SlideShare a Scribd company logo
16
Most read
18
Most read
22
Most read
Vendor Management: Using
COBIT 5
Introduction
New Guidance from ISACA
Areas covered
• IT
• Process owners and
stakeholders
• Compliance and laws
• Risk management
• Audit
• Contracts
• Service monitoring
Vendors
• A vendor is a third party that supplies
products or services to an enterprise.
• Most enterprises seek external vendor support
for assistance with operations for one of the
following reasons:
– Vendor expertise
– Vendor capacity
– Vendor assuming risk
– Vendor leveraging scale
Vendor Management
• Vendor management is a strategic process
that is dedicated to the sourcing and
management of vendor relationships so that:
– value creation is maximized and
– risk to the enterprise is minimized
Vendor Management Objectives
Managing vendors has many benefits, including:
• Data loss reduction
• Decrease in audit findings
• Cost optimization
• Increased availability
• Liability reduction
• Increased end-user satisfaction
• Value creation
Vendors to include
 Play a critical role in daily operations
 Can have critical impact on the success of
strategic projects
 Require long-term contracts
 Have potential significant financial implications
 Are difficult to change overnight
 Require frequent interaction and/or disputes
 Access or manage substantial critical or sensitive
data
Important Documents
Contract Lifecycle
Contract
Contracts accomplishes the following:
• Form a common understanding of what needs to
be achieved
• Define all deliverables, relevant service levels and
metrics
• Define responsibilities and obligations
• Define the terms and conditions
• Specify how risk will be allocated between parties
• Define legal counsel and jurisdiction stipulations
SLAs
• An SLA is an agreement, preferably documented,
between a product or service provider and the
enterprise that defines minimum performance
targets for a deliverable and how they will be
measured and reported.
• The SLA enables customer and vendor
accountabilities and expectations to be clearly
understood. Performance can have the following
implications:
– Financial rewards (for exceeding targets)
– Financial penalties (for underperformance)
SLA Common Pitfalls
• Focus on the wrong objectives
• Simplistic metrics
• Inappropriate terminology
• Room for interpretation
• Labor-intensive reporting requirements
SLA Management Benefits
• Better alignment with business objectives
• Ability to manage services proactively
• Greater transparency of service delivery
• Lower service level management overhead
• Better relationships between the enterprise and
vendor
SLA Diagram
Stakeholder Responsibilities
Risk – 5 Threat Categories
• T1 – Selection: Wrong vendor
• T2 – Contract: Incomplete | Static
• T3 – Requirements: Poorly defined
• T4 – Governance: Inadequate vendor management
• T5 – Strategy: Vendor lock-in
Mitigation Strategy
Threat COBIT 5 Guidance
1. Diversify sourcing strategy to avoid
overreliance or vendor lock in
T5 APO02 Manage strategy, APO10
Manage suppliers
2. Establish policies and procedures for
vendor management
T4, T5 APO11 Manage quality
– Enablers: Principles, Policies and
Frameworks; Information
3. Establish a vendor management
governance model
T4, T5 APO09 Manage service agreements,
APO10 Manage suppliers
– Enabler: Organisational Structures
4. Set up a vendor management
