
Vendor risk management metrics turn a gut feeling about a vendor into a number you can act on. They split in two: KRIs are the early warnings that a vendor is drifting toward trouble, and KPIs show whether your program is keeping up with what you find. That matters because most breaches now arrive through a supplier, and a risk you can't measure is one you can't manage, fund, or defend to your board or your auditors.
Plenty of programs track vendor metrics and still get blindsided, because the goal was never more data, it was the handful of numbers that change what you do next. Below, you'll find the KRIs and KPIs worth tracking, each with a plain formula, how to read it, and what to do when it moves the wrong way.
How vendor KPIs and KRIs fit together
Most vendor risk metrics are either a KRI or a KPI, and the difference is about timing. A KRI looks forward. It watches a number that tends to move before a vendor causes a problem, so you can act while you still have room. A KPI looks back. It tells you whether your program did its job over the last week, month, or quarter. Many of the strongest metrics work as both, read one way for early warning and another for performance.
You want a mix. A dashboard of only KPIs tells you how you did but never warns you in time. A dashboard of only KRIs warns you constantly but never proves the program is working. Pairing the two is what lets you manage third-party risk instead of just describing it.
To maintain a balanced overview of vendor performance and third-party risk exposure, you need to track the following metrics:
- Key performance indicators (KPIs)
- Key risk indicators (KRIs)
KPIs measure a vendor’s efficiency, quality, and consistency in delivering the contracted products and services. The following table identifies the three common categories of KPIs:
Vendor KRIs, on the other hand, are risk-based metrics that assess vulnerabilities associated with vendor relationships. They serve as early warnings of issues that could harm your business. Here are the three common categories of KRIs you can track:
8 vendor risk management KPIs to track
The KPIs below measure how well a vendor delivers on what you're paying for, from meeting deadlines to holding up their service levels. Where the risk metrics later in this guide watch for what could go wrong, these track day-to-day performance, the reliability, quality, and value a vendor brings. They fall into three groups, operational efficiency, service quality, and cost, and most programs pull a handful from each rather than tracking all ten. For each one you'll find what it measures, how to calculate it, and how to improve it.
1. On-time delivery rate
On-time delivery rate is the share of a vendor's deliveries that arrive on or before their scheduled date. It's the clearest read on whether a vendor is reliable enough to plan around, and a slipping rate is often the first sign of trouble on their end.
How to calculate this metric
Divide the number of deliveries made on or before their due date by the total number of deliveries in the period, then multiply by 100. Track it per vendor and against the commitment in their contract or SLA so the rate reflects the standard you agreed to. Watch the trend rather than a single month, since one bad period can have a one-off cause.
How to improve this metric
Raise the rate by setting clear delivery expectations in the contract and reviewing misses with the vendor promptly so patterns don't set in. Give vendors enough lead time and accurate forecasts so delays aren't your doing, and escalate repeat lateness through the relationship. For vendors that stay unreliable on critical deliveries, line up an alternative.
2. Quality of deliverables
Quality of deliverables is a composite score of how well a vendor's products or services meet the standards you set. It turns a subjective sense of good or bad work into a number you can trend and compare across vendors.
How to calculate this metric
Define the quality criteria that matter for the service, such as accuracy, completeness, or defect rate, and score each delivery against them. Combine the scores into one weighted figure per vendor, weighting the criteria that matter most to you. Keep the rubric consistent so scores stay comparable over time and across vendors.
How to improve this metric
Improve quality by sharing your rubric with vendors up front so they know exactly what good looks like. Give specific, documented feedback on shortfalls rather than general complaints, and tie repeated quality misses to contract terms or renewal decisions. Recognize vendors that score well so the standard has a reward as well as a stick.
3. Cost savings achieved
Cost savings achieved captures how much a vendor reduces your operational expense, whether through pricing, efficiency, or avoided rework. It's the KPI that shows a vendor's value in the language leadership cares about most.
How to calculate this metric
Compare your actual spend and outcomes with the vendor against a baseline, such as your prior provider, your budget, or the market rate. Include indirect savings like reduced rework or downtime where you can measure them, not just the invoice. Report savings over a consistent period so the figure reflects a real trend rather than a one-time negotiation.
How to improve this metric
Grow savings by negotiating on total value rather than headline price, and by consolidating spend with vendors that earn it through performance. Review contracts before auto-renewal so you capture market shifts, and use benchmarking data to hold pricing honest. Track the savings each vendor drives so the strong performers are easy to reward with more work.
4. Response time to incidents
Response time to incidents is the average time a vendor takes to acknowledge and resolve a problem once it's raised. For any vendor your operations depend on, this is the number that predicts how much a disruption will cost you.
How to calculate this metric
Measure the time from when an incident is reported to the vendor to when it's resolved, averaged across incidents in the period. Split acknowledgment time from resolution time, since a fast reply followed by a slow fix is a different problem than silence. Track it against the response commitments in the vendor's SLA.
How to improve this metric
Shorten response time by writing clear incident SLAs with defined severities and escalation paths into the contract. Establish a named contact and an agreed channel for urgent issues rather than a shared inbox, and run through a real incident with critical vendors before one happens. Hold vendors to their committed times and factor chronic slowness into renewals.
5. Rate of return or defects
Rate of return or defects tracks how often a vendor's goods come back or their services fall short. A rising rate points to slipping consistency, and it usually shows up here before it shows up in a bigger failure.
