A supplier review is more than reading the report

This guide revisits supplier management practices in 2019; it was written and published in 2026. The meeting, amounts, lead times and people described are fictional. The model concerns an IT service review between a client and a provider, rather than a universal legal procedure. Obligations remain those of the contract and applicable context.

At nine, Antoine, the service manager, finds the same presentation as last month: satisfactory availability, fewer tickets and three actions “in progress”. Claire, the manager of an industrial site, is still waiting for a correction affecting logins at shift start. The supplier explains that the incident represents few minutes within the monthly total. Both parties can be right within their own measurement while discussing different services.

A useful review produces a commitment that can be managed: a defined gap, a treatment, an owner, a date and evidence of closure. The supplier report is one input. Knowledge of the client’s work is another. A meeting should not become a permanent trial; it should prevent defects remaining invisible behind averages and vague wording.

Prepare three cases rather than thirty comments

Five working days before the meeting, Antoine and the provider agree on the period, services and events being examined. The client adds verified business impacts; the supplier provides the chronology and changes. Data discrepancies are identified before the session. A review should not spend half its time establishing whether a ticket was created at eight or half past eight.

Three cases are selected here: shift-start logins, recovery of ERP exchanges and knowledge transfer for a recent application. Each identifies the affected service, population, impact, events, previous actions and expected decision. Everything else remains accessible in the report and work queue. It is not deleted, simply handled at the appropriate level.

The contract manager checks which commitments apply. An operational target can be discussed without automatically becoming a new SLA, a contractual service-level commitment. If the supplier must mobilise additional capacity or alter scope, that decision follows the agreed commercial process. The session distinguishes included corrective action from a new service.

The case template to send before the review

The table below is a completed example the team can copy. An unverified assertion is retained as a hypothesis rather than promoted to a cause. The service owner confirms the business impact; the supplier confirms facts within its scope. Both parties can maintain a precise disagreement while deciding on an experiment intended to resolve it.

The case also retains previous attempts. For logins, a one-off restart restores service but does not constitute a lasting correction. Repeating it without investigating its cause explains why the same topic returns at every meeting. Expected evidence must therefore cover several shift starts, rather than merely the end of the latest incident.

Case R-12: access at shift start

Completed educational template
FieldContent
Service and periodSite A authentication, working days, 05:45 to 06:30, four weeks.
GapThree interruptions lasting 12, 18 and 9 minutes; operator access delayed.
Verified impactStart of data entry delayed for two lines; no production stoppage claimed without evidence.
CauseHypothesis: saturation after a scheduled task; correlated analysis to be supplied.
Previous actionRestart after the incident; recurrence unresolved.
Expected decisionAuthorise a task-rescheduling test and reserve observation over five shift starts.
OwnersProvider: diagnosis; client: window and business observation; service owner: decision.
DeadlineDiagnosis Thursday; test the following Monday if authorised.
ClosureNo new incident over five shift starts, logs analysed and hypothesis confirmed or invalidated.
If the test failsReturn to the initial schedule, preserve records and propose a second hypothesis.

A sixty-minute agenda with a clear outcome

Minutes zero to five: changes since preparation and confirmation of attendees’ authority. Minutes five to twenty-five: R-12, because it affects a critical period. Examine chronology, data and the hypothesis, then select the test. The client does not request “greater vigilance”; the supplier does not promise to “do its best”. Each specifies its contribution and conditions.

Minutes twenty-five to forty: ERP recovery. The session distinguishes technical restoration time from business recovery time. The supplier may restore the flow while finance still has to reconcile messages. Minutes forty to fifty: knowledge transfer. Regular support must resolve a case without the project expert, using its normal permissions and an available procedure.

The final ten minutes cover decisions and possible commercial commitments. The record is read aloud. An absent owner is not assigned an action without validation of capacity; the service manager obtains that confirmation and announces the deadline. A longer session may be necessary in a crisis, but routine management should not be confused with a resolution task force.

