The Executive Diagnostic and Governance Toolkit
Assess and Advance Your Vendor Risk Practice
Score your own function red, amber or green, find out which part is weakest, and walk into the next budget round able to defend what you want to fix. Built for leaders reviewing running RFPs on spreadsheets, scoring responses manually, re-assessing vendor risk annually.
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
| 1 |
You stop guessing where you stand. You finish with a score, not an opinion: every part of your function rated red, amber or green, with the weakest ranked first. Evidence: a Quick Scan for the shape of it, then seven domain assessments of 30 scored questions each, 210 in all, rolled into one scorecard, plus a maturity radar and a current-versus-target gap analysis. |
| 2 |
You can defend the decision. You walk into the budget round with the gap named, the owner named and done defined, instead of a case built on instinct. Evidence: project charter, scope statement, RACI, requirements traceability and work breakdown structure, pre-filled in your domain's language. |
| 3 |
The work actually moves. The month after the decision is already built, so nothing stalls waiting for someone to design a form. Evidence: more than 60 project templates across all five PMBOK process groups, plus runbooks, SOPs, a KPI framework, audit checklists and a risk matrix. 55 to 65 files in total. |
| 4 |
You use it the day it lands. No blank templates to interpret. Every workbook opens with what it is, who uses it, when, how, a 1 to 5 scoring guide, what good looks like, and a worked example you delete and type over. |
The situation this is built for
You’re accountable for vendor risk and end-to-end procurement outcomes, yet critical work still flows through disconnected spreadsheets and email threads. Scoring supplier responses takes days. Risk reassessments happen on a calendar, not a trigger. Sourcing events repeat the same manual setup. When audits come, evidence is stitched together after the fact. The pressure to modernize is rising, but jumping to technology solutions without diagnosing root gaps can deepen inefficiencies. What you need isn’t another platform demo — it’s a structured way to assess your current state, identify leverage points, and decide what changes will move the needle.
Who this is for
Head of Procurement or Director of Procurement Operations who owns vendor risk programs, sourcing lifecycle management, and cross-functional alignment with legal, security, and compliance teams.
Who this is not for
This is not for procurement analysts executing transactional tasks, nor for executives seeking high-level market trends. It is not for those looking to buy software or compare vendors.
What you walk away with
- Map your current RFP execution workflow against operational benchmarks
- Identify redundancies in annual vendor risk reassessment cycles
- Diagnose misalignments between procurement and compliance handoffs
- Uncover inefficiencies in supplier response scoring and evaluation
- Build a prioritized action plan based on functional maturity
How this maps to your situation
- Current state assessment
- Process diagnostics
- Cross-functional alignment
- Future state planning
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, designed to be completed at your pace over 6–8 weeks with reflection and team input.
How this compares to the alternatives
Unlike generic training on procurement best practices, this course provides a diagnostic lens focused specifically on operational maturity in vendor risk and sourcing execution. It does not teach theoretical models but guides you through examining your actual artifacts, meetings, and decisions.
Also included: the full course, for when you want the reasoning behind a finding (12 modules, 144 chapters)
Depth reference. The diagnostic and the templates stand on their own; this is what to read when you want the reasoning behind a finding.
- Documenting your end-to-end supplier lifecycle process
- Mapping stakeholders involved in sourcing decision approvals
- Reviewing how RFP timelines are planned and tracked
- Analyzing how supplier data flows between departments
- Identifying where manual entry occurs in procurement workflows
- Cataloging templates used for request for information forms
- Assessing version control challenges in shared documents
- Evaluating how sourcing requirements are defined upfront
- Tracking how exceptions to standard terms are managed
- Observing handoff points between procurement and legal
- Measuring time spent compiling status updates for leadership
- Benchmarking current process against industry operating models
- Breaking down the steps in manual supplier response scoring
- Reviewing how evaluation criteria weights are applied consistently
- Assessing how comment feedback is collected from evaluators
- Identifying delays caused by asynchronous reviewer input
- Examining methods used to consolidate multiple score sheets
- Mapping how conflicts in scoring are resolved post-evaluation
- Tracking how non-compliant responses are flagged and handled
- Analyzing how technical and commercial scores are combined
- Evaluating transparency of scoring in audit readiness reviews
- Documenting how evaluator bias is currently mitigated
- Reviewing use of side conversations in final selection decisions
- Measuring hours spent per sourcing event on evaluation alone
- Defining which vendors are subject to annual reassessment
- Reviewing triggers that should prompt out-of-cycle reviews
- Mapping data sources used to update vendor risk profiles
- Assessing lag time between risk event and detection
- Identifying gaps in third-party incident reporting processes
- Evaluating how findings from audits inform risk ratings
- Analyzing how residual risk acceptance is documented
- Tracking approval workflows for risk mitigation plans
- Measuring completeness of control evidence collection
- Reviewing integration between risk findings and contract renewals
- Documenting escalation paths for high-risk vendors
- Benchmarking reassessment frequency against regulatory exposure
- Mapping required sign-offs from legal before contract execution
- Reviewing how information security questionnaires are distributed
- Assessing turnaround time for privacy impact assessments