organization within the enterprise (VMO)
T4, T5 APO10 Manage suppliers
-- Enablers: Organisational Structures;
People, Skills and Competencies
5. Forecast requirements regarding
the skills and competencies of the
vendor employees
T2 APO10 Manage suppliers
– Enablers: People, Skills and
Competencies
6. Use standard documents and
templates
T2 – Enabler: Information
Mitigation Strategy
Threat COBIT 5 Guidance
7. Formulate clear requirements T3, T5 BAI02 Manage requirements
definition, BAI03 Manage solutions
identification and build
– Enabler: Information
8. Perform adequate vendor
selection
T1, T5 APO10 Manage suppliers, APO12
Manage risk
– Enablers: People, Skills and
Competencies
9. Cover all relevant life-cycle events
during contract drafting
T2 APO11 Manage quality, APO12
Manage risk
– Enabler: Information
10. Determine the adequate security
and controls needed during the
relationship
T4, T2 APO11 Manage quality; APO12
Manage risk, MEA01 Monitor,
evaluate and assess performance and
conformance
– Enablers: Service, Infrastructure and
Applications; Information
Mitigation Strategy
Threat COBIT 5 Guidance
11. Set up SLAs T2 APO09 Manage service agreements
– Enabler: Information
12. Set up operating level
agreements (OLAs) and underpinning
contracts
T2 APO09 Manage service agreements
– Enabler: Information
13. Set up appropriate vendor
performance/service level
monitoring and reporting
T2, T4 APO09 Manage service agreements,
APO10 Manage suppliers,
MEA01 Monitor, evaluate and assess
performance and conformance
– Enabler: Information
14. Establish a penalties and reward
model with the vendor
T2 APO09 Manage service agreements,
APO10 Manage suppliers
Mitigation Strategy
Threat COBIT 5 Guidance
15. Conduct adequate vendor
relationship management during the
life cycle
T4 APO08 Manage relationships, APO10
Manage suppliers
– Enablers: Ethics, Culture and
Behaviour
16. Review contracts and SLAs on a
periodic basis
T4, T5 APO09 Manage service agreements,
MEA01 Monitor, evaluate
and assess performance and
conformance
– Enabler: Information
17. Conduct vendor risk management T4, T5 APO10 Manage suppliers, APO12
Manage risk
– Enabler: Organisational Structures
Mitigation Strategy
Threat COBIT 5 Guidance
18. Perform an evaluation of
compliance with enterprise policies
T4 APO10 Manage suppliers; MEA01
Monitor, evaluate and assess
performance and conformance;
MEA03 Monitor, evaluate and assess
compliance with external requirements
– Enablers: Principles, Policies and
Frameworks; Information
19. Perform an evaluation of vendor
internal controls
T4 APO10 Manage suppliers; APO12
Manage risk; MEA01
Monitor, evaluate and assess
performance and conformance
– Enabler: Organisational Structures;
Information
Mitigation Strategy
Threat COBIT 5 Guidance
20. Plan and manage the end of the
relationship
T2, T4,
T5
APO09 Manage service agreements;
APO10 Manage suppliers;
APO12 Manage risk
– Enabler: Services, Infrastructure and
Applications; People, Skills and
Competencies; Information
21. Use a vendor management
system
T1, T2,
T3, T4
APO08 Manage relationships; APO09
Manage service
agreements; APO11 Manage quality;
APO12 Manage risk
– Enabler: Services, Infrastructure and
Applications
22. Create data and hardware
disposal stipulations
T2, T4 APO12 Manage risk
– Enablers: Services, Infrastructure and
Applications; Information; Principles,
Policies and Frameworks
Q&A

