← M&A Integration Suite Plan · Artifact 21A · how to read this suite

Vendor Management Plan

Download Word

How the program engages and runs the vendors it hires, issued August 28, 2023. This is distinct from two adjacent documents and the boundary matters: the Vendor & Contract Disposition Matrix deals with contracts the program inherited and must keep, novate or exit; the Consulting SOW is one engagement's own paper. This plan governs everything the program buys — what each statement of work must contain, how performance is measured, and how a vendor is exited.

A statement of work that ends at "delivered and working" transfers every future problem to the buyer at the moment of acceptance. This is the single most expensive omission in technology procurement, and it is invisible on the day it is made because on that day the thing works. What matters is what the contract says about the eighteen months after that — who fixes a defect found in month four, who applies the security patch, who pays when the vendor releases a version that breaks an interface, and who is contractually obliged to be available at two in the morning. §4 makes those terms mandatory rather than negotiable, precisely because they are the terms a vendor is most willing to drop to win on price.

Table of Contents

Part I — Structure
  1. Scope and Boundaries
  2. Vendor Register and Engagement Model
  3. Onboarding Gate
Part II — The Paper
  1. Mandatory Statement of Work Content
  2. Warranty, Support and Version Obligations
  3. Individual Statements of Work
Part III — Running Them
  1. Performance Management
  2. Escalation and Remedy
  3. Transition Out
Part I — Structure

1. Scope and Boundaries

DocumentCoversBoundary
This planVendors the program engagesOnboarding, SOW content, performance, escalation, exit
21 — Disposition MatrixContracts the program inherited⚠ Keep, novate, consolidate or terminate. Change-of-control mechanics.
8 — Consulting SOWThe Arrington engagement itselfOne instrument, plus the three-tier contracting model
22 — TSA Exit PlanCheatham Mutual Holdings⚠ The divesting parent is governed by the TSA, not by a program SOW

2. Vendor Register and Engagement Model

RefVendorVehicleACME ownerWhat they are engaged to deliver
VN-01Arrington Advisory GroupDeliverable SOWD. AshmoreProgram management, identity resolution, integration and cloud architecture
VN-02Rutherford Cloud OperationsFixed price + T&MB. TrammellCo-managed cloud operations against a contracted step-down. ⚠ Software and platform terms apply — see §5.
VN-03Gallatin EDI AssuranceFixed priceW. FerridayX12 transaction assurance across five transaction sets
VN-04Two Rivers Talent PartnersStaff augT. VandiverData stewards for clerical review. ⚠ ACME directs the work and owns the outcome.
VN-05Harpeth Clean Team ServicesFixed priceL. HollingsworthPre-close information barrier. Terminates at closing.
VN-06Madison Data Systems — EMPI platformLicense + supportDr. A. Ravindran⚠ Software purchase. Warranty, support and version terms are mandatory — see §5.
VN-07Azure — cloud platformConsumptionB. TrammellInfrastructure and managed database services. Business associate agreement in place.
VN-08Murfreesboro Secure Logistics — transfer appliancesFixed priceD. FontenotFive appliances, archive transfer. Chain of custody and destruction certificate.

3. Onboarding Gate

No vendor performs work before every condition is met. Each is evidenced, not asserted.

RefConditionEvidence
ON-01Business associate agreement executed⚠ Required before any access to member data, not before go-live. Signed instrument on the BAA register.
ON-02Security review completedAssessment on file; findings closed or accepted by the CISO with a named accepter
ON-03Insurance certificates currentProfessional liability, cyber, workers compensation at contracted limits
ON-04Data location commitment⚠ No member data outside the United States. Contractual, not policy.
ON-05Named personnel and background checksIndividuals identified; substitution requires ACME agreement for key roles
ON-06Access provisioned to least privilegeJust-in-time elevation where privileged access is needed; standing admin access is not granted
ON-07SOW executed with §4 content complete⚠ An incomplete SOW is not a fast start; it is an unpriced obligation
Part II — The Paper

4. Mandatory Statement of Work Content

Every program SOW carries these clauses. Anything absent is escalated to Procurement before signature rather than negotiated during delivery.

ClauseApplies toRequirement
Deliverables and acceptance criteriaAllWhat "done" means, tested how, accepted by whom. ⚠ Acceptance criteria written before work starts, not at invoice time.
Named key personnelAllIndividuals named; substitution of key roles requires ACME agreement
Rate card and vehicleAllDeliverable, fixed price or time and materials, stated explicitly. ⚠ Not left to be inferred from how invoices arrive.
Data handling and locationAllBusiness associate terms, encryption, retention, onshore constraint
Security obligationsAllIncident notification window, right to audit, subcontractor flow-down
Warranty periodSoftware, hardware, cloudSee §5
Support model and staffingSoftware, hardware, cloudSee §5
Version and upgrade obligationsSoftware, cloudSee §5
Knowledge transferAllA deliverable with named receivers and acceptance, not a by-product
Termination and transition outAllNotice period, transition assistance obligation, data return format
Intellectual property and license scopeSoftware⚠ Who owns configuration and custom rules built during the program
Change controlAllScope changes priced and approved before work, against the program's thresholds

5. Warranty, Support and Version Obligations

These apply wherever the program acquires software, hardware, or an external cloud service — the EMPI platform, the cloud platform, the managed service, and the transfer appliances.

