1. Blog >
  2. Business & procurement insights
  3. Approved vendor list: Definition, criteria, and how to build one
October 7, 2026

Approved vendor list: Definition, criteria, and how to build one

Published by

  • Léo Galera
Static spreadsheet on the left transforms into a dynamic VMS-managed list with approval statuses on the right.

An approved vendor list (AVL), also called an approved supplier list, is the register of suppliers your organization has vetted and authorized to receive work or purchase orders. To get on it, a vendor passes baseline checks on compliance, financial standing, insurance and capability, and once it's on the list, buyers can engage it without repeating that qualification each time. The AVL is the foundation of vendor risk management and purchasing consistency, and for services and contingent workforce it works quite differently from the parts-and-materials version most guides describe. 

Why an approved vendor list matters

Without an AVL, every purchase restarts the same questions: is this supplier compliant, insured, financially sound, and allowed to work with us? The answers live in different inboxes, or nowhere, and the risk lands on whoever signed the order. An approved vendor list moves those checks upstream, so they happen once, consistently, before the work starts. 

Two benefits follow. First, vendor risk management gets a defined perimeter: you know which suppliers passed which checks, and when. Second, purchasing becomes consistent, because managers pick from a vetted pool instead of whoever they happen to know. The cost of lacking that consistency is measurable: The Hackett Group's 2025 Digital World Class Procurement research found that top-performing procurement teams achieve 60% less savings lost to maverick buying and contract noncompliance than their peers. Keeping buyers inside a vetted pool is one of the most direct ways to reduce that kind of leakage. 

What to include: vendor qualification criteria 

A useful AVL is a structured record, not a list of names. Each entry should answer the same set of questions, so any buyer can see at a glance what a vendor is approved for and whether that approval still holds. 

Field What it recordsExample
Vendor name and legal entity
Who exactly is approved, including the contracting entity
Acme Consulting SAS, France
Category
What the vendor is approved to supply
IT services, engineering, consulting
Approval status
Where the vendor stands in the process
Approved, pending, suspended, removed
Certifications and documents
The evidence behind the approval, with expiry dates
ISO 27001 certificate, insurance certificate, tax registration
Performance score
How the vendor has delivered since approval
Weighted score on delivery, quality and responsiveness
Owner and next review date
Who is accountable and when it's rechecked
Category manager, review in 12 months

The vendor qualification criteria behind those fields usually cover five areas: 

  • Compliance and legal standing: registration, tax status, sanctions screening, and where relevant the right to work. 

  • Financial health: enough stability to deliver through the length of the engagement. 

  • Insurance: coverage that matches the risk of the work. 

  • Capability and references: evidence the vendor has delivered comparable work. 

  • Security and ESG: information security posture and, increasingly, sustainability criteria. ISO 20400 gives organizations guidance on integrating sustainability into procurement, and is a useful reference point when ESG criteria enter supplier qualification. 

One point that's easy to miss: vendor records contain personal data, such as the names and contact details of supplier staff and, for contingent workers, individual profiles. GDPR applies to that data, so decide what you actually need to store and for how long. The European Data Protection Board's baseline guidance sets out the principles. 

How to build an approved vendor list: the 5-step vendor approval process 

  1. Identify your current vendors. Pull every supplier from accounts payable, purchase orders, contracts and contractor records, then group them by category. Expect surprises: suppliers that were paid but never formally approved, and duplicates under different names. This is the baseline the rest of the process builds on. 

  2. Define approval criteria. Set minimum requirements per category: compliance, financial, insurance, security. Decide which are mandatory and which are weighted, and write them down as a scorecard so two different buyers reach the same decision on the same vendor. 

  3. Verify vendor data. Collect the documents and check them against the source: registration, insurance, certifications, references. A supplier's own declaration isn't evidence. Record what was checked, by whom, and when each document expires. 

  4. Assign tiers and scope. Not every vendor deserves the same scrutiny. Tier vendors by spend, criticality and risk, and define the scope of each approval: which categories, which countries, and who can engage them. 

  5. Set the review cadence. Decide how often each tier is rechecked, for example annually for critical suppliers and less often for low-risk ones. Add event-based triggers too: a document expires, performance drops, an incident occurs. Define at the same time how a vendor leaves the list, because a process for adding vendors without one for removing them produces a list that only grows. 

