An approved vendor list is the short, controlled answer to a question buyers ask every day: who are we allowed to buy this from? It turns scattered vendor knowledge into a register that anyone can act on, protecting quality and compliance while making everyday purchasing faster. This guide covers what an AVL is, why organisations keep one, what qualifies a vendor, who signs off, the data each entry should hold, conditional approvals, re-approval and removal, and how the list connects to catalogue buying.
Key takeaways
- An AVL is a permission list: it records which vendors are cleared to supply which categories.
- Approval is a decision with evidence behind it, not an entry someone typed into a spreadsheet.
- Every entry needs an owner, a scope and an expiry date, or the list quietly rots.
- An AVL only works if buying against it is easier than going around it.
What is an approved vendor list?
An approved vendor list is a controlled register of the vendors your organisation has assessed and cleared to supply defined goods or services. It is a permission artefact. When a vendor appears on the AVL for a given category, a buyer can raise a requisition against them knowing the due diligence has already been done: the company exists, it is solvent, it holds the right insurance and certifications, and someone competent has judged it capable of meeting specification.
The list sits inside the wider procurement process rather than beside it. Sourcing finds candidates, evaluation tests them, and the AVL records the outcome so the work is not repeated every time someone needs the same thing. It is the difference between a business that knows who it buys from and one that finds out only when an invoice arrives from a name nobody recognises.
An AVL is also narrower than a general vendor database. A supplier list may hold everyone you have ever traded with, including dormant and rejected records. The approved list is the subset carrying an active permission, which is why it should always be shorter than the database it is drawn from.
Why organisations keep an approved vendor list
The reasons cluster into four, and most organisations feel all of them at once.
- Quality. Approval means a vendor has demonstrated it can meet specification consistently, so buyers are not gambling on an unknown every time they order.
- Compliance. Regulated industries must show that materials and services came from assessed sources, and an auditable AVL is the evidence that proves it.
- Risk. Vetting for solvency, insurance, data handling and ethical practice before the first order is far cheaper than discovering a problem mid-contract.
- Negotiated pricing. Consolidating spend onto approved vendors gives you the volume needed to negotiate, and the list is what stops that volume leaking away.
There is a fifth benefit that rarely appears in policy documents but matters most day to day: speed. A requester who knows exactly which three vendors are cleared for laboratory consumables makes a decision in minutes. Without the list, the same request becomes an email thread, a delay and, often, an order placed with whoever answered first.
What qualifies a vendor for the list
Qualification criteria vary by category and risk, but the structure is consistent. Start with the basics: legal identity, registration details, tax status and bank verification. Then test financial health, since a vendor that fails mid-contract causes far more disruption than one that quotes slightly higher. Insurance certificates, relevant accreditations and any sector-specific licences follow.
Next comes capability. Can the vendor meet the specification, the volumes and the lead times you actually need? This is where quality or engineering input matters, whether through sample testing, a site visit, a reference check or a documented quality system. For services, capability is usually demonstrated through references, case work and named personnel.
Finally, assess conduct and continuity: data protection practices, subcontracting arrangements, modern slavery and sustainability declarations, business continuity plans and, increasingly, cyber security posture. Not every vendor needs every check. Applying the same heavy assessment to a strategic manufacturer and a stationery supplier is the fastest way to make the process resented and bypassed, so tier the requirements by category risk and expected spend.
The approval workflow and who signs off
A vendor should reach the list by a route that is written down and repeatable. In most organisations the workflow runs: request to add, initial screening, documentation collection, functional assessments, approval decision, and recording on the list with a defined scope.
Sign-off is normally shared. Procurement owns the process and the record. Quality or the technical function confirms capability. Finance confirms solvency and terms. Legal or compliance clears contracts, insurance and regulatory obligations. Above a spend or risk threshold, a category lead or director adds a final approval. Splitting sign-off this way means no single function can wave a vendor through, and each approver only judges what they are qualified to judge.
Approve a scope, not a company. The most common AVL failure is approving a vendor in general and then discovering someone has bought a regulated component from a firm that was only ever assessed for packaging. Every approval should name the categories, sites and, where relevant, the spend ceiling it covers.
Keep the workflow proportionate. A three-stage path for low-risk vendors and a full assessment for critical ones will be followed. A single ten-week process for everything will not, and the result is exactly the informal buying the list exists to prevent. Sound vendor management depends on a workflow people can live with.
The data each AVL entry should hold
An AVL that records only company names is a contact list. The value comes from the fields around the name, which turn an entry into a decision someone can rely on.
| Field | Why it matters |
|---|---|
| Legal name and registration | Identifies the entity you actually contracted with, not a trading name. |
| Approved categories | Defines the scope of the permission and prevents approval creep into unassessed goods. |
| Approval status | Full, conditional, probationary or suspended, so buyers see the real position. |
| Approval date and expiry | Makes re-approval automatic rather than dependent on someone remembering. |
| Internal owner | Names the person accountable for the relationship and the record. |
| Certifications and insurance | Holds the documents and their renewal dates in one auditable place. |
| Contract and terms | Links negotiated pricing, payment terms and the agreement itself to the entry. |
| Risk tier | Drives how often the vendor is reviewed and how deeply. |
| Performance summary | Delivery, quality and responsiveness data to inform the next re-approval. |
| Sites or entities covered | Stops an approval for one location being assumed across the whole group. |
Two fields do most of the work. The owner turns an anonymous record into someone's responsibility, and the expiry date converts a static list into a managed one.
