Vendor risk

War-game a vendor risk scorecard before you publish it

War-game a vendor risk scorecard before bands, exception paths, and clawback rules harden into how every vendor grant gets made.

Vendor risk scorecards fail when the steps invent review speed security never funded, when grants dual-count the same vendor as scored and as waived, when procurement still promises custom floors in private channels, and when security ops cannot show which exceptions actually cleared under the published path. A neat scorecard flowchart is not evidence.

Freeze the scorecard draft

State the proposed score bands and owners, which vendor classes and regions it covers, who owns exception audit and clawback, what success looks like after two quarters of average score and exception rate, and the kill criteria if shadow floors or fairness disputes past a named threshold. Attach the current vendor distribution, sample grant logs, control samples, and the measured path from request to posted score. If security, procurement, and legal disagree on whether the scorecard buys risk clarity or just deferred vendor fights, reconcile before seating.

Name the decision you will make if the war game finds nothing new, and the hold criteria if any band still lacks a named owner or a verified audit path.

Hostile seats

  • Procurement buyer. Fear that "standard band" still means a quiet floor below the published ladder.
  • Security lead. Control math that looks clean while exception cohorts cannot be listed.
  • Legal. Talk tracks that invent review speed the scorecard never wrote.
  • Finance. Macros that still host retired exception language.
  • Skeptic. The claim that looks strongest and is least sourced.

Optional privacy seat if data processing language binds the form. Same pack for every seat.

Private passes

Feed Pingpong the scorecard draft and exhibits. First pass steelmans the scoring steps. Later passes attack from the seats above. Final pass turns surviving objections into clearer bands, a published clawback path, or a hold. Delete invented "vendors already expect these floors" claims and dual-counted grant rates.

Force a day-after narrative: what happens if a large account screenshots mismatched vendor terms, if procurement still teaches unwritten floors, or if security cannot list the open exception cohort. If those stories are stronger than your mitigation plan, fix the package before you publish it. Separate a vendor risk scorecard from a vendor selection review or a vendor exit stress test so each decision stays testable.

Ask every seat to mark which grants are optional in practice. Optional clawback audits become skipped within a month if nobody names the owner and the time box. Related: pretend you are the security ops lead, war-game an access review cadence, and the war-game decisions hub.