How to calculate this metric
Divide the number of returned or defective items by the total delivered in the period, then multiply by 100. For services, adapt this to the share of work that needed rework or was rejected. Track by product or service line so a problem in one area doesn't hide in a healthy overall average.
How to improve this metric
Bring the rate down by feeding defect data back to the vendor with enough detail to find the cause, not just the symptom. Set a defect threshold in the contract with consequences for breaching it, and require a corrective action plan when a vendor crosses it. Reassess vendors whose defect rate won't come down despite clear feedback.
6. Vendor availability rate
Vendor availability rate is the share of time a vendor's service or product is up and usable when you need it. For infrastructure and SaaS vendors, this is often the single most important performance number, since their downtime becomes yours.
How to calculate this metric
Divide the time the vendor's service was available by the total time in the period, then multiply by 100, usually expressed as a percentage like 99.9. Measure against the uptime commitment in their SLA, and count only the downtime that affected you. Track planned and unplanned downtime separately so maintenance windows don't distort the picture.
How to improve this metric
Hold availability high by writing firm uptime commitments and meaningful service credits into contracts so downtime carries a cost for the vendor. Monitor availability independently rather than relying only on the vendor's own reporting, and require a root-cause analysis after major outages. For critical services, plan for failover so a single vendor's downtime doesn't stop you.
7. Compliance with service level agreements
SLA compliance measures how well a vendor lives up to the specific commitments in their service level agreement, from uptime to response times. It's the metric that tells you whether the promises in the contract are holding in practice.
How to calculate this metric
Track each SLA commitment the vendor made, then measure the share they met over the period across all of them. Weight the commitments by how much each matters to you so a missed uptime target counts more than a missed report deadline. Review the results against the credits or penalties the SLA specifies.
How to improve this metric
Improve compliance by writing SLAs that are specific and measurable rather than aspirational, so both sides know what counts as a miss. Review SLA performance with the vendor on a regular cadence, and enforce the credits or remedies the contract provides. Renegotiate or replace vendors that treat SLA targets as optional.
8. Percentage of contract fulfillment
Percentage of contract fulfillment is the share of a vendor's contractual terms and deliverables they've completed. It's a broad health check on the relationship, catching gaps that single-metric views can miss.
How to calculate this metric
List the deliverables and obligations in the contract, then divide the number completed to standard by the total due in the period, and multiply by 100. Include both the tangible deliverables and the softer commitments, like reporting or security obligations. Track it per contract so a vendor with several agreements doesn't blur into one figure.
How to improve this metric
Raise fulfillment by turning the contract into a tracked checklist rather than a document nobody revisits after signing. Review obligations with the vendor at regular checkpoints so gaps surface early, and address chronic shortfalls before renewal. Make sure your own side of the contract, like timely inputs and approvals, isn't the reason a vendor falls short.
{{cta_webinar4="/cta-blocks"}} | Webinar: Vendor risk management
The 8 vendor risk management KRIs to track
The KRIs below are the early-warning side of vendor risk. Where the performance KPIs above measure how well a vendor is delivering, these watch for the signals that a vendor is becoming a liability, from compliance failures and breaches to financial distress and over-dependence. Each one tends to move before a vendor problem reaches your business, which is what makes them worth watching rather than waiting for the incident to arrive. For each you'll find what it measures, how to calculate it, and how to reduce the risk it flags.
1. Regulatory compliance violations
Regulatory compliance violations track how often a vendor fails to meet the regulatory standards or frameworks they're bound by, from data protection law to industry rules. Each violation is a leading signal of legal and reputational risk that can flow straight through to you, since a regulator rarely stops at the vendor when your data was involved.
How to calculate this metric
Count the confirmed compliance violations across your vendors over a period, weighting by severity and by how close the vendor sits to your regulated data. Draw the count from audit findings, breach notifications, and regulatory actions rather than the vendor's own assurances alone. Track it per vendor so a single repeat offender stands out from the portfolio.
How to improve this metric
Reduce violations by making evidence of compliance a hard requirement of vendor due diligence at onboarding and again at renewal, not just a checkbox attestation. Write regulatory obligations and audit rights into contracts so you can verify rather than assume, and monitor vendors in regulated functions more closely. Where a vendor keeps falling short of a standard your business depends on, treat it as grounds to begin vendor offboarding and move the work to a replacement.
2. Number of security breaches
This KRI tracks how often a vendor suffers unauthorized access or a data breach in their environment. Because a vendor breach can expose the data and access you've granted them, their incident history is one of the sharpest predictors of a third-party incident landing on you.
How to calculate this metric
Count the confirmed breaches a vendor has disclosed or that surface through monitoring over a defined period, and weight by whether your data or access was in scope. Pull this from breach disclosures, security-rating feeds, and threat intelligence rather than waiting for the vendor to volunteer it. Track both the raw count and the trend, since a rising frequency matters more than a single old incident.
How to improve this metric
Bring the number down at the portfolio level by favoring vendors with strong, evidenced security postures and by reducing the data and access you hand each one. Require prompt breach notification in contracts so you learn early, and reassess any vendor after an incident to confirm they've closed the gap. Continuous monitoring is what turns this into an early warning rather than a yearly look back, since a platform like Vanta's Vendor Risk Management can flag a vendor's breach disclosure or a drop in their security rating as it happens.
3. Financial stability ratios
Financial stability ratios, like debt-to-equity and liquidity measures, signal whether a vendor is healthy enough to keep meeting its obligations to you. A vendor sliding toward financial distress is a continuity risk long before it misses a delivery, which is what makes this a leading indicator worth watching for critical suppliers.