Conditional and probationary approvals
Approval is rarely a clean yes or no. A vendor may be exactly what you need on capability but short of one certificate, or promising but untested at your volumes. Forcing a binary decision either blocks a good vendor or waves through an unproven one, so mature lists carry graded statuses.
Full approval
All checks passed. The vendor can be used freely within the approved categories until the expiry date.
Conditional approval
Usable now, but with a named gap, an owner and a deadline. If the condition is not met, the status drops automatically.
Probationary approval
A new vendor cleared for a limited period, spend ceiling or set of orders while performance is proven.
Suspended
No new orders pending resolution of a quality, compliance or financial issue. Existing commitments continue under review.
Graded statuses only help if the conditions are tracked. A conditional approval with no deadline is a full approval with extra paperwork, and probation that nobody ever reviews simply becomes permanent.
Re-approval, expiry, suspension and removal
Approval is a snapshot, and vendors change. Ownership shifts, key staff leave, certificates lapse, financial positions weaken. Re-approval is how the list stays true, and the practical way to run it is to give every entry an expiry date rather than attempting an annual review of everything at once. Stagger the dates by risk tier so the workload spreads across the year.
Certain events should trigger an immediate review regardless of the date: a change of ownership, a serious quality or safety failure, an expired insurance or accreditation certificate, a compliance finding, or credit deterioration. These event triggers catch the risks a calendar never would.
Removal deserves as much rigour as addition. Record the reason, the decision maker and the date, notify the vendor, close open orders properly, revoke system access and remove them from any catalogue so nobody can order from a deleted record. Keep the historical entry rather than deleting it, both for audit and so the same vendor does not quietly reappear through a different route six months later. Handled well, removal is simply one stage of the wider supplier relationship lifecycle.
Maverick spend, catalogues and keeping the list alive
An approved vendor list is a control, and controls are only as good as the behaviour they produce. Maverick spend, meaning purchasing that goes around the agreed process, is the direct measure of whether yours is working. If a large share of orders lands with vendors who are not on the list, the problem is almost never discipline. It is that buying compliantly was slower, harder or less obvious than not.
The remedy is to make the approved route the path of least resistance. Surface the AVL where requests are raised, so a requester sees approved vendors before they see a search engine. Connect approved vendors to catalogues with negotiated pricing already loaded, which is often the moment maverick spend collapses: people buy from the catalogue because it is faster, not because a policy told them to. Block or route for exception approval any requisition naming an unapproved vendor, and make the exception route real rather than theatrical, so genuine urgent needs are met and then followed up properly.
Keeping the list from going stale comes down to ownership and automation. Every entry needs a named owner, documents need expiry reminders, and performance data should flow back into the record automatically rather than being retyped from a spreadsheet. This is where a vendor management system earns its place: the AVL stops being a document someone maintains and becomes a live layer that requisitions, catalogues and approvals all read from. That is how ProcureWave handles it, with approval status, expiry dates and scope attached to the vendor record itself, so a lapsed certificate is caught before an order is raised rather than during an audit.
If you are starting from scratch, do not attempt the whole estate at once. Take your highest-spend or highest-risk category, build a proper approved list for it, wire it into how people actually raise requests, and measure how much spend moves onto it. Then repeat. Prune aggressively as you go, because a list of forty genuinely approved vendors is far more useful than four hundred names nobody has checked. If you would like to see how an AVL works when it is connected to requisitions, catalogues and approvals rather than sitting in a spreadsheet, get in touch and we will walk through it with your own categories in mind.
Frequently asked questions
What is an approved vendor list?
An approved vendor list, or AVL, is the controlled register of vendors your organisation has vetted and cleared to supply specific goods or services. Being on the list means a vendor has passed the checks your business requires, so buyers can raise an order against them without starting the assessment from scratch.
What is the difference between an approved vendor list and a preferred supplier list?
Approval is a permission and preference is a recommendation. Every vendor on a preferred supplier list should be approved, but not every approved vendor is preferred. Approval says you may buy here; preference says you should buy here first, usually because of negotiated pricing or a strategic relationship.
Who approves a vendor for the list?
Usually a small panel rather than one person. Procurement owns the process, quality or engineering confirms the vendor can meet specification, finance checks solvency and payment terms, and legal or compliance clears contracts, insurance and regulatory requirements. Larger or riskier commitments escalate to a director or category lead.
How often should an approved vendor list be reviewed?
Set an expiry date on every entry rather than reviewing the whole list at once. Critical and regulated vendors are commonly re-approved annually, routine low-risk vendors every two or three years, and any vendor is re-checked immediately after a serious failure, an ownership change or a lapsed certificate.
Can a vendor be removed from an approved vendor list?
Yes, and the ability to remove one is what gives the list its authority. Vendors are suspended for temporary problems such as an expired certificate or a run of quality failures, and removed outright for contract breaches, insolvency, compliance findings or simply because the category no longer needs them.
Want to see this in your own numbers?
Book a tailored demo and we will show ProcureWave running on scenarios that match your business.
Get in touch