RefTermWhat the SOW must specify
SW-01Warranty periodDuration from acceptance, and what it covers. ⚠ A warranty running from delivery rather than acceptance can expire before the product is in production use.
SW-02Defect remediation service levelsResponse and resolution times by severity, using the program's severity definitions rather than the vendor's
SW-03Support staffingNamed support contacts, coverage hours, on-call obligation, and escalation path. ⚠ Coverage must extend to cutover weekends and hypercare.
SW-04Version updates and patchesWho applies them, in what window, and who tests. Security patches on a defined clock separate from feature releases.
SW-05Backward compatibility and interface stability⚠ Notice period before a change that breaks an existing interface, and who pays for the remediation
SW-06End-of-life and end-of-support noticeMinimum notice before a version leaves support, and the obligation to provide a migration path
SW-07Escrow or continuityFor any product where a vendor failure would stop operations
SW-08Environment coverageWhether support covers non-production. ⚠ A test environment nobody will fix stops testing.
SW-04 and SW-05 together decide whether the program owns a system or a liability, and they are almost never argued about at signature. The failure is specific and recurring: the vendor releases a version, the release is mandatory because the previous one leaves support, the new version changes a field the integration layer depends on, and the remediation cost lands on the buyer — who is now doing unplanned work under the original schedule. The clause that prevents it is not a warranty. It is a notice period plus a stated allocation of remediation cost, agreed while the vendor still wants the business.
SW-03 is the clause that gets traded away on price, and the one whose absence surfaces at the worst possible hour. Support "during business hours" is a perfectly reasonable term that is worth nothing during a cutover weekend, which is when a platform is most likely to behave unexpectedly and least likely to be recoverable by the buyer alone. The obligation has to name the coverage window against the program's calendar, not the vendor's standard one — and it costs materially less to buy in the SOW than to buy at midnight on the night it is needed.

6. Individual Statements of Work

Each engaged vendor has its own instrument. These are the representative SOWs behind the register in §2 — scope, vehicle, term and the §4 and §5 clauses that apply to each.

RefStatement of workVehicle§5 terms that apply
VN-01Arrington — program management and specialist advisoryDeliverableNot applicable — services only. Knowledge transfer and key personnel apply.
VN-02Rutherford — co-managed cloud operationsFixed price + T&M⚠ SW-02, SW-03, SW-04, SW-08. Step-down milestones are acceptance-gated.
VN-03Gallatin — X12 transaction assuranceFixed priceSW-02 for tooling defects. Test environment coverage under SW-08.
VN-04Two Rivers — data steward staff augmentationStaff augNot applicable. ⚠ Co-employment guardrails and substitution terms apply instead.
VN-05Harpeth — clean team servicesFixed priceNot applicable. Terminates at closing; output scope defined by protocol.
VN-06EMPI platform — license, implementation and supportLicense + supportAll of SW-01 to SW-08. ⚠ Configuration and match-rule IP explicitly ACME's.
VN-07Azure — cloud platform consumptionConsumptionSW-04, SW-05, SW-06 through platform terms. BAA executed.
VN-08Transfer appliance serviceFixed priceSW-01, SW-03. Chain of custody and certified destruction.
VN-06 is the one to read closely, because it is the only instrument on this program where a vendor's product decisions can invalidate work the program has already accepted. The match rules and survivorship configuration are built inside the vendor's platform over months, tuned against this specific member population, and they are the thing identity resolution actually consists of. If the license terms leave that configuration ambiguous, the program has spent its largest work package building an asset it may not own — and a future platform change becomes a negotiation rather than a migration.
Part III — Running Them

7. Performance Management

VendorMeasured onCadence
Rutherford Cloud OperationsStep-down milestones evidenced, incident response, access disciplineCheck-in every 3 weeks; written status weekly
Two Rivers Talent Partners⚠ Steward retention and time-to-productive, not hours billedCheck-in every 3 weeks; written status weekly
Gallatin EDI AssuranceTransaction coverage, defect detection rate, agingMonthly check-in; written status weekly
Madison Data SystemsSupport response against SW-02, patch currencyMonthly
Arrington Advisory GroupDeliverable acceptance on first submissionContinuous; formal review at each gate
The Two Rivers measure is deliberately not hours delivered, and the distinction is the whole point of measuring anything. A staffing vendor paid for hours and measured on hours has every incentive aligned with churn: a replacement steward bills from day one and produces reviewed records some weeks later. Measuring time-to-productive and retention makes the vendor carry the cost of turnover that they are best placed to prevent — and it converts a metric nobody argues about into one that changes behavior.