How to calculate this metric
Pull the vendor's financial ratios from their statements, credit reports, or a third-party risk-rating service, focusing on liquidity, leverage, and profitability trends. Compare each ratio against healthy ranges for the vendor's industry rather than in isolation. Track the direction over time, since a worsening trend warns you earlier than any single reading.
How to improve this metric
Manage this risk by monitoring the financial health of your critical vendors on a regular cadence, not just at onboarding. Diversify away from vendors showing distress, and build contingency plans for the ones you can't quickly replace. Where a critical vendor's finances deteriorate, tighten payment and delivery terms and prepare an exit before a failure forces one.
4. Frequency of service disruptions
Frequency of service disruptions counts how often a vendor's service goes down or is interrupted without warning. Each unplanned outage is an operational risk that becomes yours in the moment, and a climbing frequency is an early sign a vendor's reliability is slipping.
How to calculate this metric
Count the unplanned disruptions to a vendor's service over the period, separating them from scheduled maintenance. Measure both frequency and duration, since many short blips and a few long outages point to different problems. Track against the vendor's uptime commitment so the count reflects a real breach of expectations.
How to improve this metric
Reduce disruption risk by holding vendors to firm uptime terms with meaningful credits, and by requiring a root-cause analysis after significant outages. Monitor availability independently so you catch degradation before it becomes a pattern. For services you can't afford to lose, build redundancy or a failover path so a single vendor's disruption doesn't stop your operations.
5. Vendor dependency ratio
Vendor dependency ratio measures how much a project or function relies on a single vendor's product, infrastructure, and expertise. High dependency signals vulnerabilities like delays, lock-in, and a hard exit, since the more you lean on one vendor, the more their problems become unavoidable for you.
How to calculate this metric
Assess, for each critical function, how much of it depends on one vendor across their product, their infrastructure, and the know-how only they hold. Express it as the share of the function that would stall if the vendor failed, and flag any function with a single provider and no ready substitute. Track the vendors your operations most depend on as a standing list.
How to improve this metric
Lower dependency by qualifying alternatives for your most critical functions and by avoiding designs that lock you into one vendor's proprietary approach. Keep documentation and knowledge in-house rather than resident only with the vendor, and negotiate exit terms that let you leave without losing your data or continuity. Where dependency is unavoidable, manage the relationship with the extra care a single point of failure deserves.
6. Criticality of vendor services
Criticality of vendor services rates how much a vendor's output matters to your core operations, from production to sales. It's less a moving number than a classification, but it's the lens that tells you which vendor risks are worth losing sleep over, since a failure at a critical vendor hits differently than one at a convenience tool.
How to calculate this metric
Rate each vendor by the operational impact if their service failed, considering revenue, core processes, and how quickly the failure would hurt. Use a simple tier, such as critical, important, and low, and set it from business impact rather than spend. Reassess criticality when your operations change, since a vendor's importance can rise as you build more on top of them.
How to improve this metric
You don't lower criticality so much as manage around it. Concentrate your monitoring, assessment, and continuity planning on the vendors rated critical, and hold them to tighter terms. Where a single vendor is both critical and hard to replace, reducing that concentration, through alternatives or redundancy, is the real improvement.
7. Vendor management personnel turnover
This KRI tracks turnover in the key roles that run your vendor risk program, since a program is only as stable as the people maintaining it. High turnover among the staff who assess, monitor, and manage vendors is a leading risk to your whole VRM effort, because relationships lapse and reviews slip when the people who owned them leave.
How to calculate this metric
Measure the turnover rate in your vendor management and third-party risk roles over a period, the same way you would for any team. Watch for knowledge concentrated in individuals, where one departure would leave critical vendor relationships or reviews unowned. Pair the rate with how many critical vendors lack a documented backup owner.
How to improve this metric
Reduce this risk by documenting vendor relationships and processes so knowledge lives in the program, not in one person's head. Cross-train owners and assign backups for critical vendors so a departure doesn't strand a relationship. Where risk management automation can carry monitoring and scheduling, it steadies the program against turnover better than heroics from a stretched team.
8. Vendor's business continuity
This KRI evaluates how ready a vendor is to keep operating through a crisis, from a natural disaster to a cyberattack. A vendor without a tested continuity plan is a risk that stays invisible until the day it matters most, which is exactly why you assess it before that day arrives.
How to calculate this metric
Assess each critical vendor's continuity readiness through their business continuity and disaster recovery plans, their testing history, and their recovery time objectives. Score them on whether the plans exist, are current, and have been exercised, not just whether a document is on file. Weight the assessment toward the vendors your operations most depend on.
How to improve this metric
Strengthen this by requiring evidence of tested continuity plans from critical vendors during vendor onboarding and at renewal, rather than accepting a claim. Build your own continuity plans around the vendors you can't do without, including failover and alternative suppliers. Review continuity readiness on a cadence, since a plan that was solid two years ago may no longer match the vendor's operations.
{{cta_withimage5="/cta-blocks"}}
How to choose the vendor metrics that fit your program
Start from what your vendors do for you, not from a generic list. Risk management frameworks give you the categories of risk worth watching, but they won't tell you which numbers belong on your dashboard, so use them to scope the exercise and let your vendor portfolio pick the metrics. A SaaS provider holding customer data calls for security and compliance metrics, while a vendor critical to operations calls for continuity and dependency metrics. Ask what decision each metric drives, and if a number won't change how you treat a vendor, leave it off the dashboard.