More Related Content

PDF
Shadow IT And The Failure Of IT Architecture
PDF
Enterprise Architecture Implementation And The Open Group Architecture Framew...
PDF
Using togaf™ in government_enterprise_architecture_to_describe_the_it_archite...
PDF
COBIT 2019 Overview_v1.1.pdf
PPTX
Introduction to COBIT 2019 and IT management
PDF
Reengineering The IT Operating Model to Embrace The Power Of The Cloud
PPT
Cobit presentation
PPT
Business Architecture Defined
Shadow IT And The Failure Of IT Architecture
Enterprise Architecture Implementation And The Open Group Architecture Framew...
Using togaf™ in government_enterprise_architecture_to_describe_the_it_archite...
COBIT 2019 Overview_v1.1.pdf
Introduction to COBIT 2019 and IT management
Reengineering The IT Operating Model to Embrace The Power Of The Cloud
Cobit presentation
Business Architecture Defined

What's hot (20)

PDF
The Role of Data Governance in a Data Strategy
PPTX
Introduction to Enterprise architecture and the steps to perform an Enterpris...
PPTX
IT4IT Overview (A new standard for IT management)
PDF
Ecm roadmap v2 0
PDF
Review of Information Technology Function Critical Capability Models
PPTX
Understanding ITIL CMDB
PDF
Managed IT Solutions
PPTX
CMDB - Use Cases
PPTX
Cobit 5 - An Overview
PPTX
PPSX
BCMS Presentation1
PPTX
EA maturity models
PDF
3 Keys To Successful Master Data Management - Final Presentation
PPTX
Introduction to ITIL 4 and IT service management
PPTX
Introducing The Open Group IT4IT™ Standard
PDF
Data-Ed: Data-centric Strategy & Roadmap
PDF
Qap cobit2019-20181111
PPTX
CobiT Foundation Free Training
PPT
Architecture Series 5-1 EA As Corporate Strategy Introduction
PDF
Agile Solution Architecture and Design
The Role of Data Governance in a Data Strategy
Introduction to Enterprise architecture and the steps to perform an Enterpris...
IT4IT Overview (A new standard for IT management)
Ecm roadmap v2 0
Review of Information Technology Function Critical Capability Models
Understanding ITIL CMDB
Managed IT Solutions
CMDB - Use Cases
Cobit 5 - An Overview
BCMS Presentation1
EA maturity models
3 Keys To Successful Master Data Management - Final Presentation
Introduction to ITIL 4 and IT service management
Introducing The Open Group IT4IT™ Standard
Data-Ed: Data-centric Strategy & Roadmap
Qap cobit2019-20181111
CobiT Foundation Free Training
Architecture Series 5-1 EA As Corporate Strategy Introduction
Agile Solution Architecture and Design
Ad

Viewers also liked (20)

PPT
Vendor Management Systems Best Practices
PPTX
Agility under Control - SCRUM vs COBIT
PPT
Vendor Management
PPT
Vendor Management - Compliance Checklist Manifesto Series
PPTX
Governance and Management of Enterprise IT with COBIT 5 Framework
PPT
IT Strategic Vendor Management
PPTX
Outsourcing and Vendor management
PDF
It governance & cobit 5
PPT
Top 10 Procurement KPI\'s
PPTX
Jeffrey Sweet - Third Party Risk Governance - Why? and How?
PDF
Equipo Interno de Implementacion ERP
PPTX
Horizon 2013 Zycus Vision
PPTX
BravoConnect 2014: Risk Management
PDF
Talend Data Preparation Overview
PPTX
Procurement Solutions - Paul Turner
PPTX
Introduction to Val IT
PDF
Tactica advanced sourcing solution
PDF
Key Challenges Facing Vendor Risk Management Programs
PDF
Negotiation
PPT
Supply Chain Council
Vendor Management Systems Best Practices
Agility under Control - SCRUM vs COBIT
Vendor Management
Vendor Management - Compliance Checklist Manifesto Series
Governance and Management of Enterprise IT with COBIT 5 Framework
IT Strategic Vendor Management
Outsourcing and Vendor management
It governance & cobit 5
Top 10 Procurement KPI\'s
Jeffrey Sweet - Third Party Risk Governance - Why? and How?
Equipo Interno de Implementacion ERP
Horizon 2013 Zycus Vision
BravoConnect 2014: Risk Management
Talend Data Preparation Overview
Procurement Solutions - Paul Turner
Introduction to Val IT
Tactica advanced sourcing solution
Key Challenges Facing Vendor Risk Management Programs
Negotiation
Supply Chain Council
Ad

Similar to Vendor management using COBIT 5 (20)

PPSX
How to implement a strategic IT vendor management program
PDF
Post Award Contract Management for IT Suppliers v1.0 20200701
PPTX
The Journey to World Class Presentation Contract Management - IACCM Sydney Co...
PPTX
Vendor selection
PPT
Outsource.ppt
PPTX
type of Vendor management in civil engineering
PPT
Procurement-Contract_Management_v2
PDF
The Enterprise Supply Chain View
PPT
The biggest problems caused by suppliers and how to prevent them
PPT
Iso 20000 presentation
PDF
EFS Facilities Services Group | Performance Management
PPTX
EFS Facilities Services Group | Performance Management
PDF
Supplier Relationship & Performance Management
PDF
Vendor Management Best Practices: Is Your Program Up to Par?
 
