Vendor management · Checklist · intermediate

A vendor lifecycle control record

Keep onboarding, authority, work history, payment instructions, periodic review, suspension, and offboarding in one governed record.
By Aptoria editorial team · 3 min read · Updated 2026-09-18 · Last reviewed 2026-09-18
Technical content review: Codex technical editorial review. Reviewed intent separation, internal consistency, original decision artifacts, fictional examples, source limits, and operational risk boundaries. No legal, tax, accounting, banking, safety, or human professional approval is claimed.
This is a technical review, not independent human or professional review.
The short answer
Manage a vendor lifecycle with one governed record that identifies the vendor, approved services and authority, verification evidence and dates, current contacts and payment-instruction version, work and exception history, periodic review triggers, and final access/payment offboarding. Never let an old approved state silently authorize a new identity, destination, or scope.

Operational checklist

Mark your progress, then save a working copy. Selections reset when you leave this page. A checked box is not an approval or evidence of completion.
0 of 7 marked

Key takeaways

  • Treat onboarding as the first decision, not permanent approval.
  • Version changes to identity, contacts, authority, and payment instructions.
  • Close access, queued work, and payment questions during offboarding.

Give each lifecycle stage an acceptance decision

Define requested, verifying, approved for limited scope, active, review due, restricted, suspended, and offboarded states. Record who can change state and what evidence is required. A vendor may remain active for one service category while a new category awaits review.
Do not publish or broadly copy sensitive tax, insurance, identity, access, or bank records. The control record can point to restricted evidence.

Maintain one lifecycle control record

Use effective dates so a reviewer can determine which identity, contact, authority, and payment version applied to a work order.
Vendor lifecycle record
StageDecision evidenceTrigger to revisit
OnboardingIdentity and approved verification under policyIncomplete or contradictory evidence
ActivationApproved services, geography, spend/access limits, contactsNew scope or authority request
WorkAssignments, acceptance, exceptions, completion historyRepeated unresolved exceptions
ChangeIndependently verified contact/payment/identity versionAny instruction change
Periodic reviewEvidence checked date, reviewer, open questionsExpiry, policy date, or risk event
OffboardingAccess removed, queued work resolved, final payment reviewedReactivation requires a new decision

Treat changes as new evidence events

A familiar vendor name does not validate a new email address, banking destination, ownership entity, or service authority. Use independently established channels for sensitive changes. The FBI specifically recommends independently verifying payment changes in the context of business email compromise.
Keep previous versions and their effective dates. Historical work must continue to point to the instruction and authority that applied at the time.

Close credentials as their own offboarding population

During periodic review, suspension, or offboarding, enumerate physical keys, lockbox codes, badges, portal accounts, API credentials, and other access issued through every open or historical assignment. Vendor status alone does not revoke them.
Use the vendor access credential lifecycle to record return, revocation, rotation, expiry, and verification without exposing secrets in the general vendor record.

Edge cases

  • A sole proprietor incorporates: preserve the prior entity and review the new counterparty under policy.
  • An emergency substitute vendor is used: record the temporary authority and retrospective review without presenting it as normal approval.
  • A vendor is suspended with open work: assign continuity and access actions rather than merely changing status.

Sources and references

Follow each source to check the underlying claim. Access checks and professional review are different steps.
1. Primary source · Federal Bureau of Investigation
Business Email Compromise
Independently verify changes to payment information through a known channel. This does not determine whether a vendor request is fraudulent.
Source checked 2026-09-18
Automated source-access check: 2026-09-18.

Revision history

2026-09-18
Initial Phase 2 operational article with an original decision artifact, explicit failure states, primary-source scope notes, and AI-assisted technical review.
Report a correction to this resource