Then balance leading and lagging. Pair KRIs that warn you, like a critical vendor's security rating slipping or its financial footing weakening, with KPIs that show how well a vendor delivers, like on-time delivery and SLA compliance. Keep the executive view small, usually 5 to 8 measures, and tier the rest so critical vendors get watched more closely than the long tail.
Make each metric you keep actionable. Give it a threshold tied to your risk appetite so a reading tells you whether to act, and confirm you can feed it with trustworthy vendor data on the cadence you need. Watch out for vanity metrics whose answer you already know, since a number that never moves teaches you nothing. Revisit the set as your portfolio changes, retiring measures that have sat healthy for a year and adding new ones as fresh third-party risks appear.
How often to report each metric
Cadence should match how fast a metric moves. Live KRIs, like a critical vendor's security rating or a new breach disclosure, work best as continuous monitoring with alert thresholds so a change reaches you the day it happens. Operational KPIs, like on-time delivery and response time to incidents, fit a weekly or monthly review with your team.
Portfolio-level views, like your overall vendor risk exposure and how concentrated you are on a few critical vendors, belong on a quarterly rhythm where the trend matters more than the daily movement. Keep one live view underneath for the signals that need fast action and a clean quarterly summary on top for leadership, both drawn from the same data so the numbers always agree.
{{cta_testimonial5="/cta-blocks"}}
Leveraging technology for efficient VRM
Technology plays a critical role in tracking VRM metrics efficiently. For instance, you need data collection tools to gather, visualize, and analyze KPI and KRI data from multiple sources, such as ERP and CRM platforms.
That’s why many VRM solutions today are bolstering their capabilities with AI, machine learning, and process automation technology. These tools reduce manual effort and promote efficient metrics tracking in several ways, such as:
- APIs to collect relevant data from other platforms.
- Machine learning and predictive analytics to identify trends in vendor data.
- Automation-enabled vendor due diligence and risk assessments.
- AI-powered insights to improve your VRM program.
- Dashboards offering real-time visibility into key metrics.
Turn your vendor metrics into a live view of third-party risk
Vendor metrics earn their keep only when they're current. A risk score built on a security questionnaire from last year can't warn you that a critical vendor was breached last week, and a quarterly snapshot misses the drift in between. The shift worth making is from point-in-time vendor reviews to continuous monitoring, where a vendor's rating drop or breach disclosure shows up the day it happens.
Tracking KPIs and KRIs is a non-negotiable part of building a reliable working partnership with vendors. You can ensure your tracking processes are efficient and watertight with Vanta’s Vendor Risk Management software solution.
Vanta removes manual work across your VRM program—from onboarding to risk assessment and remediation. Here are some of its key features that boost efficiency:
- Centralized vendor inventory (with automated onboarding)
- Customizable vendor risk assessments with auto-scoring
- Built-in rubrics to calculate vendor risks and analyze access controls
- Comprehensive visual dashboard with real-time insights into tracked metrics
- Automated vendor security reviews and suggested follow-up tasks
- 400+ integrations to create a cohesive VRM workflow
- Logic-based tests for continuous monitoring of controls
Watch our webinar to see Vanta in action. Or request a custom demo to get started!
{{cta_simple5="/cta-blocks"}}
Frequently asked questions
What are vendor risk management metrics?
Vendor risk management metrics are quantified measures that show how much risk your third-party vendors introduce and how well your program assesses, monitors, and reduces that risk. They split into key risk indicators, which warn you before a vendor problem reaches your business, and key performance indicators, which measure how well your program is performing.
What is the difference between vendor KPIs and KRIs?
A vendor KPI measures performance against a target, such as the percentage of findings a vendor remediates on time. A vendor KRI measures risk against a threshold, such as a critical vendor's security rating dropping below your floor. KPIs tell you how your program is doing, while KRIs warn you about trouble ahead, and a strong dashboard carries both.
What are the most important vendor risk management metrics?
The measures that matter most span both sides of vendor risk. On performance, watch on-time delivery, SLA compliance, response time to incidents, and vendor availability. On risk, watch regulatory compliance violations, security breaches, financial stability, and vendor dependency. Together they show how well a vendor delivers and where it could hurt you, and you should weight the set toward your most critical vendors.
How often should you reassess vendors?
Set reassessment frequency by vendor tier, reviewing critical vendors at least annually and often more, while lower-risk vendors can go longer. Continuous monitoring reduces how often a full manual reassessment is needed by catching posture changes between reviews. Track your reassessment overdue rate so scheduled reviews don't quietly slip.
How do you measure third-party risk?
Measure third-party risk by scoring each vendor for the risk it introduces, weighting the score by how critical the vendor is and how much data or access it holds, then rolling those scores into a vendor risk assessment report that gives you a portfolio view. Layer on coverage, remediation, monitoring, and incident metrics to see not just how much risk you carry but how well you manage it. Continuous monitoring keeps the picture current between formal assessments.
Running a VRM program
16 vendor risk management metrics teams should track in 2026

Looking to save up to 50% of time with AI-powered security reviews?
Vendor risk management metrics turn a gut feeling about a vendor into a number you can act on. They split in two: KRIs are the early warnings that a vendor is drifting toward trouble, and KPIs show whether your program is keeping up with what you find. That matters because most breaches now arrive through a supplier, and a risk you can't measure is one you can't manage, fund, or defend to your board or your auditors.
