← AI Transformation Suite Vendor Governance

Vendor & SaaS Management Plan

Download Word

This plan defines how Project Catalyst selects, governs, monitors, and — when necessary — replaces external vendors. The program relies on three categories of vendors: hyperscaler cloud providers, LLM/AI model providers, and SaaS tooling vendors. Each category carries different risk profiles and requires different governance intensity. Owned by L. Park (Vendor Manager, Pulaski) with oversight from D. Chen (EARB) for technical vendors and R. Thorne (General Counsel) for contract governance.

Table of Contents

  1. Vendor Landscape & Categories
  2. Vendor Selection Criteria
  3. Contract & BAA Requirements
  4. Procurement Authority & Thresholds
  5. Vendor Performance Management
  6. SLA Framework & Monitoring
  7. Vendor Risk Management
  8. Vendor Contingency Planning
  9. Vendor Relationship Governance
  10. Document Control

1. Vendor Landscape & Categories

CategoryExamplesBudget AllocationRisk LevelGovernance Intensity
Hyperscaler Cloud Provider(s)AWS, GCP, Azure$26.9M (cloud & AI platform infrastructure)High — platform dependency, cost volatility, data residencyMonthly performance reviews; quarterly cost optimization; annual contract review
LLM / AI Model Provider(s)OpenAI, Anthropic, or comparableIncluded in cloud allocation (inference costs) + potential licensingHigh — model quality dependency, pricing volatility, API stability, BAA requirement for PHI-adjacent workloadsMonthly performance reviews; quarterly model evaluation; vendor contingency plan maintained
SaaS Tooling VendorsGovernance platforms, compliance monitoring, test automation, MLOps tooling, observability$1.9M (tooling budget)Medium — operational dependency but individually replaceableQuarterly reviews; annual license renewal assessment

1.1 Multi-Cloud Strategy Context

Per Change Control CN-003, Project Catalyst adopted a multi-cloud architecture to reduce single-vendor concentration risk and enable competitive pricing. The practical implementation: a primary hyperscaler is selected for default workloads (compute, storage, managed services); secondary providers are qualified for specific workloads where they offer cost or capability advantages (e.g., GPU pricing for model training, specialized AI/ML services). Workloads can be migrated between providers within 4 weeks if needed (vendor contingency plan, Section 8).

2. Vendor Selection Criteria

All vendor selections are evaluated against a weighted scoring framework. Criteria and weights are set during Phase 0 and approved by the EARB before any vendor evaluation begins.

CriterionWeightWhat We Evaluate
Healthcare Compliance Readiness25%HIPAA compliance posture, BAA willingness and terms, SOC 2 Type II certification, HITRUST certification (preferred), data residency controls (US-only for PHI)
Technical Fit25%Service capabilities matching program requirements, API maturity and stability, integration with existing ACME systems, scalability to production volumes
Cost & Commercial Terms20%Total cost of ownership (not just list price), pricing model transparency, volume discount availability, contract flexibility (term, exit clauses)
Operational Reliability15%Historical uptime (target: 99.9%+ for critical services), incident response SLAs, support tier availability (24/7 for critical), documented disaster recovery
AI/ML Capability Depth10%Managed AI/ML services, GPU availability and pricing, model hosting capabilities, MLOps integration, vector database services (for RAG)
Strategic Viability5%Financial stability, market position, investment trajectory, risk of acquisition or discontinuation during 36.5-month program

3. Contract & BAA Requirements

3.1 Business Associate Agreements (BAA)

Non-Negotiable: Every vendor that processes, stores, transmits, or has access to Protected Health Information (PHI) must execute a Business Associate Agreement with ACME before any PHI flows through their systems. No exceptions. No "we'll get to it later." BAA status is tracked by S. Patel (Vendor Contract Specialist, Legal) and verified by E. Sato (CPO) before any vendor environment is provisioned for PHI workloads.

3.2 Standard Contract Provisions

4. Procurement Authority & Thresholds

Contract ValueApproval AuthorityRequired Reviews
< $50,000Program Director (C. Tyrrell)Vendor Manager review
$50,000 – $500,000Program Director + CFO (S. Williams)Vendor Manager + Legal review
$500,000 – $2,000,000Executive Steering BoardVendor Manager + Legal + EARB review
> $2,000,000Executive Sponsor + CFO + LegalFull vendor evaluation scorecard; EARB technical approval; Audit Committee notification

