What counts as a vendor — and what doesn't
A vendor is any third party — a company, service, or piece of software — that your organization relies on to run its business. If you use it, it belongs in your vendor inventory. Free, API-only, no access to your data, no personal data — none of that exempts it. The only real exclusions are things with no ongoing third-party relationship: a one-off purchase, an internal tool you built yourself, or a self-hosted open-source library with nobody upstream.
How to decide
Ask one question: is this an outside party we depend on to operate? If yes, add it. Whether it's free, paid, reached only through an API, or holds none of your data doesn't change the answer — those details describe a vendor's risk, not whether it counts.

Don't over-correct and pad the list either. Every vendor you add has to go through reviews, so the goal is complete, not inflated. Skip genuine non-vendors; include everything real.
The "we just use their free API" myth
The most common reason inventories come up short is the belief that certain tools don't "really" count. They do. Here's the honest version of each:
- Free doesn't exempt it. A free plan is still a third party you depend on. Paid or free, it's a vendor.
- API-only doesn't exempt it. Reaching a service only through an integration is still using that service. The connection type doesn't change what it is.
- No personal data doesn't exempt it. A vendor that holds no personal data and touches none of your systems is still a vendor. "Low risk" is not the same as "not a vendor."
- A reseller isn't the whole story. If you buy a product through a middleman, list the reseller — and usually the upstream provider that actually runs the product, too.
- Open source depends on how you use it. A hosted open-source service, or one you pay for support or data handling, is a vendor. A library you self-host with no company behind it is the edge case that's usually out of scope.
Examples
The verdict follows how you use the tool, not its name or price. Each case assumes the typical use described.
Count these:
- SaaS and software you use to operate - paid, free, or reached only through an API (a project tracker, a design tool, a scheduling app).
- Cloud and infrastructure providers (a host running your app and database).
- Analytics, monitoring, email, and helpdesk services (a product-analytics tool, an error monitor, a transactional email service).
- Back-office services (a payroll provider, an accounting platform).
- Outsourced work and agencies — a contractor or agency delivering a service counts as a vendor.
- A reseller you buy through — and typically the upstream provider behind it.
- Vendors with no access to your systems and no personal data. Still in.
Leave these out:
- A one-off purchase with no ongoing data or system relationship (a single stock-photo license you'll never touch again).
- A tool your team built and hosts entirely in-house.
- A self-hosted open-source library with no third-party service, support, or data flow behind it.
Why it matters / what your auditor expects
Inventory completeness is the foundation every vendor review sits on. The platform's vendor tests only evaluate the vendors already on your list — they can confirm those vendors are reviewed, but they can never flag one you left off. Under-reporting is invisible to the tests, which is exactly why it's dangerous: an auditor will catch it by cross-checking your list against contracts, invoices, and your published subprocessor page. A missing vendor is a classic audit finding.
An empty inventory doesn't pass either — the vendor tests sit pending until there's something real to review. Build the list once, honestly and completely. Complete, not padded.
Common mistakes
- Skipping a tool because you're on its free or API-only tier. The relationship counts, not the plan you pay for.
- Leaving off a vendor because it holds no personal data or has no system access. That makes it low-risk, not a non-vendor.
- Listing only the reseller. The company actually running the product usually belongs on the list too.
- Padding the list to look thorough. Every entry gets reviewed — add real vendors, not filler.
