When onboarding new vendors, it takes the median company an average of 90 days to complete due diligence — 20 days longer than it did four years ago, according to Gartner. In a competitive business climate where speed can be the difference between success and failure, a lengthy onboarding process undercuts your organization’s efforts at digital transformation and growth acceleration. And now, with as much as 75% of the workforce in some industries shifting to remote work due to the coronavirus outbreak, finding operational efficiencies in your onboarding process is more important than ever.
So, how can you speed up your vendor onboarding process, while still maintaining a high security standard? It all comes down to determining the right level of vendor risk assessment for each potential third party.
No two vendors are the same
It’s time to leave the one-size-fits-all onboarding process behind. After all, different vendors present variable risk levels — and should not all be evaluated using the same cookie-cutter approach. For instance, a payroll provider working with sensitive employee and company information represents a much higher level of inherent risk than a food service provider that doesn’t have direct access to your network.
Instead of wasting time doing long, full-blown assessments on every vendor, allocate your resources to those that require greater vendor due diligence. Doing so will empower you to reap the benefits of your technology as quickly as possible.
Take the two steps outlined below to streamline your vendor onboarding process:
1. Define whether the vendor is “critical”
First things first: Before you begin an assessment, you must evaluate how critical that third party is to your organization.
To identify whether a particular vendor meets this criteria, consider asking:
- What type of data will they hold?
- Would you face financial or reputational harm if this data was compromised?
- What is this vendor being used for?
- How critical is this use case to your business operations?
- Will the vendor have persistent access across your network?
While a critical vendor may require a full-blown, on-site evaluation, performing that same level of assessment on a non-critical vendor could be a waste of your time and resources.
2. Evaluate the vendor’s security posture
Your next step in determining the right type of assessment is evaluating the potential third party’s security posture. In particular, you should assess the number and severity of security issues they have that should be reviewed and acted on.