Contractor / Vendor Management System
Compliance is calculated, never claimed.
One governed register for contractors, vendors, suppliers, manufacturers, subcontractors and inspection companies, with compliance status derived from defined requirements, supporting evidence and expiry dates, and an assurance chain that preserves how the position was reached.
Nobody types a compliance status. The engine classifies every dated item.
Expired, missing evidence, renewal overdue, expiring soon and renewal due are derived classifications. Each is calculated from the requirement, the evidence supplied against it and the relevant dates, with days overdue or remaining retained alongside the classification.
The worklist is bounded and ordered by severity, so it characterises the queue rather than listing every dated record in the tenant.
- Missing evidence is its own stateAn item with no expiry date and no evidence is not treated as compliant, and not treated as expired either. It is shown as what it is.
- Unlinked items still surfaceA compliance item not yet linked to an organisation appears in the worklist rather than disappearing until somebody connects it.
- Thresholds are tenant settingsWhat counts as expiring soon is configured by the organisation, not fixed by the application.
Suppliers take part without holding authority.
An external portal is where the supplier works: compliance evidence, documents, prequalification responses, contracts, performance, audits and corrective actions. None of it counts until it is verified on the customer side, and a supplier never sees its own prequalification score.
The internal console
The organisation register, compliance engine, prequalification scoring, contracts, supplier performance and assurance chain are controlled through role-based access so each organisation sees only the information it is authorised to access.
- · Tenant administrator, manager, member and read-only
- · An assurance authority for audit review, corrective-action verification and risk approval
The supplier portal
A separate surface where the external organisation submits and responds. Seventeen portal areas, each mapped to the internal record it feeds, and every submission verified before it changes anything.
- · Submissions are proposals until verified
- · Prequalification scoring stays invisible to the supplier
An audit finding does not stop at the audit report.
Audit, finding, corrective action, independent verification and risk are one linked chain. Closure is measured as a share of all non-cancelled actions, so cancelling is never a route to a better number.
An audit is planned and carried out against an organisation, with its scope and its state recorded rather than assumed from a calendar entry.
Levels go to your matrix. The ratings come back.
Likelihood and consequence are recorded as the organisation's own matrix defines them, and control effectiveness feeds the residual calculation. The inherent and residual ratings are the engine's output, not a field on a form.
A risk then advances only along its transition table: where a next state is not valid, the service refuses it rather than the interface quietly omitting it. Seven states, from identified through assessed, treatment planned, treated, monitored and accepted, to closed.
Inherent and residual, with the exposure and the trend.
The record carries both scores and both ratings, the exposure behind them and whether the position is improving. Every transition is recorded against the record's own history, with a note attached to the transition rather than to the risk in general.

Twenty-two modules, inside and outside the organisation.
The application's own navigation, with the external portal as a first-class surface rather than an afterthought. Every chip is a page.
The organisation register
One record per external organisation with a complete view across every module, and the documents that organisation has provided held against it rather than in somebody’s mailbox.
- Register
- Documents
- Knowledge
Qualification and compliance
Prequalification templates and submissions with scoring the supplier cannot see, a compliance engine that classifies every dated item, contracts and variations, and supplier performance scoring.
- Prequalification
- Compliance
- Contracts
- Supplier performance
The assurance chain
Audits raise findings, findings raise corrective actions, corrective actions are verified by an assurance authority, and risks carry their own lifecycle. One chain rather than four disconnected registers.
- Audits
- CAPA
- Risk
The supplier portal
Suppliers take part without holding authority. They submit compliance evidence, documents, prequalification responses and performance information, and every submission is verified on the customer side before it counts.
- Compliance
- Documents
- Prequalification
- Contracts
- Performance
- Audits
- CAPA
- Support
Work and insight
A personal work queue, notifications, scheduled expiry monitoring with service-level escalation, and governed reporting with schedules and history.
- My work
- Notifications
- Reporting
- Report settings
Configuration
Requirement catalogues, risk matrices, workflows and operations are tenant configuration, so the rules the engine applies are the organisation’s own rather than a vendor default.
- Configuration
- Workflows
- Data management
- Operations

Approved for this work, on this date, with this evidence.
The question a contracts or HSE manager has before a contractor mobilises is narrow and dated: are the licences current, is the insurance in force, has the prequalification been decided, and is there a corrective action still open. CVMS answers it from the register rather than from a folder.
- Organisation standing across approved, under review, prospective, suspended and expired
- Compliance exposure by expired, renewal overdue and expiring soon
- Risks on register with escalation carried separately
Twenty-four report definitions, grouped by business area.
Executive, organisational, compliance, prequalification, contract, supplier-performance, audit, assurance, corrective-action, risk and operational reporting, with each report stating the governed record from which its position is derived.

Status the engine derives
Expired, missing evidence, renewal overdue, expiring soon and renewal due are classifications the compliance engine produces from requirements, evidence and dates. No one types a compliance status.
Participation without authority
A supplier can submit, respond and upload through the portal, and none of it counts until it is verified on the customer side. The supplier never sees its own prequalification score.
The matrix is yours
Inherent and residual ratings come from the tenant’s configured matrix. Levels go to the matrix and the ratings come back; the application does not impose a scale.
Transitions are validated
A risk advances only along its transition table. Where a next state is not valid the service refuses it rather than the form quietly hiding it.
More of what the application covers.
- Prequalification templates with supplier-blind scoring
- Contracts and variations against the organisation
- Supplier performance scoring over time
- Scheduled expiry monitoring with escalation
- Requirement catalogue as tenant configuration
- Organisation classification and country breakdown
- Import, export and templates for governed data
- An advisory assistant that cites its sources and changes nothing
Supplier assurance, beside the systems that transact.
- PMSPMS: Procurement Management SystemPMS transacts with suppliers; CVMS qualifies them and maintains the compliance and assurance record.
- CMSCMS: Contracts Management SystemCMS governs the contract and its obligations; CVMS governs the assurance position of the counterparty behind it.
- QMSQMS: Quality Management SystemQMS governs internal non-conformance and corrective action; CVMS applies equivalent assurance controls across external organisations.
- HSEHSE: Health, Safety & Environment Management SystemHSE governs contractor HSE profiles and competencies in the operational safety context, alongside the commercial and supplier-assurance record.
See CVMS with one of your contractor registers.
Bring one contractor and its compliance evidence. We will show what the engine classifies it as, what the portal would ask the contractor for, and where an audit finding would travel.

