The lifecycle of a dependency
Six steps
1. Qualifying the need. Is the target function critical or important? That qualification, made before any sourcing, determines everything else: due diligence depth, required clauses, approval level.
2. Concentration assessment. Before contracting, not after. It may lead to walking away.
3. Due diligence. Proportionate to criticality. Fifteen evidence-seeking questions for a critical provider; a standard questionnaire for the rest.
4. Contracting. The clause set applies according to criticality. The exit strategy is documented before signature.
5. Ongoing monitoring. Periodic review of service levels, certifications, financial position and sub-outsourcing changes.
6. Exit. Planned, tested, costed.
The neglected step
Ongoing monitoring is the one organisations drop first. The reasons are always the same: it has no deadline, no visible deliverable, and it concerns contracts signed three years ago by people who have left.
Yet that is where the signals that matter are detected: service level degradation, ownership change, a certification not renewed, a subcontractor added without notice.
What triggers a reassessment
- Contract renewal or amendment;
- Change in the criticality of the supported function;
- Major incident involving the provider;
- Change of control, insolvency proceedings, or financial deterioration;
- Addition or change of a subcontractor in the chain;
- Regulatory change altering the mandatory clauses.
Each of these events must be linked to an owner. With no named owner per critical provider, none of these triggers will be seen.
Key takeaways
- Six steps, three of which happen before signature
- Ongoing monitoring is the most neglected step
- Exit is prepared at entry