business-unit feedback, and, in some programs, independent or third-party data. Reliance on self-reported inputs alone limits the objectivity of the assessment.
Scorecards and Reporting
Structured formats that consolidate KPI and SLA results into a periodic view for stakeholders, often aggregated across relationships to support comparison and prioritization. Scorecards summarize performance but do not by themselves verify the accuracy of the underlying data.
Governance, Escalation, and Remediation
The defined roles, review meetings, and processes for addressing underperformance, including corrective action plans and escalation triggers. This links monitoring outputs to accountable decision-making rather than leaving results as passive reporting.

Common questions

Answers to the questions practitioners most commonly ask about Performance Monitoring.

Is performance monitoring the same as risk monitoring?
No. Performance monitoring typically tracks whether a third party is delivering against agreed service levels, quality standards, and contractual obligations, while risk monitoring focuses on changes to the third party's risk profile (for example financial, cybersecurity, geopolitical, or ESG exposures). A vendor can meet its performance targets while its underlying risk posture deteriorates, and a vendor with an acceptable risk profile can still underperform. Many programs run both in parallel because each addresses a distinct question, and treating one as a substitute for the other can leave gaps.
Does strong performance monitoring mean due diligence is no longer needed?
No. Performance monitoring is an ongoing activity that observes delivery over time, whereas due diligence, particularly at onboarding, establishes the initial understanding of a third party's capabilities, controls, and risk. Ongoing performance data does not replace periodic reassessment or refreshed due diligence, especially for higher-risk relationships. Good performance against SLAs does not, on its own, confirm that a provider's control environment, financial stability, or compliance posture remains sound, so most programs treat the two as complementary rather than interchangeable.
What metrics are typically used in third-party performance monitoring?
Metrics commonly include service level agreement (SLA) attainment, delivery timeliness, quality or defect rates, availability or uptime for service providers, responsiveness to issues, and remediation of identified deficiencies. The appropriate set depends on the nature of the relationship and the risk tier; a critical technology provider may be measured on availability and incident response, while a goods supplier may be measured on on-time delivery and defect rates. Metrics are generally most useful when tied to specific, measurable obligations in the contract rather than to general expectations.
How frequently should performance be monitored?
Frequency typically varies by risk tier and criticality. Higher-risk or business-critical relationships are often monitored more frequently, sometimes through continuous or near-real-time data feeds where available, while lower-risk relationships may be reviewed periodically, such as through scheduled business reviews. A limitation of point-in-time reviews is that conditions can change between checkpoints, so many programs supplement periodic reviews with event-driven triggers for significant incidents or performance breaches.
How should performance data be sourced and validated?
Performance data can come from internal systems, the third party's own reporting, or independent measurement, and each source has trade-offs. Self-reported metrics may be efficient but can lack independent validation, so higher-risk relationships often benefit from corroboration through the organization's own monitoring or independent verification. Where feasible, defining measurement methods and data sources in the contract can reduce disputes over how performance is calculated and reported.
What happens when a third party fails to meet performance expectations?
Responses typically depend on the severity and persistence of the shortfall and on the remedies established in the contract. Common steps include documenting the deficiency, requiring a corrective action or remediation plan, escalating through governance forums, and, where provided for, applying contractual remedies such as service credits or, in serious cases, considering termination and exit planning. Performance monitoring is generally most effective when tied to a clear escalation and remediation process rather than treated as data collection alone.

Common misconceptions

Performance monitoring is the same as risk assessment.
Performance monitoring evaluates whether a third party is meeting agreed service and quality expectations, typically against SLAs and KPIs. It does not by itself measure inherent or residual risk across financial, security, operational, geopolitical, or ESG dimensions. Strong SLA conformance does not indicate that a third party is low-risk in areas the monitoring does not cover.
If a vendor reports good performance metrics, the results are validated.
Much performance data may be self-reported by the third party. Self-reported metrics are an attestation of results, not independent verification. Without corroborating data from the buyer's own records or independent sources, reported performance may not reflect actual delivery.
A single performance review confirms the relationship is healthy going forward.
Performance monitoring is inherently point-in-time when conducted at intervals, and results can become stale as circumstances change. Meeting targets in one period does not guarantee sustained performance, which is why monitoring cadence is typically set by risk tier rather than treated as a one-time check.

Best practices

Define measurable KPIs and SLA thresholds at onboarding, and tie each metric to a clear remedy, escalation path, or corrective action trigger so that monitoring outputs drive decisions.
Set monitoring cadence and depth according to the criticality and risk tier of each relationship, monitoring higher-criticality third parties more frequently.
Corroborate vendor self-reported metrics with the organization's own operational records, business-unit feedback, or independent data rather than relying on attestation alone.
State explicitly what performance monitoring does and does not cover, and pair it with separate assessments of financial, security, operational, geopolitical, and ESG risk where relevant.
Establish governance with defined roles and periodic review meetings so underperformance results in documented corrective action plans and escalation rather than passive reporting.
Treat interval-based results as point-in-time indicators that can become stale, and refresh performance data on a schedule appropriate to the relationship's risk.
Promotional banner for the Pentest Readiness checklist download