5. Vendor Performance Management

5.1 Performance Review Cadence

Vendor CategoryReview FrequencyReview OwnerEscalation Path
Hyperscaler Cloud ProviderMonthlyL. Park + W. KumarProgram Director → EARB → ESB
LLM / AI Model ProviderMonthlyL. Park + S. KhuranaProgram Director → AI Gov Board → ESB
SaaS Tooling VendorsQuarterlyL. ParkProgram Director → EARB

5.2 Performance Scorecard

Each vendor is scored monthly (hyperscaler/LLM) or quarterly (SaaS) across five dimensions:

DimensionWeightGreenYellowRed
Uptime / Availability30%≥ 99.9%99.5% – 99.8%< 99.5%
Support Responsiveness20%Within SLA for all tickets1–2 SLA breaches/month3+ SLA breaches/month
Cost vs. Forecast20%Within ±5% of forecast±5–15% of forecast> ±15% of forecast
Technical Quality20%No quality incidents1 minor quality incidentMajor quality incident or regression
Contract Compliance10%Full complianceMinor non-compliance (remediated)Material non-compliance

A vendor scoring Red on any dimension for 2 consecutive review periods triggers an escalation meeting with the vendor's account executive and ACME's Program Director. A vendor scoring Red for 3 consecutive periods triggers a vendor replacement assessment.

6. SLA Framework & Monitoring

6.1 Minimum SLA Requirements (All Vendors)

SLA MetricTargetMeasurement
Service Availability≥ 99.9% (monthly)Vendor-reported + ACME-monitored
Incident Response (Critical)≤ 15 minutes acknowledgment; ≤ 4 hours resolutionTicket system timestamps
Incident Response (High)≤ 1 hour acknowledgment; ≤ 8 hours resolutionTicket system timestamps
Data Backup / RecoveryRPO ≤ 1 hour; RTO ≤ 4 hoursQuarterly DR test results
Security Patch ApplicationCritical patches within 24 hours; High within 72 hoursPatch management reports

6.2 SLA Monitoring

7. Vendor Risk Management

7.1 Vendor Risk Categories

7.2 LLM Provider-Specific Risks

The LLM vendor relationship carries unique risks: API terms may change (rate limits, content policies, pricing), model quality may degrade between versions, and the vendor may deprecate models the program depends on. These risks are distinct from traditional SaaS vendor risks because the program cannot easily replicate the vendor's model — switching LLM providers requires re-tuning, re-validation, and potentially re-architecture. The vendor contingency plan (Section 8) addresses this with a documented alternative provider and estimated switching timeline.

8. Vendor Contingency Planning

8.1 Contingency Plan Requirements

Every vendor classified as "High" risk (hyperscaler cloud, LLM provider) must have a documented contingency plan maintained by L. Park and reviewed quarterly. The plan includes:

8.2 Current Contingency Plans

Vendor CategoryPrimaryContingencyEstimated Switch TimelineEstimated Switch Cost
Hyperscaler CloudPrimary vendor (selected Phase 0)Secondary qualified vendor (multi-cloud)2–4 weeks per workload$200K–$500K engineering effort
LLM / AI ModelPrimary LLM providerAlternative LLM provider (pre-evaluated)4–8 weeks (includes re-tuning + re-validation)$300K–$800K (engineering + validation)
SaaS ToolingPer-tool vendorAlternative tool identified per category2–6 weeks$50K–$150K per tool

9. Vendor Relationship Governance

9.1 Vendor Manager Role

L. Park (Vendor Manager, Pulaski) is the single point of contact for all vendor relationships. Responsibilities:

9.2 Vendor Governance Meetings

MeetingFrequencyAttendeesPurpose
Vendor Operational SyncWeekly (per hyperscaler/LLM vendor)L. Park + vendor TAMTactical: open tickets, upcoming changes, capacity planning
Vendor Performance ReviewMonthlyL. Park + W. Kumar + vendor account execStrategic: scorecard review, SLA compliance, cost forecast, roadmap alignment
Vendor Quarterly Business ReviewQuarterlyL. Park + C. Tyrrell + D. Chen + vendor leadershipExecutive: relationship health, contract performance, strategic alignment, upcoming needs
Annual Contract ReviewAnnuallyL. Park + R. Thorne (Legal) + S. Williams (CFO)Contract renewal assessment: pricing, terms, alternatives, continue/renegotiate/replace decision

9.3 Vendor Information Security Requirements

10. Document Control

FieldValue
Document TitleVendor & SaaS Management Plan
Version1.0
Date17 August 2026
OwnerL. Park (Vendor Manager, Pulaski Advisory Group)
Approved ByC. Tyrrell (Program Director), D. Chen (EARB Chair), R. Thorne (General Counsel)