How to run a vendor risk assessment as Asset Management Founders
You're managing relationships with 8–15 service providers — fund administrator, prime broker, compliance consultant, auditor, legal counsel, data vendors — and your vendor contracts live in a Google Drive folder nobody has organized since inception. Renewal dates slip. You find out your data vendor auto-renewed at a 20% price increase three weeks after it happened. You can't quickly pull the liability cap in your fund admin agreement when you're on a call with an LP asking about operational risk. You're spending real hours digging through email threads to reconstruct what you agreed to with whom, and that time comes directly out of portfolio work.
What you'll set up
Apps, data, and prompts
The combination of Starch apps, the data sources they pull from, and the prompts you use to drive them.
Starch syncs your Gmail data on a schedule so the Email Agent can surface vendor-related threads and renewal notices without manual searching. Your Notion pages (if you use Notion for internal docs) sync on a schedule as well, so existing vendor notes pull into the knowledge base automatically. Connect your Google Drive from Starch's integration catalog; the agent queries it live to pull existing contract files when you're building the registry. For vendors with portals but no API — like your compliance filing system or a niche data vendor's client portal — Starch automates those sites through your browser, no API needed.
Step-by-step
See this running on Starch
Connect your tools, describe what you want, and the agent builds it. Closed beta is free.
Q1 2026 Vendor Risk Review — $85M Emerging Fund
| Fund Administrator (NAV calculation, LP reporting) | 42,000 |
| Legal Counsel (fund agreements, ongoing) | 38,000 |
| Auditor (annual audit) | 28,000 |
| Bloomberg Terminal (2 seats) | 27,000 |
| Compliance Consultant (CCO services) | 24,000 |
| Prime Broker (custody + margin) | 0 |
| Cybersecurity / IT MSP | 14,400 |
| Data Vendor — Alt Data (ESG scores) | 9,600 |
You're a $85M emerging fund three years into operation. You have eight active vendor relationships totaling roughly $183,000 in annual cash spend, plus your prime broker relationship which has zero direct fee but carries the highest operational dependency in your stack. Going into Q1 2026, you ask Starch to scan your Gmail for the past 18 months and surface any pricing or renewal communications. It finds that your Bloomberg contract auto-renewed in January at a 12% increase you didn't formally acknowledge, and that your alt data vendor sent a 60-day termination notice requirement buried in a thread from November 2024 — your renewal window is April 30, 2026, 47 days away. Your compliance consultant's agreement has no SOC 2 on file despite having read access to your compliance management portal. The Task Manager immediately creates three tasks: (1) confirm Bloomberg renewal decision by March 15, (2) alt data vendor renewal decision by April 1 to honor notice period, (3) request SOC 2 or written security attestation from compliance consultant by end of week. You build the vendor risk dashboard — all eight vendors scored, two flagged red (compliance consultant: high data access, no SOC 2; alt data vendor: renewal deadline approaching). When your anchor LP sends their annual DDQ asking about vendor oversight, you export the registry summary and your documented assessment policy in 10 minutes. No scrambling.
How you'll know it's working
What this replaces
The other ways teams handle this today, and how the Starch version compares.
One platform — contract lifecycle management, task manager, email agent all running on connected data. Setup in plain English; numbers stay current via scheduled syncs and live agent queries.
Try it on Starch →Frequently asked questions
Can Starch actually extract renewal dates and notice periods from my existing PDF contracts?
Is the Contract Lifecycle Management app available today?
My fund admin and prime broker don't have APIs. Can Starch still interact with their portals?
Is Starch SOC 2 certified? My LP compliance team will ask.
Can I use this for counterparty risk on portfolio companies, not just my own vendors?
How does Starch handle vendor outreach for compliance document collection?
Related guides for Asset Management Founders
Investor Q&A and info requests are the administrative tax on raising capital and maintaining LP relationships.
Read guide →A 13-week cash flow forecast is a rolling, week-by-week view of what hits your account and what leaves it — covering roughly one quarter ahead.
Read guide →A strategic account plan is a documented, living view of a specific customer or prospect — their business goals, the stakeholders who matter, the gaps your product fills, the risks to the relationship, and the actions your team is taking.
Read guide →A monthly board financial pack is the document your board, lead investors, or advisors use to understand whether the business is on track.
Read guide →Run a Vendor Risk Assessment for other operators
The AI stack built for small in-house legal and compliance teams.
Read guide →The AI stack built for small IT and ITOps teams.
Read guide →The AI stack built for small finance teams.
Read guide →The AI stack built for the founder's office.
Read guide →Ready to run run a vendor risk assessment on Starch?
Request closed-beta access. Everything is free during beta.