Assess procurement risk across vendor viability, security, privacy, legal terms, concentration, implementation, continuity, data portability, support, and exit conditions before commitment.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add Dadmin88/hermes-profile-packs --skill procurement-risk --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Procurement Risk?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/dadmin88-procurement-risk)More formats (shields.io, HTML) on the badges page.
---
name: procurement-risk
description: Assess procurement risk across vendor viability, security, privacy, legal terms, concentration, implementation, continuity, data portability, support, and exit conditions before commitment.
---
# Procurement Risk
Use when a vendor, service, tool, or contract could create meaningful operational, financial, security, legal, or dependency exposure.
## Procedure
1. Define the business dependency, scope, spend, users, data, systems, criticality, and decision horizon.
2. Review vendor viability, ownership, support model, service maturity, roadmap dependence, references, and material concentration risk.
3. Review security, privacy, compliance, data location, subprocessors, access, incident response, and contractual obligations with the relevant specialist owners.
4. Review implementation and migration risk: integration complexity, required internal capacity, hidden prerequisites, timeline assumptions, and operational ownership.
5. Review commercial and continuity exposure including pricing mechanics, renewal terms, lock-in, minimums, usage growth, service changes, and termination rights.
6. Define exit and portability: export formats, data retrieval, migration effort, replacement options, transition support, and deletion/retention obligations.
7. Separate mitigable risks from accepted residual risk and assign owners for required controls or contract changes.
8. Record the decision with evidence, assumptions, material unknowns, and review triggers.
## Decision rules
- Procurement risk is not just vendor security review.
- Cheap acquisition can create expensive exit or migration risk.
- Escalate legal, security, privacy, and financial interpretation to the proper specialists.
- Do not convert an unresolved material dependency into a hidden assumption.
## Quality gate
The assessment is ready when consequential vendor, implementation, continuity, contractual, security, and exit risks are visible; mitigations and owners are explicit; residual risk is understood; and the decision can be revisited from recorded evidence rather than memory.Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!