Skip to main content
Category: Governance and Procurement

Vendor Selection

Also known as: Supplier Selection, Vendor Selection Process, Supplier Selection Process
Simply put

Vendor selection is the process an organization uses to identify, evaluate, and choose an external company to supply goods or services. It typically involves setting criteria, such as quality, cost, reliability, and strategic fit, and comparing candidate vendors against them to find the most suitable match. It is the decision stage before a vendor is engaged, and it is distinct from the ongoing management of a vendor once selected.

Formal definition

Vendor selection is the structured process of identifying candidate suppliers, evaluating them against defined selection criteria (commonly quality, cost, reliability, capability, and strategic fit), and choosing the most suitable provider of goods or services. In many programs it incorporates preliminary due diligence and comparative techniques such as weighted scoring to rank candidates. It should be understood as a point-in-time, pre-contract decision activity focused on the organization's direct (third-party) relationship; the evidence available describes the selection and evaluation stage and does not, in itself, extend to post-award onboarding, contract execution, or ongoing monitoring, which are typically governed by separate processes.

Why it matters

Vendor selection is the decision point at which an organization commits to a direct third-party relationship, and the criteria applied at this stage, quality, cost, reliability, capability, and strategic fit, shape the risk profile the organization will carry for the life of the engagement. A rigorous selection process gives the organization a defensible basis for choosing one candidate over others and an opportunity to conduct preliminary due diligence before a contractual obligation exists. Weaknesses in the criteria, or in how candidates are compared against them, can carry forward into problems that are more costly to address once a vendor is engaged.

It is important to recognize what vendor selection does and does not accomplish. Selection is a point-in-time, pre-contract activity: it evaluates candidates as they present themselves at the moment of assessment. It does not, on its own, guarantee performance over time, nor does it substitute for the post-award onboarding, contract execution, and ongoing monitoring that are typically governed by separate processes. A vendor that scores well during selection may still drift out of alignment with the organization's requirements later, which is why selection is best understood as the first stage of a broader lifecycle rather than a one-off decision that settles risk permanently.

Because selection often incorporates only preliminary due diligence, the depth of scrutiny applied at this stage may not match the risk the vendor ultimately poses. In many programs the rigor of selection is calibrated to the risk tier of the goods or services being sourced, and organizations that treat all selections uniformly risk over-investing in low-stakes decisions or under-investing in high-stakes ones.

Who it's relevant to

Procurement and Sourcing Teams
Procurement and sourcing professionals own the mechanics of vendor selection: identifying candidates, defining evaluation criteria, and applying comparative techniques such as weighted scoring to reach a defensible choice. They are responsible for ensuring the criteria reflect the organization's quality, cost, reliability, capability, and strategic-fit requirements for the goods or services being sourced.
Third-Party Risk Management Practitioners
TPRM practitioners are concerned with the preliminary due diligence conducted during selection and with how selection feeds into subsequent lifecycle stages. Because selection is a point-in-time, pre-contract activity, these teams typically ensure that a favorable selection decision is followed by the separate onboarding and ongoing monitoring processes needed to manage risk over the life of the relationship.
Business and Functional Stakeholders
Internal stakeholders who will rely on the selected vendor's goods or services have a direct interest in how strategic fit and capability are weighed during selection. Their input helps ensure that selection criteria reflect actual operational requirements rather than cost or convenience alone.

Inside Vendor Selection

Requirements Definition
The upfront specification of functional, technical, commercial, and risk-related criteria against which candidate vendors are evaluated. This typically includes service scope, performance expectations, security and compliance requirements, and cost parameters, and it frames the basis for comparison across bidders.
Market Screening and Sourcing
Identification of a candidate pool through methods such as requests for information (RFIs), requests for proposal (RFPs), or requests for quotation (RFQs). This stage narrows a broad market to a shortlist but does not by itself constitute due diligence into a vendor's risk posture.
Pre-Contract Due Diligence
Assessment of shortlisted vendors' financial stability, operational capability, security controls, regulatory standing, and reputational factors before award. This is a point-in-time exercise focused on onboarding decisions and does not extend to ongoing monitoring after the relationship begins.
Risk Tiering
Classification of candidate vendors by the level of risk they would introduce, often based on data sensitivity, criticality of the service, and access granted. Tiering typically calibrates the depth of assessment applied, so higher-tier candidates receive more rigorous scrutiny than lower-tier ones.
Evaluation and Scoring
Structured comparison of candidates against weighted criteria, which may combine commercial factors with risk indicators. Scoring supports a defensible award decision but reflects the criteria chosen and the quality of information supplied, much of which may be self-reported.
Award and Transition to Onboarding
The decision to select a vendor and the handoff into contracting and onboarding activities. Selection concludes at award; contract negotiation, control validation, and continuous monitoring are distinct subsequent stages of the third-party lifecycle.

