← University
Vendor and Third-Party Risk Management
0 of 4

A regional healthcare network operating 4 outpatient clinics across southern Ontario discovered during a routine audit that patient billing records processed by its external billing services provider contained errors affecting approximately 1,200 accounts over a 7-month period. The billing provider, engaged 3 years earlier to handle all patient invoicing, insurance claims processing, and collections, had undergone a change in ownership 14 months into the relationship. The new ownership had subsequently migrated the billing platform to a different cloud infrastructure provider and reduced staffing levels by roughly 30 percent, changes the healthcare network learned about only after the audit findings emerged.

The healthcare network had originally selected the billing provider following a competitive procurement process that evaluated 5 candidate firms. The selection committee, comprising the network's chief financial officer, its operations director, and an external consultant, had assessed each candidate's financial statements, client references, data security certifications, and proposed service delivery model. The successful vendor had demonstrated ISO 27001 certification, carried professional liability coverage of $5 million per occurrence, and provided audited financial statements showing 4 consecutive years of profitability. At the time of engagement, the vendor appeared to represent a low-risk, cost-effective solution for a function the healthcare network had struggled to perform efficiently in-house.

The master services agreement executed between the parties ran to 47 pages and included standard provisions addressing confidentiality, indemnification, and termination. The agreement required the vendor to maintain "commercially reasonable" data security practices and to provide 60 days' notice before any material change in service delivery. It did not define what constituted a material change, did not require notification of ownership transitions, and did not establish specific performance metrics against which the vendor's work could be measured. The healthcare network had not requested a right-to-audit clause during negotiations and had not conducted any formal review of the vendor's operations since the initial engagement.

The billing errors had resulted in delayed insurance reimbursements, patient complaints regarding incorrect balances, and at least 3 formal inquiries from the provincial health insurance plan regarding claims discrepancies. The healthcare network now faces questions about how to assess the full scope of the problem, what remedies exist under the current contract, whether to continue the vendor relationship or transition to an alternative provider, and what changes to its vendor management practices might prevent similar situations in future engagements.

Ongoing Monitoring and What to Do When a Vendor Fails

Every organization that relies on vendors eventually confronts an uncomfortable truth: contracts do not guarantee performance, and due diligence at the point of selection does not prevent deterioration over time. The vendor who demonstrated financial stability and operational excellence during the procurement process may look quite different eighteen months later after a change in ownership, a pivot in strategic direction, or the quiet departure of key personnel. This reality makes ongoing monitoring not merely a best practice but an essential component of any mature vendor management program. Canadian organizations across every sector, from resource extraction companies managing specialized equipment suppliers in northern Alberta to healthcare networks in Ontario coordinating with dozens of clinical service providers, must develop systematic approaches to watching their vendor relationships and preparing for the possibility that even trusted partners may fail to meet their obligations.

The foundation of ongoing vendor monitoring rests on the recognition that risk is dynamic rather than static. When an organization first engages a vendor, the initial assessment captures a snapshot of that vendor's capabilities, financial health, regulatory compliance, and operational capacity. That snapshot ages quickly. Market conditions shift, leadership changes, supply chains fracture, and regulatory requirements evolve. A printing company that handled sensitive donor communications for a Halifax-based charity may have had impeccable data security practices in 2024, but those practices may have degraded by 2026 due to staff turnover or cost-cutting measures that the charity would never detect without deliberate monitoring. The principle underlying ongoing monitoring is straightforward: organizations must continuously verify that the conditions that made a vendor acceptable at contract signing continue to hold throughout the relationship.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.