- Identifying duplication in due diligence across departments
- Documenting how compliance exceptions are formally approved
- Analyzing how service level agreements align with obligations
- Tracking resolution of open items pre-go-live with suppliers
- Evaluating joint ownership of vendor exit checklists
- Measuring consistency in risk language across contracts
- Reviewing coordination mechanisms during breach notifications
- Observing cross-functional attendance at vendor governance meetings
- Assessing shared understanding of critical versus non-critical vendors
- Documenting how business units submit sourcing requests
- Reviewing how market research informs supplier shortlists
- Mapping communication channels during RFP clarification
- Assessing how amendments are communicated to bidders
- Tracking version history of final RFP documentation
- Evaluating how responses are received and logged
- Identifying bottlenecks in accessing encrypted submissions
- Analyzing how redaction rules are applied to public disclosures
- Measuring time from close date to evaluation kickoff
- Reviewing data retention policies for closed sourcing events
- Documenting how lessons learned are captured post-award
- Benchmarking data handoffs against procurement system capabilities
- Locating documented statements of risk tolerance levels
- Reviewing how risk thresholds vary by vendor criticality
- Assessing alignment between finance and procurement on exposure limits
- Mapping how cyber risk tolerances influence sourcing choices
- Identifying cases where risk exceeded stated thresholds
- Evaluating how board-level risk reports are synthesized
- Documenting delegation of authority for risk acceptance
- Analyzing how risk trade-offs are recorded in meeting minutes
- Reviewing escalation criteria for executive intervention
- Measuring consistency in applying risk scoring rubrics
- Tracking variance between assessed and actual vendor incidents
- Benchmarking tolerance definitions against peer organizations
- Mapping current process for contract version tracking
- Reviewing how key dates like auto-renewal are monitored
- Identifying missed obligations due to poor visibility
- Assessing how amendment histories are maintained
- Documenting storage locations for executed agreements
- Evaluating searchability of contract terms across portfolio
- Tracking performance against negotiated service levels
- Analyzing how contract insights inform future sourcing
- Measuring time to retrieve documents during audits
- Reviewing notification processes for upcoming expirations
- Observing handovers during supplier relationship transitions
- Benchmarking contract oversight against operational scale
- Locating formal records of sourcing committee decisions
- Reviewing how scoring summaries support award justification
- Assessing completeness of evaluation summary reports
- Identifying missing context in archived decision files
- Documenting how minority evaluator opinions are retained
- Analyzing how commercial negotiations influence final choice
- Tracking references to non-price factors in rationale
- Evaluating accessibility of decision records for auditors
- Measuring lag between decision and documentation finalization
- Reviewing format consistency across different sourcing types
- Observing whether deviations from process are explained
- Benchmarking record quality against regulatory requirements
- Measuring processing time per million dollars sourced
- Reviewing team capacity under peak sourcing demand
- Assessing ability to handle concurrent global RFPs
- Identifying breaking points in current workflow design
- Documenting workarounds used during high-pressure cycles
- Analyzing reliance on individual institutional knowledge
- Tracking error rates as workload increases
- Evaluating onboarding speed for new procurement staff
- Measuring reuse of past evaluation frameworks
- Reviewing adaptability to new regulatory mandates
- Observing response time to urgent supplier replacements
- Benchmarking operational elasticity against growth targets
- Locating current dashboards showing vendor risk distribution
- Reviewing frequency of risk portfolio reporting to executives
- Assessing accuracy of self-reported supplier control data
- Identifying blind spots in sub-processor oversight
- Documenting how concentration risk is calculated and shown
- Analyzing how emerging threats are reflected in reporting
- Tracking timeliness of risk dashboard updates post-event
- Evaluating clarity of risk heat maps for non-experts
- Measuring alignment between reported risk and actual incidents
- Reviewing inclusion of financial health indicators in views
- Observing use of risk data in enterprise risk management forums
- Benchmarking transparency of exposure reporting against peers
- Prioritizing pain points using impact and feasibility filters
- Reviewing quick wins that reduce manual rework immediately
- Assessing change readiness across stakeholder groups
- Identifying foundational data improvements needed first
- Documenting dependencies between improvement initiatives
- Analyzing sequencing of people, process, and tool changes
- Tracking resource availability for internal projects
- Evaluating communication strategy for rollout phases
- Measuring expected ROI from targeted interventions
- Reviewing pilot opportunities for new approaches
- Observing feedback loops for continuous adjustment
- Benchmarking improvement pace against business urgency
- Compiling assessment results into executive summary
- Reviewing recommended changes by functional area
- Assessing alignment with broader organizational strategy
- Identifying ownership for each proposed initiative
- Documenting success metrics for improvement efforts
- Analyzing budget implications of prioritized actions
- Tracking governance model for ongoing oversight
- Evaluating integration points with future systems
- Measuring readiness to revisit vendor risk frequency
- Reviewing playbook update schedule and stewardship
- Observing alignment with enterprise architecture principles
- Benchmarking final playbook against operational resilience goals
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
Thousands of organisations have bought from The Art of Service since 2000.