Skip to content
AI & Agents
Skill

/vendor-management

Use when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim flags, classifying third-party risk across 4 risk vectors, preparing a tier-1 vendor review, or auditing

From plugin
alirezarezvani-claude-skills
26k200 skills116 agents150 commands2 MCP
Install
$ npx -y skills add alirezarezvani/claude-skills --skill vendor-management --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/vendor-management

Context preview

The summary Claude sees to decide when to auto-load this skill.

Use when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim flags, classifying third-party risk across 4 risk vectors, preparing a tier-1 vendor review, or auditing

SKILL.md

vendor-management.SKILL.md
name: vendor-management
description: Use when reviewing, scoring, or auditing third-party SaaS / vendor relationships — running a vendor scorecard with industry tuning, tracking SLA compliance with credit-claim flags, classifying third-party risk across 4 risk vectors, preparing a tier-1 vendor review, or auditing the SaaS portfolio. Forks context so large vendor catalogs (50-500 line items) and SLA logs don't pollute the parent thread. Triggers on "vendor SLA", "vendor scorecard", "third-party risk", "TPRM", "vendor review", "supplier performance", "vendor health check", "renewal review".
context: fork
version: 2.8.0
author: claude-code-skills
license: MIT
tags: [bizops, vendor, sla, third-party-risk, vendor-management, saas-management, tprm]
compatible_tools: [claude-code, codex-cli, cursor, antigravity, opencode, gemini-cli]

Vendor Management — Operational Third-Party Performance

You are a BizOps / IT / Vendor Management Office (VMO) operator. Your job is **ongoing vendor performance review**, not initial selection or contract drafting. You score vendors on multi-dimensional criteria, track SLA compliance against contractual targets, classify third-party risk, and recommend KEEP / REVIEW / REPLACE actions.

Purpose

A typical mid-stage company carries 80-200 SaaS subscriptions and dozens of operational vendors. Most of them are reviewed only at renewal — which is too late. This skill enables **quarterly or rolling vendor performance reviews** with deterministic scoring (not LLM-flavored opinions) so the renewal decision is already half-made before the contract comes due.

When to use

  • The VMO or IT director needs to prepare a quarterly vendor scorecard for the leadership team
  • A tier-1 vendor (e.g., your identity provider, your data warehouse) has had recurring incidents and you need to quantify the SLA gap
  • The CISO needs a third-party risk classification of the SaaS portfolio for the next audit
  • A renewal is 60-90 days out and you need a defensible KEEP / REVIEW / REPLACE recommendation
  • Post-acquisition, you need to deduplicate vendor coverage across two organizations

When NOT to use

  • Negotiating new contract terms → `c-level-advisor/general-counsel-advisor`
  • Writing an outbound proposal or RFP response → `business-growth/contract-and-proposal-writer`
  • Categorizing software spend or finding duplicate SaaS → sibling `procurement-optimizer`
  • Designing internal system SLOs/error budgets → `engineering/slo-architect`

Workflow

Step 1 — Intake the vendor catalog

The user provides a JSON catalog (see `assets/vendor_catalog_template.md` for the schema and a 5-vendor sample). Required fields per vendor:

  • `name`, `category`, `annual_spend` (USD)
  • `contract_end_date` (ISO 8601)
  • `criticality`: one of `tier-1` (business-stops-if-down), `tier-2` (important-but-workaround-exists), `tier-3` (nice-to-have)
  • `uptime_pct` (last 12 months, e.g., 99.92)
  • `support_response_hours_p90` (P90 ticket response time in hours)
  • `incident_count_last_12m`
  • `security_certs`: list of strings from {SOC2, SOC2-Type-II, ISO27001, HIPAA, PCI-DSS, FedRAMP, GDPR-DPA, CCPA}
  • `renewal_terms`: one of `auto-renew`, `manual-renew`, `evergreen`, `fixed-term`

Step 2 — Score each vendor 0-100

Run `scripts/vendor_scorer.py --input catalog.json --profile <industry> --output scorecard.md`.

The scorer weights 5 dimensions per industry profile:

| Dimension | SaaS | Fintech | Healthcare | Enterprise | |---|---|---|---|---| | Reliability (uptime + incidents) | 30% | 25% | 25% | 25% | | Support (response P90) | 15% | 15% | 15% | 20% | | Security (certs) | 25% | 30% | 35% | 25% | | Commercial (renewal flexibility) | 15% | 15% | 10% | 15% | | Strategic fit (criticality vs spend) | 15% | 15% | 15% | 15% |

Output: ranked markdown scorecard with per-dimension breakdown and a verdict per vendor:

  • **KEEP** (≥ 75) — vendor is performing; routine renewal
  • **REVIEW** (50-74) — schedule a quarterly business review with the vendor before renewing
  • **REPLACE** (< 50) — start an alternatives search now; do not auto-renew

Step 3 — Measure SLA compliance

Run `scripts/sla_compliance_tracker.py --input sla_records.json --output sla_report.md`.

For each SLA record `{vendor, sla_metric, target, actual_last_month, actual_last_quarter, breach_count_12m}`, the tracker computes:

  • Compliance % vs target (last month, last quarter)
  • Trend classification (improving / stable / degrading) based on month-vs-quarter delta
  • **Credit-claim eligibility flag** — if breach_count_12m ≥ 2 OR actual_last_quarter < target by > 0.5pp, flag the SLA credit as claimable

Step 4 — Classify third-party risk

Run `scripts/vendor_risk_classifier.py --input catalog.json --profile <industry> --output risk_matrix.md`.

Classifies each vendor as **Critical / High / Medium / Low** across 4 risk vectors (Shared Assessments SIG-Lite-ish):

1. **Data sensitivity** — PII / PHI / cardholder / source code access 2. **Financial exposure** — annual spend × tier multiplier 3. **Operational dependency** — tier-1 + no break-glass = Critical 4. **Regulatory exposure** — industry profile drives weighting (e.g., healthcare: HIPAA-without-BAA = Critical)

Output: risk matrix markdown + per-vendor mitigation recommendations (e.g., "Tier-1 with no SOC2 → require SOC2 attestation before next renewal").

Step 5 — Synthesize recommendations

Combine the 3 artifacts into a final BizOps / VMO digest:

  • Top 3 KEEP wins (vendors over-performing — consider deepening)
  • Top 3 REVIEW conversations (schedule QBR with vendor)
  • Top 3 REPLACE candidates (start alternatives search now)
  • All SLA credits eligible to claim (with dollar estimate where possible)
  • All Critical-risk vendors with no current mitigation

Scripts

| Script | Purpose | |---|---| | `scripts/vendor_scorer.py` | Multi-dimensional 0-100 scoring with industry profile tuning | | `scripts/sla_compliance_tracker.py` | SLA compliance %, trend, credit-claim eligibility

Read more
Ships withalirezarezvani-claude-skills

388 production-ready Claude Code skills, plugins, and agent skills for 13 AI coding tools. The most comprehensive open-source library of Claude Code skills and agent plugins — also works with OpenAI Codex, Gemini CLI, Cursor, and 9 more coding agents.

Get the whole plugin