Ontech ICTM platform

IT Vendor Management Software

Know who supplies your technology, what you have agreed with them, and which services would stop if one of them failed.

What is IT vendor management?

IT vendor management is the practice of selecting, contracting, overseeing and assessing the suppliers that provide an organisation's technology, from software licences to connectivity and support. It covers contracts, service levels, costs and the risk each supplier represents. Ontech ICTM keeps a supplier register, contracts and a vendor risk analysis based on application dependencies.

Most IT services now depend on outside suppliers: software vendors, cloud and hosting providers, internet providers, hardware maintainers and support partners. Vendor management makes sure those relationships are documented, that their terms are understood, and that the organisation knows how exposed it is to each supplier.

The commercial side — who the supplier is, what the contract is worth, when it renews and which service levels apply — is only half of it. The other half is dependency risk: which applications rely on a supplier, whether there is any alternative, and whether the supplier's recovery commitments match your own targets.

ICTM covers both halves. The vendor register and contracts hold the commercial details, while Vendor Risk in the Business Continuity module maps suppliers to applications, flags single points of failure, scores each dependency and analyses how concentrated your reliance on individual suppliers has become.

What ICTM does for it vendor management

Vendor register

Keep each supplier's contacts, taxpayer identification number (TPIN), bank details and payment terms in one register instead of scattered spreadsheets and email threads.

Contract records

Record each contract's value and currency, its start and end, whether it renews automatically and the notice period needed to exit or renegotiate it.

SLA policies linked to contracts

Link a contract to the service-level policy that applies to it, so the agreed service levels are visible next to the commercial terms.

Application dependency mapping

Record which applications and services depend on each supplier, so the impact of a supplier failure is known in advance.

Single-point-of-failure flags

Flag dependencies where one supplier is the only route to keeping an application running, so they can be reviewed and, where needed, mitigated.

Supplier recovery commitments

Capture each supplier's SLA uptime, RTO and RPO against the applications that rely on them, and compare them with your own recovery targets.

Vendor risk scores

Give each supplier dependency a risk score from 0 to 100 so the riskiest relationships stand out.

Concentration-risk analysis

ICTM calculates how much of your application estate depends on individual suppliers, showing where too many services rest on one relationship.

AI vendor-risk analysis

Request an AI analysis of supplier risk to test your assumptions; it can run on a locally hosted language model and is advisory.

ICTM modules: Vendors · Vendor Risk · Business Continuity

Use cases

Preparing for contract renewals

See each contract's end date, auto-renew flag and notice period in one place before negotiations start.

Checking supplier resilience

Compare a supplier's RTO and RPO with the targets your business impact analysis has set.

Reducing single-supplier dependence

Identify services that depend entirely on one internet provider, hosting company or software vendor.

Supplier due diligence for regulators

Show a documented supplier register, contract terms and dependency risks when asked how outsourced technology is overseen.

Finance and procurement records

Keep supplier TPINs, bank details and payment terms consistent for the teams that pay suppliers.

Benefits

One supplier record

Commercial, contractual and risk details for each supplier sit together.

Visible dependency risk

Single points of failure and concentration risk are recorded, not discovered during an outage.

Better negotiations

Knowing a contract's value, renewal terms and service levels strengthens renewal discussions.

Supplier risk in the wider picture

Vendor single points of failure feed ICTM's unified risk score.

Frequently asked questions

What vendor information does ICTM store?

For each supplier ICTM stores contacts, TPIN, bank details and payment terms. For each contract it records the value, currency, dates, the linked SLA policy, whether it renews automatically and the notice period. Vendor Risk adds the applications that depend on the supplier and its recovery commitments.

Does ICTM send contract renewal reminders?

ICTM records each contract's end date, auto-renew flag and renewal notice period so renewal decisions are visible in the vendor register. It does not currently send renewal reminders automatically, so review upcoming renewals as part of your regular supplier meetings.

What is a single point of failure in vendor management?

A single point of failure is a supplier whose outage would stop a service on its own because there is no alternative, such as one internet provider for a branch or one vendor for a core application. ICTM lets you flag these dependencies so they can be mitigated or consciously accepted.

What is vendor concentration risk?

Concentration risk is the exposure created when many services depend on the same supplier. Each dependency may look acceptable on its own, but together they mean a single supplier problem could affect a large part of the organisation. ICTM calculates concentration across your recorded application dependencies.

Does ICTM monitor supplier SLA performance?

ICTM records the service levels a supplier has committed to, including uptime, RTO and RPO, and links contracts to SLA policies. It does not measure the supplier's live performance against those levels, so record any breaches you observe through incidents and review them with the supplier.

See it vendor management in Ontech ICTM

Book a walkthrough with the Ontech team, or start a free trial and explore the platform yourself.