Plenty of programs track vendor metrics and still get blindsided, because the goal was never more data, it was the handful of numbers that change what you do next. Below, you'll find the KRIs and KPIs worth tracking, each with a plain formula, how to read it, and what to do when it moves the wrong way.
How vendor KPIs and KRIs fit together
Most vendor risk metrics are either a KRI or a KPI, and the difference is about timing. A KRI looks forward. It watches a number that tends to move before a vendor causes a problem, so you can act while you still have room. A KPI looks back. It tells you whether your program did its job over the last week, month, or quarter. Many of the strongest metrics work as both, read one way for early warning and another for performance.
You want a mix. A dashboard of only KPIs tells you how you did but never warns you in time. A dashboard of only KRIs warns you constantly but never proves the program is working. Pairing the two is what lets you manage third-party risk instead of just describing it.
To maintain a balanced overview of vendor performance and third-party risk exposure, you need to track the following metrics:
- Key performance indicators (KPIs)
- Key risk indicators (KRIs)
KPIs measure a vendor’s efficiency, quality, and consistency in delivering the contracted products and services. The following table identifies the three common categories of KPIs:
Vendor KRIs, on the other hand, are risk-based metrics that assess vulnerabilities associated with vendor relationships. They serve as early warnings of issues that could harm your business. Here are the three common categories of KRIs you can track:
8 vendor risk management KPIs to track
The KPIs below measure how well a vendor delivers on what you're paying for, from meeting deadlines to holding up their service levels. Where the risk metrics later in this guide watch for what could go wrong, these track day-to-day performance, the reliability, quality, and value a vendor brings. They fall into three groups, operational efficiency, service quality, and cost, and most programs pull a handful from each rather than tracking all ten. For each one you'll find what it measures, how to calculate it, and how to improve it.
1. On-time delivery rate
On-time delivery rate is the share of a vendor's deliveries that arrive on or before their scheduled date. It's the clearest read on whether a vendor is reliable enough to plan around, and a slipping rate is often the first sign of trouble on their end.
How to calculate this metric
Divide the number of deliveries made on or before their due date by the total number of deliveries in the period, then multiply by 100. Track it per vendor and against the commitment in their contract or SLA so the rate reflects the standard you agreed to. Watch the trend rather than a single month, since one bad period can have a one-off cause.
How to improve this metric
Raise the rate by setting clear delivery expectations in the contract and reviewing misses with the vendor promptly so patterns don't set in. Give vendors enough lead time and accurate forecasts so delays aren't your doing, and escalate repeat lateness through the relationship. For vendors that stay unreliable on critical deliveries, line up an alternative.
2. Quality of deliverables
Quality of deliverables is a composite score of how well a vendor's products or services meet the standards you set. It turns a subjective sense of good or bad work into a number you can trend and compare across vendors.
How to calculate this metric
Define the quality criteria that matter for the service, such as accuracy, completeness, or defect rate, and score each delivery against them. Combine the scores into one weighted figure per vendor, weighting the criteria that matter most to you. Keep the rubric consistent so scores stay comparable over time and across vendors.
How to improve this metric
Improve quality by sharing your rubric with vendors up front so they know exactly what good looks like. Give specific, documented feedback on shortfalls rather than general complaints, and tie repeated quality misses to contract terms or renewal decisions. Recognize vendors that score well so the standard has a reward as well as a stick.
3. Cost savings achieved
Cost savings achieved captures how much a vendor reduces your operational expense, whether through pricing, efficiency, or avoided rework. It's the KPI that shows a vendor's value in the language leadership cares about most.
How to calculate this metric
Compare your actual spend and outcomes with the vendor against a baseline, such as your prior provider, your budget, or the market rate. Include indirect savings like reduced rework or downtime where you can measure them, not just the invoice. Report savings over a consistent period so the figure reflects a real trend rather than a one-time negotiation.
How to improve this metric
Grow savings by negotiating on total value rather than headline price, and by consolidating spend with vendors that earn it through performance. Review contracts before auto-renewal so you capture market shifts, and use benchmarking data to hold pricing honest. Track the savings each vendor drives so the strong performers are easy to reward with more work.
4. Response time to incidents
Response time to incidents is the average time a vendor takes to acknowledge and resolve a problem once it's raised. For any vendor your operations depend on, this is the number that predicts how much a disruption will cost you.
How to calculate this metric
Measure the time from when an incident is reported to the vendor to when it's resolved, averaged across incidents in the period. Split acknowledgment time from resolution time, since a fast reply followed by a slow fix is a different problem than silence. Track it against the response commitments in the vendor's SLA.
How to improve this metric
Shorten response time by writing clear incident SLAs with defined severities and escalation paths into the contract. Establish a named contact and an agreed channel for urgent issues rather than a shared inbox, and run through a real incident with critical vendors before one happens. Hold vendors to their committed times and factor chronic slowness into renewals.
5. Rate of return or defects
Rate of return or defects tracks how often a vendor's goods come back or their services fall short. A rising rate points to slipping consistency, and it usually shows up here before it shows up in a bigger failure.
How to calculate this metric
Divide the number of returned or defective items by the total delivered in the period, then multiply by 100. For services, adapt this to the share of work that needed rework or was rejected. Track by product or service line so a problem in one area doesn't hide in a healthy overall average.
How to improve this metric
Bring the rate down by feeding defect data back to the vendor with enough detail to find the cause, not just the symptom. Set a defect threshold in the contract with consequences for breaching it, and require a corrective action plan when a vendor crosses it. Reassess vendors whose defect rate won't come down despite clear feedback.
