The risk that scorecards miss
A weighted scorecard compares vendors against your requirements. It says little about execution dependency after the contract is signed, when your leverage collapses and the vendor's begins. The risk is not only choosing the wrong vendor. It is discovering, in month seven, that you chose a workable vendor on unworkable terms.
The matrix
| Risk area |
What to examine before signing |
Early warning sign |
Mitigation to demand in contract |
| Delivery capability |
Delivery record on projects of your size and sector, not the vendor's flagship references |
References are all larger or smaller than you, or hand-picked by the sales team |
Milestone-based payments tied to acceptance criteria you define |
| Key-person dependency |
Which named individuals the proposal quality actually rests on |
The people who impressed you in the pitch are "subject to availability" |
Named-resource clause with approval rights over substitutions |
| Commercial model |
Where the vendor makes its real margin: licences, change requests, or support |
Suspiciously low implementation fee against a high run-rate |
Rate card and change-request pricing fixed for the contract term |
| Lock-in and exit |
What it costs, in money and months, to leave at year three |
Data export is possible "via professional services engagement" |
Documented exit assistance, data formats and transition period in the contract |
| Financial stability |
Whether the vendor survives the length of your dependency on it |
Funding rounds standing in for revenue |
Source-code escrow or step-in rights for critical systems |
| Integration effort |
Who owns the joins between this system and everything it must talk to |
Integration listed as "out of scope" or "customer responsibility" in small print |
Integration acceptance tests defined before signature, not after |
| Support model |
What the escalation path looks like at 2am during your peak trading period |
Support SLAs measured on response time, never on resolution |
Resolution-time commitments with service credits that actually sting |
| Roadmap dependence |
Which of your requirements are met by the product today versus the roadmap |
The demo showed features that turn out to be "generally available next year" |
Contractual remedies if committed roadmap items slip beyond a named date |
Using the matrix inside your selection process
Fill it in after the shortlist is formed but before best-and-final offers, because that is the last point at which findings convert into contract terms. Procurement holds the document, but each row needs its natural owner: IT scores integration, finance scores stability, legal scores exit. One person completing all nine rows produces nine guesses.
Four ways teams neutralise their own matrix
- Rows are filled in from the vendor's RFP responses instead of from independent verification, so the matrix repeats the sales narrative in a different layout.
- Every risk is marked medium because nobody wants to defend an extreme score in front of the sponsor.
- The matrix is completed for the preferred vendor only, removing its power as a comparison instrument.
- Findings are recorded but never carried into the negotiation, so the document becomes an archive of known problems the contract does nothing about.
When the completed matrix warrants independent eyes
If the matrix shows concentrated risk in lock-in, key people or roadmap dependence (the categories internal teams are least equipped to price), that is the point to seek challenge from operators who have run this vendor, or this category, on the buying side. A selection team that agrees on every rating has usually stopped testing its own assumptions, and vendor selection is where untested assumptions carry multi-year consequences.