Services Inventory and Attributes - Vendor and Supplier attributes for the Services Inventory
Services Inventory and Attributes
Chapter 23. Vendor and Supplier attributes for the Services Inventory
Executive Summary: Chapter Overview
IF4ITThe Bottom Line
Core Concepts
| Concept | Definition & Strategic Role |
|---|---|
| Primary Vendor | For consumed Services, the Vendor providing the Service — the connection to the Vendors Inventory and the foundation of Vendor concentration analysis at the Service level. |
| Subcontracted Vendors | Fourth-party providers the primary Vendor depends on — the visibility required by regulations such as DORA and APRA CPS 230 for critical Service relationships. |
Quick Q&A
Question: Why does fourth-party visibility matter for Service-level governance?
Question: How does Subcontracted Vendors interact with the [Vendors Inventory](https://if4it.org/best-practices/vendors-inventory-and-attributes/)?
Read More Below
Vendor and Supplier attributes capture the Vendor relationships for consumed Services — the primary Vendor and any subcontracted Vendors. These attributes connect the Services Inventory to the Vendors Inventory and support fourth-party risk visibility.
| Attribute Name | Maturity | Description and Notes |
|---|---|---|
| Primary Vendor | Walk | Description — For consumed Services, the primary Vendor providing the Service. References the Vendors Inventory by Semantic ID. Benefit(s) — Connects Services to Vendors in the Enterprise Model. Enables vendor concentration analysis at the Service level. Supports vendor risk management informed by Service-level dependency. Source — Manual. Examples — VND-SALESFORCE, VND-AWS, VND-OKTA Notes — Empty for internally-provided Services. Refer to the IF4IT Vendors Inventory and Attributes document for Vendor governance. |
Subcontracted Vendors [Multi-Value] | Walk | Description — Sub-vendors involved in Service delivery — fourth-party providers that the primary Vendor depends on. References the Vendors Inventory by Semantic ID where governed there. Benefit(s) — Surfaces fourth-party risk. Supports the discipline of fourth-party visibility required by regulations such as DORA, FCA Critical Third Parties, and APRA CPS 230. Source — Manual. Examples — VND-AWS (Salesforce hosts on AWS); VND-FASTLY (Vendor uses Fastly for CDN) Notes — May be empty for Services with no significant sub-vendor dependencies. For regulated Services, sub-vendor identification may be required by contract. |
How to cite this page
When referencing this page in academic work, internal standards, or external publications, include the page title, IF4IT as author and publisher (The International Foundation for Information Technology (IF4IT), LLC), the URL, and your access date.
Example (informal web citation):
The International Foundation for Information Technology (IF4IT), LLC. Vendor and Supplier attributes for the Services Inventory | Services Inventory and Attributes. https://if4it.org/best-practices/services-inventory-and-attributes/vendor-and-supplier-attributes-for-the-services-inventory/ (accessed 2026-07-23).
See About Us for content governance and site-wide citation guidance.
Copyright for The International Foundation for Information Technology (IF4IT), LLC: 2008 - Present
Legal Disclaimers