6. Vendor availability rate
Vendor availability rate is the share of time a vendor's service or product is up and usable when you need it. For infrastructure and SaaS vendors, this is often the single most important performance number, since their downtime becomes yours.
How to calculate this metric
Divide the time the vendor's service was available by the total time in the period, then multiply by 100, usually expressed as a percentage like 99.9. Measure against the uptime commitment in their SLA, and count only the downtime that affected you. Track planned and unplanned downtime separately so maintenance windows don't distort the picture.
How to improve this metric
Hold availability high by writing firm uptime commitments and meaningful service credits into contracts so downtime carries a cost for the vendor. Monitor availability independently rather than relying only on the vendor's own reporting, and require a root-cause analysis after major outages. For critical services, plan for failover so a single vendor's downtime doesn't stop you.
7. Compliance with service level agreements
SLA compliance measures how well a vendor lives up to the specific commitments in their service level agreement, from uptime to response times. It's the metric that tells you whether the promises in the contract are holding in practice.
How to calculate this metric
Track each SLA commitment the vendor made, then measure the share they met over the period across all of them. Weight the commitments by how much each matters to you so a missed uptime target counts more than a missed report deadline. Review the results against the credits or penalties the SLA specifies.
How to improve this metric
Improve compliance by writing SLAs that are specific and measurable rather than aspirational, so both sides know what counts as a miss. Review SLA performance with the vendor on a regular cadence, and enforce the credits or remedies the contract provides. Renegotiate or replace vendors that treat SLA targets as optional.
8. Percentage of contract fulfillment
Percentage of contract fulfillment is the share of a vendor's contractual terms and deliverables they've completed. It's a broad health check on the relationship, catching gaps that single-metric views can miss.
How to calculate this metric
List the deliverables and obligations in the contract, then divide the number completed to standard by the total due in the period, and multiply by 100. Include both the tangible deliverables and the softer commitments, like reporting or security obligations. Track it per contract so a vendor with several agreements doesn't blur into one figure.
How to improve this metric
Raise fulfillment by turning the contract into a tracked checklist rather than a document nobody revisits after signing. Review obligations with the vendor at regular checkpoints so gaps surface early, and address chronic shortfalls before renewal. Make sure your own side of the contract, like timely inputs and approvals, isn't the reason a vendor falls short.
{{cta_webinar4="/cta-blocks"}} | Webinar: Vendor risk management
The 8 vendor risk management KRIs to track
The KRIs below are the early-warning side of vendor risk. Where the performance KPIs above measure how well a vendor is delivering, these watch for the signals that a vendor is becoming a liability, from compliance failures and breaches to financial distress and over-dependence. Each one tends to move before a vendor problem reaches your business, which is what makes them worth watching rather than waiting for the incident to arrive. For each you'll find what it measures, how to calculate it, and how to reduce the risk it flags.
1. Regulatory compliance violations
Regulatory compliance violations track how often a vendor fails to meet the regulatory standards or frameworks they're bound by, from data protection law to industry rules. Each violation is a leading signal of legal and reputational risk that can flow straight through to you, since a regulator rarely stops at the vendor when your data was involved.
How to calculate this metric
Count the confirmed compliance violations across your vendors over a period, weighting by severity and by how close the vendor sits to your regulated data. Draw the count from audit findings, breach notifications, and regulatory actions rather than the vendor's own assurances alone. Track it per vendor so a single repeat offender stands out from the portfolio.
How to improve this metric
Reduce violations by making evidence of compliance a hard requirement of vendor due diligence at onboarding and again at renewal, not just a checkbox attestation. Write regulatory obligations and audit rights into contracts so you can verify rather than assume, and monitor vendors in regulated functions more closely. Where a vendor keeps falling short of a standard your business depends on, treat it as grounds to begin vendor offboarding and move the work to a replacement.
2. Number of security breaches
This KRI tracks how often a vendor suffers unauthorized access or a data breach in their environment. Because a vendor breach can expose the data and access you've granted them, their incident history is one of the sharpest predictors of a third-party incident landing on you.
How to calculate this metric
Count the confirmed breaches a vendor has disclosed or that surface through monitoring over a defined period, and weight by whether your data or access was in scope. Pull this from breach disclosures, security-rating feeds, and threat intelligence rather than waiting for the vendor to volunteer it. Track both the raw count and the trend, since a rising frequency matters more than a single old incident.
How to improve this metric
Bring the number down at the portfolio level by favoring vendors with strong, evidenced security postures and by reducing the data and access you hand each one. Require prompt breach notification in contracts so you learn early, and reassess any vendor after an incident to confirm they've closed the gap. Continuous monitoring is what turns this into an early warning rather than a yearly look back, since a platform like Vanta's Vendor Risk Management can flag a vendor's breach disclosure or a drop in their security rating as it happens.
3. Financial stability ratios
Financial stability ratios, like debt-to-equity and liquidity measures, signal whether a vendor is healthy enough to keep meeting its obligations to you. A vendor sliding toward financial distress is a continuity risk long before it misses a delivery, which is what makes this a leading indicator worth watching for critical suppliers.
How to calculate this metric
Pull the vendor's financial ratios from their statements, credit reports, or a third-party risk-rating service, focusing on liquidity, leverage, and profitability trends. Compare each ratio against healthy ranges for the vendor's industry rather than in isolation. Track the direction over time, since a worsening trend warns you earlier than any single reading.
