--- name: respond-to-a-major-vendor-failure category: start description: Respond to a major vendor failure through safety and customer continuity, evidence and contract control, alternate-service activation, financial and data reconciliation, recovery, and exit. Use when a critical supplier suffers outage, compromise, insolvency, loss of capacity, or persistent nonperformance. --- # respond-to-a-major-vendor-failure Continuity decisions must account for data, money, customers, and obligations already in flight. ## When to use - Use for critical technology, payroll, logistics, manufacturing, facilities, payment, data, or professional suppliers. - Activate qualified operational, security, privacy, safety, finance, procurement, legal, regulatory, and communications support. ## Preconditions - Establish incident, service, customer, safety, security, data, finance, procurement, legal, vendor, alternate-supplier, and communications authority. - Define affected services, regions, customers, workers, obligations, dependencies, materiality, and stop authority. - Preserve contracts, current state, transactions, data, access, communications, monitoring, and vendor representations. ## Procedure Complete **customer and safety continuity**, **evidence and obligation scope**, **alternate service and exit coordination**, and **recovery and reconciliation** as one response. 1. Open a **vendor failure timeline and control register** covering services, dependencies, alerts, vendor notices, incidents, decisions, transactions, data, access, contractual deadlines, and communications. 2. Protect people and customers through safe-mode operations, work stoppage, alternate fulfillment, manual continuity, status communication, and accessible support. 3. Verify vendor status through authorized channels and preserve service, security, capacity, financial, legal, insolvency, and subcontractor evidence. 4. Map direct and transitive dependencies, including integrations, credentials, data, inventories, work in progress, funds, licenses, facilities, personnel, subcontractors, and downstream promises. 5. Build an **impact, transaction, data, and obligation reconciliation** by customer, employee, order, payment, shipment, record, service, region, and contract. 6. Review service levels, notification, cure, step-in, audit, access, portability, escrow, continuity, insurance, liability, termination, and transition rights with qualified owners. 7. Revoke, restrict, or rotate vendor access proportionate to risk while preserving continuity and evidence. 8. Activate tested alternate processes or suppliers with verified capacity, compatibility, security, privacy, safety, financial, and jurisdiction controls. 9. Enforce a cross-provider transaction handoff fence. Classify each payroll batch, message, shipment, identity change, cloud operation, payment, and record as created, sent, accepted, committed, failed, cancelled, or explicitly indeterminate; bind its durable owner and idempotency key before any fallback may act. 10. Reconcile customer remedies, payroll or vendor payments, inventory, refunds, credits, liabilities, insurance, and accounting without erasing original history. 11. Decide restore, dual-source, remediate, restructure, step in, or exit using service, risk, cost, customer, legal, and recovery evidence. 12. Transition in bounded waves with acceptance, support, monitoring, rollback, and residual-duty ownership. 13. Recover or delete data, disable credentials, return assets, preserve records, settle commitments, and verify subcontractor disposition. 14. Review detection, concentration, contract, architecture, continuity, and governance controls through tested remediation. ## Failure plan - If the vendor cannot establish trustworthy state, treat affected data and transactions as unresolved and contain further mutation. - If the alternate lacks safe capacity or required authority, reduce service explicitly rather than duplicate or improvise critical actions. - If insolvency threatens access to data or assets, activate qualified legal, escrow, continuity, and evidence measures immediately. - If restoration and exit paths conflict, preserve the option that best protects people, customers, evidence, and irreplaceable state. ## Worked example A critical vendor providing payroll, identity, cloud hosting, customer messaging, and regional logistics suffers a cyber incident while financial distress limits staffing, subcontractors stop work, data exports are incomplete, some transactions are pending, contractual notices conflict, and the next payroll plus customer delivery cycle is hours away. The organization protects people and customers, reconciles every in-flight item, restricts unsafe access, activates bounded alternatives, avoids duplicate execution, and chooses recovery or exit from verified evidence. ## Done - A vendor failure timeline and control register verifies services, dependencies, evidence, access, transactions, data, contracts, decisions, communications, and ownership - An impact, transaction, data, and obligation reconciliation proves customer, employee, order, payment, record, asset, liability, remedy, and unresolved status - A continuity, recovery, and exit report demonstrates alternate capacity, one-owner processing, security and privacy, financial controls, contractual handling, transition tests, credential closure, and remediation