8. Escalation and Remedy

LevelTriggerOwnerAction
1Missed deliverable or service levelACME vendor ownerRaised at the next check-in with a recovery date
2Repeat miss, or a recovery date missedC. TyrrellWritten notice; remediation plan required within five business days
3Remediation plan failsH. CastellowContractual remedy invoked — service credits, withheld payment, or step-in
4Material breachD. Ashmore + Legal⚠ Termination assessed against transition risk, not against frustration
Level 4 carries a warning because terminating a vendor mid-program is frequently the more damaging option and rarely feels like it at the time. The question is not whether the vendor deserves it. It is whether the program can absorb the transition — re-procurement, onboarding, knowledge loss — inside a schedule with a contractual wall at the end of it. Leverage over a vendor is set by how long you still need them, and on a program with a fixed exit date that leverage runs out well before the anger does.

9. Transition Out

RequirementStandard
Transition assistanceContracted obligation with a defined period, not goodwill
Data and artifact return⚠ In a usable, documented format. "Available on request" is not a format.
Configuration and IPACME retains configuration, rules and documentation built during the engagement
Access revocationSame-day on exit, evidenced. Includes subcontractor accounts.
Knowledge transfer acceptanceReverse-shadowing: ACME performs unaided while the vendor observes
Surviving obligationsConfidentiality, business associate terms and record retention continue past termination
Every vendor on this program is temporary, including the ones nobody expects to leave. The managed service provider steps down by contract; the clean team dissolves at closing; the staffing vendor ends when the queue clears. Writing the exit terms while the relationship is new is straightforward and costs nothing; writing them while it is ending is a negotiation conducted from the weaker position. That is the practical reason transition-out is a mandatory §4 clause rather than something handled when the time comes.

Schedule A — Register of Engaged Suppliers and Signatories

Every supplier the program engages, the instrument that binds them, and the officer authorized to execute on their behalf. Issued with this plan on August 28, 2023 and updated as instruments are executed.

RefSupplier and authorized signatory InstrumentVehicle ACME ownerWarranty terms
VN-01Arrington Advisory Group
G. Hollowell, Managing Principal
ARR-2023-01Deliverable statement of workD. Ashmorenone — services only
VN-02Rutherford Cloud Operations
D. Pennington, President
SOW-02Fixed price for the operating baseline, time and materials for project workB. Trammell4 of 8
VN-03Gallatin EDI Assurance
M. Everly, Managing Director
SOW-03Fixed price, deliverable-basedW. Ferriday2 of 8
VN-04Two Rivers Talent Partners
R. Sowell, President
SOW-04Time and materials, staff augmentationT. Vandivernone — services only
VN-05Harpeth Clean Team Services
E. Sandlin, Managing Partner
SOW-05Fixed price, engaged through ACME LegalL. Hollingsworthnone — services only
VN-06Madison Data Systems
A. Thornbury, Senior Vice President, Contracts
SOW-06Perpetual license + implementation services + annual supportDr. A. Ravindran8 of 8
VN-07Microsoft Azure
T. Hargrove, Vice President, Enterprise Agreements
SOW-07Consumption, ordered under ACME's existing enterprise agreementB. Trammell3 of 8
VN-08Murfreesboro Secure Logistics
C. Wexler, Director of Secure Logistics
SOW-08Fixed price per appliance rotationD. Fontenot2 of 8
The second column carries the name of a person, not only a company, and that is the point of the schedule. A register that lists suppliers answers "who are we buying from". A register that lists the authorized signatory answers "who can bind them" — which is the question that matters when a deliverable is late, a term is disputed, or an instrument has to be amended under time pressure. ⚠ Two entries deliberately carry no program signatory: the Clean Team is engaged by counsel rather than by the program, and the cloud platform sits under an enterprise agreement that predates this transaction. Both are listed rather than omitted, so a reader does not conclude the register is incomplete.
Every execution requires four signatures — the ACME owner named above, the supplier's authorized officer, VP Procurement, and General Counsel. The full block appears at §7 of each statement of work. Procurement confirms the commercial terms match the framework agreement; Legal confirms the §4 and §5 clauses are present rather than assumed.

Related artifacts: 8 — Consulting SOW & Engagement Model · 9 — Integration Management Plan · 12 — Program Budget · 14 — Resource Plan · 17 — Communications Plan · 21 — Vendor & Contract Disposition Matrix · 22 — TSA Schedule & Exit Plan · 24 — Cloud Migration Strategy