Each toolkit is versioned, documented and revised by a working group. Members may adapt them internally; the reasoning behind every choice is written down so an adaptation can be defended to an auditor or a regulator.
Twenty-seven contract management and third party risk indicators, each with a definition, a formula, a data source, an owner and a tolerance band. The four classifications separate what the board reads from what explains it, and what prevents a failure from what detects one.
Criticality tiering, an inherent risk score across eight domains, control evidence, and a residual rating that sets the depth of due diligence. Deliberately simple: one screen, no login, nothing to install. The spreadsheet edition holds the same model for portfolio use.
Clause checklists, exit and step-in planning, obligation registers and a review calendar, mapped to the register fields the assessment tool expects. Written to be adapted, not adopted whole.
Notify me on releaseOne matrix from register field and KPI to the obligation it evidences, so a European programme can show coverage without maintaining three parallel control sets.
Follow the working group