Vendor Intake & Onboarding
Vendor onboarded in one week
Vendor onboarding is a slow-motion multi-team relay: legal reviews the contract, security reviews the questionnaire, finance sets up the payment record, IT provisions any SSO integration. The vendor waits weeks. Every hand-off risks a drop. Every drop is a purchase-order clock ticking.
An hour-by-hour walkthrough.
Step by step.
- 01
Collect vendor info + docs
Requester fills a form or DMs Fin: vendor name, use case, spend, contract terms. Fin auto-requests the standard doc pack: W-9, banking, insurance certificate, security questionnaire, data-processing addendum.
Slack · Portal · Email - 02
Run risk + security check
Legal (via Lex) reviews contract terms. Security (via Sig) scores the questionnaire and checks against your risk framework (data types, retention, sub-processors). Both scores + flags feed the joint decision card.
Ironclad · Vanta · Drata - 03
Create vendor record
On approval, create the vendor record in your ERP with tax-ID, banking details, payment terms, cost-centre. Vendor immediately available for PO creation.
NetSuite · QuickBooks · SAP · Coupa - 04
Notify AP
Accounts payable notified of the new vendor with payment terms and PO expectations. First invoice can be processed on receipt.
Bill · Coupa · NetSuite
What you connect to make this run.
Ironclad · DocuSign
read+writeContract lifecycle managed in Ironclad; DocuSign for signature. Redline tracking + counterparty response events fed into the vendor timeline.
Vanta · Drata
readSecurity posture scored against your risk framework. High-risk flags require legal + security joint approval.
NetSuite · QuickBooks · Xero · SAP S/4HANA
writeVendor-master write with tax ID, banking, payment terms. Zero-manual-entry once approval clears.
Bill · Coupa · SAP Concur · Zip
writeAP integration for payment scheduling. Vendor record synced from ERP.
Before and after, honestly.
Playbooks that pair with this one.
Vendor Legal Review Intake
The legal-owned view of the same review flow.
Vendor Security Review
The security-owned view — questionnaire scoring + risk framework.
Bill Payment Approval
Downstream — once the vendor is onboarded, invoices route through payment approval.
Vendor Risk + Payment Hold
The watchdog that freezes payments if a vendor's risk posture changes.
Answers about this playbook.
What if the vendor is small — do they still need a full security review?
Risk-tiered. Vendors under $10k spend with no PII / financial-data access get a lighter review (basic security questionnaire, no DPA). Vendors above thresholds trigger the full review. Configurable per your risk framework.
How does dedup work across business units?
Fin checks the vendor master by tax ID + business name + domain before creating a new record. Match found → offers to link to the existing vendor with a new cost-centre association. Prevents the classic "three copies of Salesforce as a vendor" pattern.
What if legal and security disagree on approval?
Joint decision card routes to CFO + GC (or your policy-defined escalation). Both approvals required for high-risk vendors. Full context of both reviews attached to the decision.
Can we standardise contract terms?
Yes — your approved MSA template lives in Ironclad; Lex drafts starting from it. Counterparty-requested deviations tracked as redlines; standard responses drafted for common asks (indemnity caps, jurisdiction, notice periods).
How does this handle renewals?
The Contract-Renewal-Watcher playbook fires on approaching end dates. Same review flow re-runs with lighter defaults (existing risk posture, no new questionnaire unless changed).
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.