HomeTemplatesVendor Onboarding SOP Template
Operations & ITSOPFree template

Vendor onboarding SOP template — from request to active supplier in days

Vendor onboarding failures — work starting before contracts are signed, systems provisioned before security review, invoices sent to the wrong entity — all trace back to the same root cause: no consistent process. This interactive SOP guides procurement teams through every step from vendor request to active supplier, with the right approvals at the right time.

No credit card required · Free plan available · Setup in minutes

Who is this for?

Procurement managers, operations leads, and finance teams at companies with 50–2,000 employees that onboard 5–50 new vendors per year. Also valuable for fast-growing startups establishing their first formal procurement process before vendor relationships become ungovernable.

The problem it solves

Most vendor onboarding is reactive: someone needs a tool, they buy it, and procurement catches up afterward. This creates security exposure (unvetted third-party access), compliance gaps (no signed DPA for data-processing vendors), and finance chaos (no PO before the first invoice). An SOP that every stakeholder follows in real time prevents these gaps from forming.

How the template is structured

Every step is editable. Customise the content, labels, and branching logic to match your exact process.

1

Vendor request and business justification

Requestor submits vendor name, proposed spend, business justification, and preferred start date. The SOP routes the request to the budget owner for initial approval before any further steps begin.

2

Vendor categorisation and risk tier

Procurement categorises the vendor by spend level and data access type. Low-risk (no data access, under $5k/year) follows a fast-track path. Medium and high-risk vendors require legal review, security assessment, and a signed DPA before proceeding.

3

Vendor due diligence and vetting

Procurement collects vendor registration documents, insurance certificates, and references. For high-risk vendors, a security questionnaire is sent and reviewed. Results are logged against the vendor record.

4

Contract review and execution

Legal receives the proposed contract with all supporting documents. The SOP tracks: redlines sent, vendor response received, final version signed by both parties. No system access or payment setup begins until this step is complete.

5

Compliance and security provisioning

IT provisions the required access based on the vendor's approved scope. Data processors are added to the vendor register with DPA reference. GDPR, SOC 2, or ISO 27001 compliance requirements are checked and documented.

6

Payment setup and system activation

Finance collects banking details, sets up the vendor in the ERP or payment system, and creates the initial PO. The SOP confirms all steps are complete before marking the vendor as active.

What you get with this template

No more work starting before contracts are signed
Security and compliance checks enforced before system access is granted
Consistent vetting regardless of who in procurement handles the request
Full audit trail for every vendor: who approved what and when
Risk-tiered paths — low-risk vendors onboard fast, high-risk get full review
Webhook integration updates your ERP and vendor register automatically
Analytics show average onboarding time by vendor tier and bottleneck steps
Update compliance requirements once — all future onboardings reflect the change

New vendor onboarded, contracts signed, systems live — without the chase

Free to use. Customise every node, label, and branch in PathPilot's visual canvas. Publish with one click.

Get started free

Frequently asked questions

Can this SOP handle GDPR and data processing requirements?
Yes. Add a branch on the vendor categorisation step: if the vendor processes personal data, route to a compliance sub-flow that includes DPA review, GDPR lawful basis confirmation, and sub-processor registration. PathPilot's branching handles this without a separate document.
Can we set different approval thresholds based on spend level?
Fully customisable. Edit the risk tier classification node to define your own spend thresholds and approval requirements. Under $5k might go to the budget owner; over $50k might require CFO sign-off. Branch logic handles each path.
How do we track which vendors are at which stage?
PathPilot's analytics show completion rates and current step distribution across all active sessions. For a dedicated vendor tracker, use webhook integration to push stage updates to your procurement system (Coupa, SAP Ariba, or a Google Sheet).
Can vendors complete parts of this themselves?
Create a separate public-facing flow for vendor self-registration: company details, banking information, insurance upload, and questionnaire completion. PathPilot's form nodes support file uploads. Link this flow from the due diligence step of the internal SOP.