PPTX
Vendor Selection Process
PDF
The Enterprise Supply Chain View
PDF
The Enterprise Supply Chain View
PPT
Danforth Intl Presentation
PPTX
Governance in Outsourcing Made Simple
PPT
Improve Regulatory Compliance & Risk Management Using Best Practices
How to implement a strategic IT vendor management program
Post Award Contract Management for IT Suppliers v1.0 20200701
The Journey to World Class Presentation Contract Management - IACCM Sydney Co...
Vendor selection
Outsource.ppt
type of Vendor management in civil engineering
Procurement-Contract_Management_v2
The Enterprise Supply Chain View
The biggest problems caused by suppliers and how to prevent them
Iso 20000 presentation
EFS Facilities Services Group | Performance Management
EFS Facilities Services Group | Performance Management
Supplier Relationship & Performance Management
Vendor Management Best Practices: Is Your Program Up to Par?
 
Vendor Selection Process
The Enterprise Supply Chain View
The Enterprise Supply Chain View
Danforth Intl Presentation
Governance in Outsourcing Made Simple
Improve Regulatory Compliance & Risk Management Using Best Practices

Recently uploaded (20)

PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Getting Started with Data Integration: FME Form 101
PPTX
OMC Textile Division Presentation 2021.pptx
PPTX
TLE Review Electricity (Electricity).pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
Machine Learning_overview_presentation.pptx
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Approach and Philosophy of On baking technology
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPTX
cloud_computing_Infrastucture_as_cloud_p
PPTX
1. Introduction to Computer Programming.pptx
PPT
Teaching material agriculture food technology
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Empathic Computing: Creating Shared Understanding
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Network Security Unit 5.pdf for BCA BBA.
Getting Started with Data Integration: FME Form 101
OMC Textile Division Presentation 2021.pptx
TLE Review Electricity (Electricity).pptx
Encapsulation_ Review paper, used for researhc scholars
Programs and apps: productivity, graphics, security and other tools
Spectral efficient network and resource selection model in 5G networks
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Per capita expenditure prediction using model stacking based on satellite ima...
Machine Learning_overview_presentation.pptx
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Approach and Philosophy of On baking technology
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
cloud_computing_Infrastucture_as_cloud_p
1. Introduction to Computer Programming.pptx
Teaching material agriculture food technology
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
Empathic Computing: Creating Shared Understanding
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf

