Brief: vendor-selection
Research brief for vendor-selection · how it was made.
Research brief — vendor-selection
| Field | Value |
|---|---|
| Slug | vendor-selection |
Primary query / seo_intent | Where Vendor Risk Actually Concentrates in Selection |
| Template (A–E) | C |
| Evidence tier (1–3) | 1–2 (NIST C-SCRM + Verizon DBIR + Kraljic + practitioner register) |
| Audience (one line) | Buyers and ops leads drowning in RFPs and demos - blunt procurement voice, not SaaS sales MBA |
| Public byline | 8020.in Editorial |
| Reviewer | Practitioner / procurement-minded pass |
| Date | 2026-07-20 |
1. Concentration claim (one sentence)
In vendor selection, most expensive failure concentrates in a few bottlenecks - misclassifying strategic vs routine buys, scoring theater instead of must-work scenarios, skipping exit and single-source risk, and treating third-party security as paperwork - not in equal fuss over every feature on every proposal.
2. Hard anchors (2–5)
- Kraljic matrix (Peter Kraljic, HBR 1983; overview) — Segment purchases by profit/value impact × supply risk into strategic / bottleneck / leverage / non-critical; unequal procurement posture by quadrant. https://en.wikipedia.org/wiki/Kraljic_matrix
- NIST SP 800-161 Rev. 1 — C-SCRM: identify/assess/mitigate cybersecurity risks throughout the supply chain; criticality-based supplier inventory and risk assessment integrated with enterprise risk. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1.pdf · https://csrc.nist.gov/Projects/cyber-supply-chain-risk-management
- Verizon DBIR 2025 — Third-party involvement in breaches doubled from ~15% (2024 metric) to 30% of analyzed breaches. https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf
- Vendor pain register — org measurement (never invent universal “20% of vendors = 80% of risk”).
2b. Field 80/20 examples
| Approx % claim | Field / context | Source | Where |
|---|---|---|---|
| Unequal posture by strategic/bottleneck vs non-critical | Procurement segmentation | Kraljic | Classification section |
| Criticality-ranked supplier inventory | ICT/OT supply chain | NIST 800-161r1 | Security section |
| Third-party involvement in 30% of breaches (2025 DBIR) | Breach dataset | Verizon DBIR 2025 | Security section |
| Illustrative: top 3 pain tags → next RFP rigor | Team register | Illustrative | Checklist |
Never invent “20% of vendors cause 80% of outages” as a measured universal for the reader’s org.
3. Original observation (only-on-8020 seed)
Vendor pain register: last 6–12 months of vendor-caused pain (missed SLA, lock-in surprise, security scare, failed implementation, switching cost blowup) → one tag: class | criteria | proof | exit | security | contract → next high-impact buy gets rigor only on dominant tags.
4. Ignored majority (named)
Equal RFP depth for every SKU; 40-row feature scorecards; polished demos without a real workflow pilot; ignoring exit/export until year three; security questionnaires filed and forgotten; inventing exact 80/20 vendor slogans.
5. Composite policy
| Scenario | Keep as Illustrative? |
|---|---|
| Pain register sample | Yes |
6. Vital few (bottleneck sections)
- Classify impact / supply risk before the beauty contest
- Vital criteria (not feature democracy)
- Proof: real scenarios / pilot over demo theater
- Exit, switching cost, and single-source risk
- Third-party security / C-SCRM for critical vendors
- Contract terms that concentrate failure (SLA, data, liability) - can fold lightly into exit or short section
7. Device budget
Warning sign / Action today each section · ≤1 8020 move · viz: none · misreads not FAQ
8. SEO / links
- Internal:
/cybersecurity,/inventory-management,/decision-making,/quality-control,/risk-management - Outbound: Kraljic wiki, NIST 800-161r1, NIST C-SCRM project, Verizon DBIR 2025 exec summary
9. Common-sense gate
- Opens in buying/ops language, not “apply Pareto to vendors”
- Template C labels only as lead-ins
-; link attrs- Not a vendor endorsement or RFP template product