Our key vendor or developer may disappear. How do we protect the company?

Secure what you're entitled to now: code or configuration, documentation, data, environments and credentials, under the company's control. Then check what the contract gives you on insolvency, change of control and exit, and prepare a continuation plan you hope never to use. Watch closely the few vendors and people the company cannot run without.

Draft for Tamir's review. Not published.

Tamir Khason · Updated · Decision guides

Secure what you hold before you talk

Take possession of deliverables, documentation, data and access to date. Put code, environments and credentials under company control. Confirm that accounts and recovery channels belong to the company and not to a person.

Read the contract with counsel for insolvency, escrow, step-in, change-of-control and named-staff terms. Then talk to the vendor or its new owner with facts, and ask for its commitments in writing.

Reduce a dependence on one person

When one developer is the only person who understands a critical system, reduce the dependence before deciding the system's future. Agree a paid knowledge transfer with that person: documentation, a second developer working alongside, tests and recorded walkthroughs.

Then assess the system's state and decide whether to keep, modernize or replace it. Prepare for the departure anyway: who covers, what breaks and for how long.

Depending on your seat

If you're on the board, ask for the list of vendors the company cannot run without. For each, ask what depends on it, its financial health and the contract's protections. Require a continuation plan for each and review the list periodically.

If you're the CEO about to sign with a provider that runs a core service, settle the exit before you sign. Ask where customer funds or data sit, how the provider would wind down, and whether a second provider could take over.

What to check before you decide

  • List the vendors and people the company cannot run without, and what depends on each.
  • Take possession of the deliverables, code or configuration, documentation and data you're entitled to.
  • Put code, environments, credentials and account recovery under company control today.
  • Check the contract for insolvency, escrow, step-in, change-of-control and named-staff terms.
  • Identify the vendor people the work depends on, and ask whether they're being paid and retained.
  • Prepare a continuation plan with what it would take to finish or run with another firm.
  • Decide what can keep operating safely while you choose between recovery and replacement.

Questions people ask

Our project vendor is reported to be in financial trouble, what should the committee do before it becomes our problem?

Secure the deliverables, source or configuration, documentation and data the contract entitles the body to, confirm key staff and payment status, and prepare a continuation plan with another party. Then talk to the vendor about continuity with facts. It depends on what the contract gives the body in a vendor insolvency and on how much knowledge sits with the vendor's people.

A key vendor went bankrupt and we scrambled, how should the board require vendor financial risk to be managed?

Require a list of the vendors the company cannot run without, with their financial health, contract protections such as escrow and step-in, and a continuation plan for each. Monitor the few that matter rather than all. It depends on how many vendors are critical and on what the contracts already provide.

What continuity evidence should directors require from a small municipal IT supplier?

Evaluate organizational continuity rather than assuming size determines suitability. Selection depends on documented knowledge, access ownership, substitute capability, and a practical response when key people are unavailable.

Signing with a banking as a service provider, what protects our customers if the provider fails or leaves the market?

Get clarity on where customer funds sit and under whose license, a documented exit with data and customer migration support, and the right to run a second provider in parallel. Ask the provider how it would wind down and whether its regulator has seen the plan. It depends on your own regulatory status and on what the provider's license lets it promise.

The vendor on our key project was acquired, what should I do to protect the project?

Secure what you hold: deliverables to date, documentation, environments and the named team in the contract. Ask the new owner in writing for its commitments to the product and the project. Prepare an exit you hope never to use. It depends on the acquirer's business and on how much of the project's knowledge sits with the vendor's people.

Our dispatch system depends on one developer who may leave, how do I protect the company?

Reduce the dependence before deciding on the system: documentation, a second person working alongside him, tests, and controlled access, with his cooperation paid for. Then decide on keeping, modernising or replacing the system with that knowledge in hand. It depends on how long he will cooperate and on how critical the system is to daily operations.

What should we decide when our mobility software supplier stops trading?

Establish what the business can still access and operate before choosing recovery or replacement. It depends on legal rights, available service dependencies, support capability, and the practical reuse of connected equipment.

How I can help with this decision

Ask or talk (Free)
I give my view on what to secure first, and how to approach the vendor, its new owner or the key person without triggering what you fear.
Review (Pay if it was worth it)
I write an independent assessment of the company's exposure to the vendor or person and the continuation options. I recommend actions, contract positions and a contingency.
Retain (When it makes sense)
I stay close through the transition or the vendor's difficulties to review its commitments and your protection.