How to run a vendor risk assessment as Chief of Staff and Founder's Office
Vendor risk assessments land on your desk because no one else has the full picture. You're chasing down contracts in a shared Google Drive folder (if you're lucky), pinging legal and finance for renewal dates, cross-referencing Slack threads to figure out which tools the engineering team spun up without telling anyone, and manually building a spreadsheet that's out of date the moment you share it. At a 150-person company, you might have 40–80 active vendors — SaaS subscriptions, contractors, professional services, infrastructure — and zero single source of truth for spend, contract status, data-access scope, or renewal dates. You're the one who gets blamed when a vendor auto-renews at $60k and nobody caught it.
What you'll set up
Apps, data, and prompts
The combination of Starch apps, the data sources they pull from, and the prompts you use to drive them.
Starch syncs your QuickBooks data on a schedule (invoices, bills, vendors, payments) to pull actual spend per vendor. Connect Notion from Starch's integration catalog — the agent queries it live — to pull any existing vendor documentation or contract notes your team has stored there. Starch syncs your Gmail data on a schedule so the agent can surface vendor communication threads and flag unanswered renewal conversations. Starch syncs your Slack data on a schedule to push automated weekly alerts to your ops or chief-of-staff channel. For vendors whose contracts or compliance docs live on portals with no API (carrier portals, government vendor registries, niche SaaS admin pages), Starch automates those through your browser — no API needed.
Step-by-step
See this running on Starch
Connect your tools, describe what you want, and the agent builds it. Closed beta is free.
Q2 2026 Vendor Risk Review — 150-person growth-stage SaaS company
| AWS (infrastructure) | 148,000 |
| Salesforce (CRM) | 54,000 |
| Workday (HR) | 42,000 |
| Legal outside counsel (services) | 38,500 |
| Segment / PostHog (analytics) | 22,000 |
| Figma (design tooling) | 8,400 |
| Notion (docs) | 6,200 |
Before this review, the vendor list lived in a Google Sheet that hadn't been touched since Q4 2024. The CoS had QuickBooks showing $319,100 in the 'Software & Subscriptions' and 'Professional Services' lines but no breakdown by vendor, no renewal dates, and no record of which vendors had access to customer PII. The Starch vendor risk registry pulled QuickBooks bills and payments directly to populate annual spend per vendor. It flagged three immediate issues: (1) Salesforce at $54,000 was renewing in 38 days with no renewal decision made and no negotiation started — the alert hit Slack on a Monday and gave the CoS two weeks to loop in the CFO; (2) a $12,000/year data enrichment vendor had full CRM data access with no SOC 2 on file — Starch's browser automation pulled their trust portal page and found their SOC 2 report was 14 months old; (3) two 'shadow IT' subscriptions totaling $4,200 appeared in QuickBooks from vendors nobody in ops recognized. The final scorecard showed 34 active vendors, $319,100 in annual spend, 68% with SOC 2 on file, 4 flagged high-risk, and 6 renewals due in the next 90 days. The CoS handed the CFO a one-page summary instead of a spreadsheet, and the prep took 3 hours instead of two days.
How you'll know it's working
What this replaces
The other ways teams handle this today, and how the Starch version compares.
One platform — contract lifecycle management, task manager all running on connected data. Setup in plain English; numbers stay current via scheduled syncs and live agent queries.
Try it on Starch →Frequently asked questions
We don't have a formal vendor list anywhere. How do we even start?
QuickBooks report views like P&L aren't working — will that affect this?
Can Starch pull SOC 2 reports or compliance docs directly from vendor portals?
Is my vendor data stored securely? Is Starch SOC 2 certified?
What about Contract Lifecycle Management — the catalog mentions it but I don't see it available?
We use Salesforce, not HubSpot. Can Starch still pull vendor and spend data?
Related guides for Chief of Staff and Founder's Office
Vendor and category spend analysis means knowing, at any point in time, where your money is actually going — which vendors are getting paid, how much, how often, and whether that number is creeping up or down relative to last month.
Read guide →Investor Q&A and info requests are the administrative tax on raising capital and maintaining LP relationships.
Read guide →A 13-week cash flow forecast is a rolling, week-by-week view of what hits your account and what leaves it — covering roughly one quarter ahead.
Read guide →An annual operating budget is a forward-looking plan that maps expected revenue against planned spending for the next 12 months, broken into categories you'll actually track — payroll, software, marketing, COGS, facilities.
Read guide →Run a Vendor Risk Assessment for other operators
The AI stack built for small in-house legal and compliance teams.
Read guide →The AI stack built for small IT and ITOps teams.
Read guide →The AI stack built for emerging fund managers.
Read guide →The AI stack built for small finance teams.
Read guide →Ready to run run a vendor risk assessment on Starch?
Request closed-beta access. Everything is free during beta.