Ask a business owner how many vendors they have and you will usually get a confident number. Ask them to name every one, with what it costs and when it renews, and the confidence drains out fast. Somewhere in there is a line item for software nobody has opened in two years, a service that quietly went up at the last renewal, and two products that do the same job because two different people bought them.
This is not a discipline problem. It is a visibility problem. Vendor relationships accumulate one reasonable decision at a time, spread across years and across people, and no single document ever holds all of them. The fix is boring and it works: one list, reviewed once a year, owned by one person. What follows is what belongs on that list and how to use it.
Build the One List
A spreadsheet is fine. What matters is that it is single, current, and visible to more than one person. For every vendor, capture these.
- What they actually do for you. One plain sentence. Not the product name, the job. “Sends our invoices” tells you more than “AcmeBill Pro.”
- What you pay, and how. The amount, the billing period, and the card or account it hits. Charges on a personal card that gets expensed are the ones that vanish from view.
- The renewal date. Not “sometime in spring.” The date. This is the single most valuable column and the one most often left blank.
- The notice period. Many agreements require written cancellation 30, 60, or 90 days before renewal. Miss that window and you have bought another year no matter how the conversation goes.
- Who owns the relationship. A named person, not a department. Someone has to be responsible for knowing whether this vendor is still worth having.
- Where the contract lives. A link or a folder path. If the only copy is in a former employee’s inbox, you do not have a contract, you have a memory.
- What data or systems they touch. Customer records, financial data, remote access to your machines, or nothing at all. This column drives the security conversation later.
Building the first version takes an afternoon. Pull twelve months of bank and card statements, pull your accounting system’s vendor report, and work through both. You will find things. Everyone does.
Why Price Creep Goes Unnoticed
Vendors rarely raise prices in a way that triggers a decision. They raise them in a way that clears an approval threshold. A subscription that went from $340 a month to $395 does not look like anything on a bank statement. Repeat that across fifteen vendors over three years and you are spending real money on a set of choices you never actually made.
The audit is simple. Put last year’s monthly cost next to this year’s for every line. Sort by the difference. You are not looking for villains, you are looking for numbers that moved without a corresponding change in what you get. Then ask the honest question for each one: if this vendor were pitching us today at today’s price, would we sign? Some answers will be an easy yes. A few will not be, and those are your renegotiation calls. We wrote about the compounding version of this in our year-end review of what neglected subscriptions cost, and the pattern holds every year.
Look for Overlap Before You Look for Discounts
The biggest savings in most vendor reviews are not negotiated. They are eliminated. Once the list exists, overlap becomes obvious in a way it never is month to month.
- Duplicate file storage. Most businesses are paying for storage inside their main productivity suite and separately for a second service somebody preferred.
- Three ways to hold a meeting. Your phone system, your productivity suite, and a standalone video product often all include conferencing.
- Overlapping security tools. Antivirus bundled with the operating system, a paid endpoint product, and a third thing installed years ago and never removed.
- Seats for people who left. Per-user pricing keeps billing long after the user stops existing.
- Departmental tools nobody centrally approved. One team’s project tracker, another’s design subscription. This is the paid corner of the broader pattern we described in our post on shadow IT.
A caution, because consolidation gets oversold. Moving everything to one vendor lowers your bill and raises your concentration risk. If that single provider has an outage, a breach, or a price increase you cannot refuse, you have very little room to move. Consolidate genuine duplicates. Think harder before consolidating things that merely look similar.
The Security Questions Belong in the Same Review
You already have every vendor in front of you with a column showing what they touch. That is the right moment to ask a few security questions, rather than scheduling a separate exercise that never happens.
CISA’s guidance on assessing IT service providers frames the core questions plainly, including “Who is responsible for security and operations when outsourcing IT services to an MSP?” and “What network and system access levels are appropriate for third-party service providers?” Those two apply to any vendor with access, not just an IT provider.
The vendor risk template that CISA’s supply chain task force published for small and medium businesses adds the contract side. It asks whether you have written supply chain risk requirements in your supplier contracts, recommends that you “include contractual obligations to protect information and information systems handled by your suppliers,” and calls for “timely notification of updated risk management information” along with policies requiring suppliers to tell you when their subcontractors or offerings change. That last point catches a lot of businesses off guard, because the vendor you signed with is often not the company doing the work.
Three practical additions for each vendor with access: confirm multi-factor authentication is turned on for your account with them, confirm you know who at your company can log in, and confirm you can revoke that access yourself without calling their support line.
Run It Once a Year, On the Calendar
An annual vendor review that lives in good intentions does not happen. One that lives on the calendar does. Pick a month that is quiet for your business, block two hours, and make it recur.
- Update the list. Add what is new, remove what is gone, correct the amounts.
- Run the price comparison. Last year versus this year, sorted by change.
- Mark every renewal and notice deadline. Put a reminder on the calendar two weeks before each notice window closes, not on the renewal date itself.
- Flag the keep, cut, and renegotiate decisions. Assign each to the named relationship owner with a due date.
- Check access for anyone who left. Departed employees are frequently still active in third-party systems long after their email is disabled.
The Bottom Line
Vendor management does not require software or a formal program. It requires one list with seven columns, an honest look at what changed since last year, and a recurring calendar block so nothing renews by accident. The money you find is real, but the bigger return is knowing exactly who has access to your business and being able to answer that question in a minute instead of a week.
If you would like help building that list, sorting out which tools genuinely overlap, or working through the access and security questions for the vendors who touch your systems, we do this with clients regularly. We work with small and mid-sized businesses across Denton County, and we are happy to start with a straightforward conversation. Contact us today.
Sources:
Comments are closed