How to improve this metric
Manage this risk by monitoring the financial health of your critical vendors on a regular cadence, not just at onboarding. Diversify away from vendors showing distress, and build contingency plans for the ones you can't quickly replace. Where a critical vendor's finances deteriorate, tighten payment and delivery terms and prepare an exit before a failure forces one.
4. Frequency of service disruptions
Frequency of service disruptions counts how often a vendor's service goes down or is interrupted without warning. Each unplanned outage is an operational risk that becomes yours in the moment, and a climbing frequency is an early sign a vendor's reliability is slipping.
How to calculate this metric
Count the unplanned disruptions to a vendor's service over the period, separating them from scheduled maintenance. Measure both frequency and duration, since many short blips and a few long outages point to different problems. Track against the vendor's uptime commitment so the count reflects a real breach of expectations.
How to improve this metric
Reduce disruption risk by holding vendors to firm uptime terms with meaningful credits, and by requiring a root-cause analysis after significant outages. Monitor availability independently so you catch degradation before it becomes a pattern. For services you can't afford to lose, build redundancy or a failover path so a single vendor's disruption doesn't stop your operations.
5. Vendor dependency ratio
Vendor dependency ratio measures how much a project or function relies on a single vendor's product, infrastructure, and expertise. High dependency signals vulnerabilities like delays, lock-in, and a hard exit, since the more you lean on one vendor, the more their problems become unavoidable for you.
How to calculate this metric
Assess, for each critical function, how much of it depends on one vendor across their product, their infrastructure, and the know-how only they hold. Express it as the share of the function that would stall if the vendor failed, and flag any function with a single provider and no ready substitute. Track the vendors your operations most depend on as a standing list.
How to improve this metric
Lower dependency by qualifying alternatives for your most critical functions and by avoiding designs that lock you into one vendor's proprietary approach. Keep documentation and knowledge in-house rather than resident only with the vendor, and negotiate exit terms that let you leave without losing your data or continuity. Where dependency is unavoidable, manage the relationship with the extra care a single point of failure deserves.
6. Criticality of vendor services
Criticality of vendor services rates how much a vendor's output matters to your core operations, from production to sales. It's less a moving number than a classification, but it's the lens that tells you which vendor risks are worth losing sleep over, since a failure at a critical vendor hits differently than one at a convenience tool.
How to calculate this metric
Rate each vendor by the operational impact if their service failed, considering revenue, core processes, and how quickly the failure would hurt. Use a simple tier, such as critical, important, and low, and set it from business impact rather than spend. Reassess criticality when your operations change, since a vendor's importance can rise as you build more on top of them.
How to improve this metric
You don't lower criticality so much as manage around it. Concentrate your monitoring, assessment, and continuity planning on the vendors rated critical, and hold them to tighter terms. Where a single vendor is both critical and hard to replace, reducing that concentration, through alternatives or redundancy, is the real improvement.
7. Vendor management personnel turnover
This KRI tracks turnover in the key roles that run your vendor risk program, since a program is only as stable as the people maintaining it. High turnover among the staff who assess, monitor, and manage vendors is a leading risk to your whole VRM effort, because relationships lapse and reviews slip when the people who owned them leave.
How to calculate this metric
Measure the turnover rate in your vendor management and third-party risk roles over a period, the same way you would for any team. Watch for knowledge concentrated in individuals, where one departure would leave critical vendor relationships or reviews unowned. Pair the rate with how many critical vendors lack a documented backup owner.
How to improve this metric
Reduce this risk by documenting vendor relationships and processes so knowledge lives in the program, not in one person's head. Cross-train owners and assign backups for critical vendors so a departure doesn't strand a relationship. Where risk management automation can carry monitoring and scheduling, it steadies the program against turnover better than heroics from a stretched team.
8. Vendor's business continuity
This KRI evaluates how ready a vendor is to keep operating through a crisis, from a natural disaster to a cyberattack. A vendor without a tested continuity plan is a risk that stays invisible until the day it matters most, which is exactly why you assess it before that day arrives.
How to calculate this metric
Assess each critical vendor's continuity readiness through their business continuity and disaster recovery plans, their testing history, and their recovery time objectives. Score them on whether the plans exist, are current, and have been exercised, not just whether a document is on file. Weight the assessment toward the vendors your operations most depend on.
How to improve this metric
Strengthen this by requiring evidence of tested continuity plans from critical vendors during vendor onboarding and at renewal, rather than accepting a claim. Build your own continuity plans around the vendors you can't do without, including failover and alternative suppliers. Review continuity readiness on a cadence, since a plan that was solid two years ago may no longer match the vendor's operations.
{{cta_withimage5="/cta-blocks"}}
How to choose the vendor metrics that fit your program
Start from what your vendors do for you, not from a generic list. Risk management frameworks give you the categories of risk worth watching, but they won't tell you which numbers belong on your dashboard, so use them to scope the exercise and let your vendor portfolio pick the metrics. A SaaS provider holding customer data calls for security and compliance metrics, while a vendor critical to operations calls for continuity and dependency metrics. Ask what decision each metric drives, and if a number won't change how you treat a vendor, leave it off the dashboard.
Then balance leading and lagging. Pair KRIs that warn you, like a critical vendor's security rating slipping or its financial footing weakening, with KPIs that show how well a vendor delivers, like on-time delivery and SLA compliance. Keep the executive view small, usually 5 to 8 measures, and tier the rest so critical vendors get watched more closely than the long tail.