When the client contributes to the gap

The provider supplies the ERP chronology. Messages were available, but a client control blocked processing because reference data had not been updated. Antoine must resist two reflexes: defending his team without examining facts, or accepting all responsibility to preserve the relationship. The review separates events and responsibilities.

The client updates the data; the supplier improves rejection detection if that belongs to the agreed service; both rerun reconciliation. The contract may require particular deadlines or forms for disputes and notifications. The contract manager handles these matters in parallel without blocking a useful operational correction.

A good service relationship permits this reciprocity. The supplier must be able to identify a failing client dependency with evidence, and the client an inadequate supplier outcome. Transparency does not erase the contract; it prevents the meeting becoming an exchange of impressions that cannot be closed.

Do not close an action merely because it was delivered

An action has a status, target date and closure criterion. “Fix deployed” means a change is in place. “Problem resolved” requires checking the behaviour that justified the action. For R-12, five incident-free shift starts are observational evidence; if the cause is unconfirmed, distinguish provisional resolution from analysis still open.

The log retains dependencies and the person empowered to authorise a change. A test requiring a production window cannot be assigned to the supplier without site coordination. Client availability belongs in the schedule. An old action is reassessed when its context changes, rather than automatically renewed with another date.

The closure rate considers only actions whose deadline has arrived. Seven closed actions out of ten give 70%. The remaining three are examined individually, because one critical action can matter more than seven easy ones. The rate is therefore not used alone to praise or penalise the provider.

Three measures with a shared definition

Recurrence counts incidents involving the same mechanism on the same service under an agreed rule. Similar symptoms do not prove an identical cause. Technical restoration time runs from defined detection to component recovery; business recovery time ends when the useful journey is again possible and verified. Waiting for client approvals is retained separately to understand responsibilities.

The third measure is compliance with review commitments: actions closed according to the criterion by the promised date. The table distinguishes new risk, persistent defect and scope change. A trend without volume or period is insufficient. Fewer tickets may mean fewer incidents, but also abandoned reporting or a new way of grouping requests.

In the scenario, two recurrences after announced closure lead to reopening root-cause analysis and considering additional expertise. The threshold is chosen for the example. The contractual relationship determines what can be requested, charged, notified or penalised; the review does not invent rights that do not exist.

Three contexts, three forms of service evidence

In pharmaceuticals, a service may contribute to a regulated environment. Corrections then follow the context’s change-control and validation requirements. The case connects the incident to the relevant process, versions and tests rather than a simple infrastructure average. The quality manager participates where their authority is required.

In banking, the timing of a payment or closing incident may be decisive. Restoration checks include pending transactions and their reconciliation. In an industrial group, support-team location and language can determine recovery at five in the morning. Coverage at shift start is verified against people actually available, rather than theoretical coverage written into the contract.

For a business service, validation may concern a processed case or a genuinely self-sufficient user. The review must then examine quality, exceptions and recovery, rather than application availability alone. The service owner remains responsible for connecting technical commitments to the outcome the company needs.

The day after the review

Antoine distributes the log, reserves windows and checks owners’ capacity. Resolution discussions follow the rhythm of the action without waiting for the next monthly meeting. The sponsor is involved only when risk, capacity or the contract exceeds the normal mandate.

The next meeting begins with evidence for R-12 and new facts. If the test invalidated the hypothesis, the supplier states that clearly and proposes a different investigation. Credible management does not depend on every month being green; it depends on precise commitments, shared observations and the ability to correct an explanation that has become false.

Sources and method

Current official references illuminate performance and supplier-relationship concepts. The Sourcing Playbook consulted in 2026 is not presented as the text governing a French contract in 2019. The model, timings, thresholds and narrative responsibilities are original proposals to adapt to the contract and actual constraints.

Links verified on 4 October 2026. The scenarios and thresholds proposed in this dossier are educational; they describe neither a client engagement nor a result achieved by CYTIZEN.