As an illustration of steps 4 and 5, one simple tiering looks like this, to adapt to your own risk appetite:

TierTypical vendorReviewDocuments required
Tier 1, critical
Access to systems or data, or a critical service, with high spend
Annually, plus event-based triggers
Full set: legal, financial, insurance, security, references
Tier 2, standard
Regular supplier with moderate spend and limited access
Every one to two years
Core set: legal, insurance, references
Tier 3, low risk
Low spend, no access, easily replaced
When a document expires
Basic set: registration and insurance

Approved vendor lists for services and contingent workforce 

Most AVL guidance assumes physical parts and materials: quality certifications, material specifications, plant audits. For consulting, IT, engineering and staffing, the logic changes. You aren't approving a product, you're approving a firm, its people and the way it delivers, which shifts almost every criterion.

Good and materials Services and contingent workforce
What's being approved
A product specification and the plant that makes it
A firm, its people and how they deliver
Typical evidence
Quality certifications, material specs, audit reports
Insurance, tax and social-security documents, security posture, references
Pricing control
Price lists and unit prices
Rate cards by profile and seniority
Performance measure
Defect rate, on-time delivery
Mission delivery, budget adherence, stakeholder ratings, renewals
What expires
Certifications, audit cycles
Insurance, tax certificates, contractor tenure limits
Unit of approval
The supplier, per part or material
The supplier, per skill area and country

For contingent workforce vendors, the list also has to support panel management: keeping a pre-qualified group per category, with agreed rate cards, so a new request goes to vetted suppliers first. It has to track compliance documents that expire during a mission, and it has to keep track of contractor tenure limits and co-employment safeguards, which a goods supplier list never needs. The same applies to SOW-based procurement, where approval covers the vendor's ability to deliver against a defined scope and acceptance criteria, not just its paperwork. 

Approved vendor list vs. preferred vendor list vs. supplier panel 

The three terms overlap, and they're often used interchangeably, but they answer different questions: who is allowed, who is chosen first, and who is invited to bid for a category.

Approved vendor listPreferred vendor listSupplier panel
What it is
Every vendor cleared to be used
A subset selected for best value or strategic fit
A pre-qualified group for one category
How vendors get in
Pass baseline compliance and capability checks
Approved, then selected on price, quality and fit
Qualified for the category, often with agreed rates and pricing grids
What it gives them
Permission to be engaged
Priority for new work, negotiated terms
Access to competitive sourcing for that category
Typical use
Defines the compliance perimeter
Sets the default choice
Drives shortlists and RFPs

In most setups they layer: the AVL is the company-wide perimeter, panels group approved suppliers by category, and preferred vendors are the default within them. The preferred vendor guide covers that second layer in more depth. 

Common mistakes when managing an approved supplier list 

  1. Letting reviews go stale. A vendor approved three years ago on documents that have since expired is still showing as approved. The list looks controlled while the underlying evidence has lapsed. 

  2. No tiering. Treating a low-risk stationery supplier and a consultancy with access to your systems the same way either over-burdens the first or under-checks the second. 

  3. No removal process. Without a defined way to suspend or remove a vendor, poor performers stay on the list by default, and nobody can say who decides. 

  4. No clear owner. When procurement, legal, security and the business each assume someone else maintains the list, nobody does. 

  5. Documents scattered across inboxes. If the evidence behind an approval can't be retrieved quickly, it won't survive an audit, which in practice means the check wasn't done. 

  6. A list that isn't connected to sourcing. If buyers can bypass it without friction, they will, and the spend that matters most stays outside the perimeter. 

How a vendor management system keeps your approved vendor list current 

A spreadsheet-based approved vendor list is accurate the day someone builds it and decays from then on. A vendor management system turns the list into a maintained process. The difference shows up in four places: 

  • Document expiry. In a spreadsheet, someone has to remember that an insurance certificate lapses in March. In a VMS, expiry dates are tracked as data, and alerts fire before the approval quietly stops being true. 

  • Compliance tracking. A spreadsheet points to files stored elsewhere. A VMS centralizes the documents and checks against each supplier and engagement, so the evidence behind an approval is easy to retrieve. 

  • Audit trail. Who approved a vendor, on what evidence, and when it changed is recorded automatically instead of being reconstructed for an audit. 

An e-procurement suite can hold a supplier master too, but it isn't built around time-based, services and contingent workforce spend. VMS vs. e-procurement explains where each tool fits. 

From spreadsheet to a list that stays current 

If your approved vendor list still lives in a spreadsheet, the gap is rarely the list itself, it's keeping it current as suppliers, documents and engagements change. Eleven VMS's platform maintains it from live supplier and mission data, and the 6 criteria for choosing a VMS are a practical way to evaluate the switch.  

Book a meeting with one of our experts for a personalized demo. 

Frequently asked questions

Eleven VMS Blog

Find out more articles