Make each metric you keep actionable. Give it a threshold tied to your risk appetite so a reading tells you whether to act, and confirm you can feed it with trustworthy vendor data on the cadence you need. Watch out for vanity metrics whose answer you already know, since a number that never moves teaches you nothing. Revisit the set as your portfolio changes, retiring measures that have sat healthy for a year and adding new ones as fresh third-party risks appear.
How often to report each metric
Cadence should match how fast a metric moves. Live KRIs, like a critical vendor's security rating or a new breach disclosure, work best as continuous monitoring with alert thresholds so a change reaches you the day it happens. Operational KPIs, like on-time delivery and response time to incidents, fit a weekly or monthly review with your team.
Portfolio-level views, like your overall vendor risk exposure and how concentrated you are on a few critical vendors, belong on a quarterly rhythm where the trend matters more than the daily movement. Keep one live view underneath for the signals that need fast action and a clean quarterly summary on top for leadership, both drawn from the same data so the numbers always agree.
{{cta_testimonial5="/cta-blocks"}}
Leveraging technology for efficient VRM
Technology plays a critical role in tracking VRM metrics efficiently. For instance, you need data collection tools to gather, visualize, and analyze KPI and KRI data from multiple sources, such as ERP and CRM platforms.
That’s why many VRM solutions today are bolstering their capabilities with AI, machine learning, and process automation technology. These tools reduce manual effort and promote efficient metrics tracking in several ways, such as:
- APIs to collect relevant data from other platforms.
- Machine learning and predictive analytics to identify trends in vendor data.
- Automation-enabled vendor due diligence and risk assessments.
- AI-powered insights to improve your VRM program.
- Dashboards offering real-time visibility into key metrics.
Turn your vendor metrics into a live view of third-party risk
Vendor metrics earn their keep only when they're current. A risk score built on a security questionnaire from last year can't warn you that a critical vendor was breached last week, and a quarterly snapshot misses the drift in between. The shift worth making is from point-in-time vendor reviews to continuous monitoring, where a vendor's rating drop or breach disclosure shows up the day it happens.
Tracking KPIs and KRIs is a non-negotiable part of building a reliable working partnership with vendors. You can ensure your tracking processes are efficient and watertight with Vanta’s Vendor Risk Management software solution.
Vanta removes manual work across your VRM program—from onboarding to risk assessment and remediation. Here are some of its key features that boost efficiency:
- Centralized vendor inventory (with automated onboarding)
- Customizable vendor risk assessments with auto-scoring
- Built-in rubrics to calculate vendor risks and analyze access controls
- Comprehensive visual dashboard with real-time insights into tracked metrics
- Automated vendor security reviews and suggested follow-up tasks
- 400+ integrations to create a cohesive VRM workflow
- Logic-based tests for continuous monitoring of controls
Watch our webinar to see Vanta in action. Or request a custom demo to get started!
{{cta_simple5="/cta-blocks"}}
Frequently asked questions
What are vendor risk management metrics?
Vendor risk management metrics are quantified measures that show how much risk your third-party vendors introduce and how well your program assesses, monitors, and reduces that risk. They split into key risk indicators, which warn you before a vendor problem reaches your business, and key performance indicators, which measure how well your program is performing.
What is the difference between vendor KPIs and KRIs?
A vendor KPI measures performance against a target, such as the percentage of findings a vendor remediates on time. A vendor KRI measures risk against a threshold, such as a critical vendor's security rating dropping below your floor. KPIs tell you how your program is doing, while KRIs warn you about trouble ahead, and a strong dashboard carries both.
What are the most important vendor risk management metrics?
The measures that matter most span both sides of vendor risk. On performance, watch on-time delivery, SLA compliance, response time to incidents, and vendor availability. On risk, watch regulatory compliance violations, security breaches, financial stability, and vendor dependency. Together they show how well a vendor delivers and where it could hurt you, and you should weight the set toward your most critical vendors.
How often should you reassess vendors?
Set reassessment frequency by vendor tier, reviewing critical vendors at least annually and often more, while lower-risk vendors can go longer. Continuous monitoring reduces how often a full manual reassessment is needed by catching posture changes between reviews. Track your reassessment overdue rate so scheduled reviews don't quietly slip.
How do you measure third-party risk?
Measure third-party risk by scoring each vendor for the risk it introduces, weighting the score by how critical the vendor is and how much data or access it holds, then rolling those scores into a vendor risk assessment report that gives you a portfolio view. Layer on coverage, remediation, monitoring, and incident metrics to see not just how much risk you carry but how well you manage it. Continuous monitoring keeps the picture current between formal assessments.




Explore more TPRM articles
Introduction to TPRM
Vendor lifecycle management
Vendor risk assessment
Running a VRM program
Regulatory compliance and industry standards
Get started with TPRM
Start your TPRM journey with these related resources.

How to minimize third-party risk with vendor management
Get insights and best practices from security & compliance experts on how to manage third-party vendor risk in this free guide.
Vanta in Action: Vendor Risk Management
Vendor security reviews can be manual and time-consuming, draining security teams of precious hours. Vanta’s Vendor Risk Management solution changes that, automating and streamlining security reviews so that you can spend less time on repetitive work and more time strengthening your security posture. Curious to see what it looks like?

10 important questions to add to your security questionnaire [with examples]
Use these 10 vendor security questionnaire questions to assess compliance, uncover risks, and evaluate third-party vendors before onboarding.