Vendor management using COBIT 5

  • 3. New Guidance from ISACA Areas covered • IT • Process owners and stakeholders • Compliance and laws • Risk management • Audit • Contracts • Service monitoring
  • 4. Vendors • A vendor is a third party that supplies products or services to an enterprise. • Most enterprises seek external vendor support for assistance with operations for one of the following reasons: – Vendor expertise – Vendor capacity – Vendor assuming risk – Vendor leveraging scale
  • 5. Vendor Management • Vendor management is a strategic process that is dedicated to the sourcing and management of vendor relationships so that: – value creation is maximized and – risk to the enterprise is minimized
  • 6. Vendor Management Objectives Managing vendors has many benefits, including: • Data loss reduction • Decrease in audit findings • Cost optimization • Increased availability • Liability reduction • Increased end-user satisfaction • Value creation
  • 7. Vendors to include  Play a critical role in daily operations  Can have critical impact on the success of strategic projects  Require long-term contracts  Have potential significant financial implications  Are difficult to change overnight  Require frequent interaction and/or disputes  Access or manage substantial critical or sensitive data
  • 10. Contract Contracts accomplishes the following: • Form a common understanding of what needs to be achieved • Define all deliverables, relevant service levels and metrics • Define responsibilities and obligations • Define the terms and conditions • Specify how risk will be allocated between parties • Define legal counsel and jurisdiction stipulations
  • 11. SLAs • An SLA is an agreement, preferably documented, between a product or service provider and the enterprise that defines minimum performance targets for a deliverable and how they will be measured and reported. • The SLA enables customer and vendor accountabilities and expectations to be clearly understood. Performance can have the following implications: – Financial rewards (for exceeding targets) – Financial penalties (for underperformance)
  • 12. SLA Common Pitfalls • Focus on the wrong objectives • Simplistic metrics • Inappropriate terminology • Room for interpretation • Labor-intensive reporting requirements
  • 13. SLA Management Benefits • Better alignment with business objectives • Ability to manage services proactively • Greater transparency of service delivery • Lower service level management overhead • Better relationships between the enterprise and vendor
  • 16. Risk – 5 Threat Categories • T1 – Selection: Wrong vendor • T2 – Contract: Incomplete | Static • T3 – Requirements: Poorly defined • T4 – Governance: Inadequate vendor management • T5 – Strategy: Vendor lock-in
  • 17. Mitigation Strategy Threat COBIT 5 Guidance 1. Diversify sourcing strategy to avoid overreliance or vendor lock in T5 APO02 Manage strategy, APO10 Manage suppliers 2. Establish policies and procedures for vendor management T4, T5 APO11 Manage quality – Enablers: Principles, Policies and Frameworks; Information 3. Establish a vendor management governance model T4, T5 APO09 Manage service agreements, APO10 Manage suppliers – Enabler: Organisational Structures 4. Set up a vendor management organization within the enterprise (VMO) T4, T5 APO10 Manage suppliers -- Enablers: Organisational Structures; People, Skills and Competencies 5. Forecast requirements regarding the skills and competencies of the vendor employees T2 APO10 Manage suppliers – Enablers: People, Skills and Competencies 6. Use standard documents and templates T2 – Enabler: Information
  • 18. Mitigation Strategy Threat COBIT 5 Guidance 7. Formulate clear requirements T3, T5 BAI02 Manage requirements definition, BAI03 Manage solutions identification and build – Enabler: Information 8. Perform adequate vendor selection T1, T5 APO10 Manage suppliers, APO12 Manage risk – Enablers: People, Skills and Competencies 9. Cover all relevant life-cycle events during contract drafting T2 APO11 Manage quality, APO12 Manage risk – Enabler: Information 10. Determine the adequate security and controls needed during the relationship T4, T2 APO11 Manage quality; APO12 Manage risk, MEA01 Monitor, evaluate and assess performance and conformance – Enablers: Service, Infrastructure and Applications; Information
  • 19. Mitigation Strategy Threat COBIT 5 Guidance 11. Set up SLAs T2 APO09 Manage service agreements – Enabler: Information 12. Set up operating level agreements (OLAs) and underpinning contracts T2 APO09 Manage service agreements – Enabler: Information 13. Set up appropriate vendor performance/service level monitoring and reporting T2, T4 APO09 Manage service agreements, APO10 Manage suppliers, MEA01 Monitor, evaluate and assess performance and conformance – Enabler: Information 14. Establish a penalties and reward model with the vendor T2 APO09 Manage service agreements, APO10 Manage suppliers
  • 20. Mitigation Strategy Threat COBIT 5 Guidance 15. Conduct adequate vendor relationship management during the life cycle T4 APO08 Manage relationships, APO10 Manage suppliers – Enablers: Ethics, Culture and Behaviour 16. Review contracts and SLAs on a periodic basis T4, T5 APO09 Manage service agreements, MEA01 Monitor, evaluate and assess performance and conformance – Enabler: Information 17. Conduct vendor risk management T4, T5 APO10 Manage suppliers, APO12 Manage risk – Enabler: Organisational Structures
  • 21. Mitigation Strategy Threat COBIT 5 Guidance 18. Perform an evaluation of compliance with enterprise policies T4 APO10 Manage suppliers; MEA01 Monitor, evaluate and assess performance and conformance; MEA03 Monitor, evaluate and assess compliance with external requirements – Enablers: Principles, Policies and Frameworks; Information 19. Perform an evaluation of vendor internal controls T4 APO10 Manage suppliers; APO12 Manage risk; MEA01 Monitor, evaluate and assess performance and conformance – Enabler: Organisational Structures; Information
  • 22. Mitigation Strategy Threat COBIT 5 Guidance 20. Plan and manage the end of the relationship T2, T4, T5 APO09 Manage service agreements; APO10 Manage suppliers; APO12 Manage risk – Enabler: Services, Infrastructure and Applications; People, Skills and Competencies; Information 21. Use a vendor management system T1, T2, T3, T4 APO08 Manage relationships; APO09 Manage service agreements; APO11 Manage quality; APO12 Manage risk – Enabler: Services, Infrastructure and Applications 22. Create data and hardware disposal stipulations T2, T4 APO12 Manage risk – Enablers: Services, Infrastructure and Applications; Information; Principles, Policies and Frameworks
  • 23. Q&A