Common questions

Answers to the questions practitioners most commonly ask about Vendor Selection.

Is vendor selection the same as vendor risk assessment?
No. Vendor selection is the decision process for choosing among candidate vendors against defined criteria, whereas vendor risk assessment evaluates the risks a given vendor may pose. Risk assessment typically feeds into selection as one input among others such as cost, capability, and fit, but selection also weighs commercial and strategic factors that fall outside the scope of risk assessment. Treating them as identical can cause a program to conflate a favorable commercial decision with an acceptable risk posture.
Does completing vendor selection mean due diligence and ongoing monitoring are finished?
No. Vendor selection is generally a point-in-time activity that concludes at the award decision. Onboarding due diligence, contracting controls, and ongoing monitoring are distinct downstream stages. A selection decision reflects information available at the time of evaluation and can become stale; in many programs, continued oversight through the relationship lifecycle is required to detect changes in the vendor's risk profile after selection.
How should selection criteria be weighted across cost, capability, and risk?
Weighting typically depends on the risk tier and criticality of the service being sourced. In many programs, higher-criticality or higher-inherent-risk engagements assign greater weight to risk and control factors, while lower-risk commodity purchases may emphasize cost and capability. Documenting the weighting rationale in advance helps reduce bias and supports defensible, repeatable decisions.
What role does self-reported information play in vendor selection?
Questionnaires and attestations from candidate vendors are commonly used during selection, but they are self-reported and may lack independent validation. Depending on the risk tier, programs may supplement them with independent verification such as third-party assessment reports or references. It is important not to treat a vendor's attestation as equivalent to verified assurance when making a selection decision.
Should selection consider risks beyond the direct vendor?
For higher-criticality engagements, many programs consider the candidate's own reliance on subcontractors or downstream providers, since fourth-party or Nth-party dependencies can introduce risk that is not visible in a first-tier evaluation. Visibility beyond the direct vendor is often limited, so selection criteria may include questions about the vendor's own management of its supply chain, recognizing that such information may be incomplete.
How can concentration risk be addressed during vendor selection?
Selection decisions can account for whether awarding to a particular vendor would increase dependence on a single provider or geographic region. Distinguishing single-source dependency from single point of failure is useful here: choosing one vendor for a service is not inherently a failure point, but it may warrant contingency planning or a multi-sourcing strategy depending on criticality. These considerations are typically weighed alongside cost and capability rather than in isolation.

Common misconceptions

Vendor selection is the same as vendor risk management.
Selection is a single, largely point-in-time phase focused on choosing among candidates before award. Third-party risk management is a broader lifecycle that continues through contracting, onboarding, ongoing monitoring, and offboarding. A rigorous selection does not remove the need for continuous oversight, since a vendor's risk posture can change after the relationship begins.
A vendor that provides certifications or attestations during selection has been independently verified as low risk.
Documents such as a SOC 2 report or self-completed questionnaires are typically point-in-time and, in the case of questionnaires, self-reported. A SOC 2 report is an attestation, not a certification, and reflects a defined scope and period. Depending on the risk tier, additional independent validation may be warranted rather than relying on attestations alone.
Selecting the vendor with the strongest security controls addresses the full range of selection risk.
Information security is only one dimension. Selection decisions may also need to weigh financial stability, operational resilience, concentration and single-source dependency, geopolitical exposure, and ESG factors, depending on the service and risk tier. Focusing on one risk category can leave others unassessed.

Best practices

Define risk-based evaluation criteria before sourcing, and weight them according to the candidate's likely risk tier so that critical, high-access vendors receive proportionately deeper scrutiny.
Treat self-reported questionnaires and attestations as inputs rather than conclusions; where the risk tier warrants, seek independent evidence and validate that any SOC 2 report or similar document covers the relevant scope and period.
Assess multiple risk dimensions during selection, including financial, operational, security, geopolitical, and ESG factors as relevant, rather than optimizing on a single category.
Evaluate concentration and single-source dependency at the point of selection, considering whether awarding to a particular vendor introduces a single point of failure that alternative sourcing could mitigate.
Document selection criteria, scoring, and the rationale for award to create a defensible record, and record open risk items to be carried into contracting and onboarding.
Plan explicitly for the transition beyond selection by defining requirements for ongoing monitoring, since point-in-time due diligence conducted at selection becomes stale over the course of the relationship.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide