The Firm About Petronus — the approach, the standards, and the people behind the work.
Vendor presenting an ID badge at a controlled access checkpoint beneath a Vendor Access Requirements sign

Specialized Domain

Vendor &
Contractor Oversight

Vendors enter through ordinary work: service calls, procedure support, construction activity, system access, equipment repair, and contracted operations. Petronus reviews whether that outside activity is authorized through a responsible sponsor, connected to the risks it creates, and closed on defensible evidence.

Current. Controlled. Defensible.

Operational Reality

Vendor presence becomes risk when it becomes access.

A representative supports a procedure. A contractor opens a ceiling. A technician enters a mechanical space. A software vendor touches clinical systems. None of that is unusual.

The governance question starts when ordinary work crosses into patient care, infrastructure, restricted access, or digital systems. At that point, the organization needs one connected pathway: who entered, who sponsored the access, and what risk the work carried.

01

Presence

An outside party enters the organization for a defined purpose.

02

Access

A named sponsor authorizes where the vendor may go and what may be touched.

03

Risk pathway

The work activates conditions that must be governed, verified, and closed with evidence.

Governance Turn

Presence is not the control. The pathway is: access, sponsor responsibility, risk, and closeout evidence connected as one record.

Vendor Governance Model

One vendor. One responsible sponsor. One risk pathway.

The schedule makes the pathway visible. A vendor enters through a named responsible sponsor, never “the organization.” The sponsor connects the outside party to the risk conditions created by the work.

The examples stay intentionally limited to the highest-risk pathways. Other vendor relationships follow the same logic.

The Vendorwho enters
Responsible Sponsorthe named role
Risk Pathwaywhat the work requires the sponsor to govern
Every vendor · on entry

The sponsor knows who entered and who authorized them. An unknown person in occupied space is the exposure itself.

Highest-risk pathways
Facilities contractor / utility vendor
Facilities / Project Lead

Physical Environment, Construction & Project Risk, ICRA / infection prevention, Interim Life Safety Measures, utilities, access, air, water, pressure, penetrations, and closeout evidence.

OR / procedural vendor representative
Surgical Services

Infection Prevention, Physical Environment, sterile field discipline, traffic, attire, credentialing, introduced equipment, privacy, supervision, and case-linked evidence.

IT / EHR / connected-device vendor
Information Technology

System access, privacy, cybersecurity coordination, device availability, change control, downtime readiness, failure response, and retained evidence.

Every vendor · on exit

Whatever the work disturbed, the sponsor is responsible for the finding-to-fix-to-record trail that closes it — and proves it closed.

What Petronus Reviews

For each vendor, Petronus tests one chain: a named sponsor authorized the access, the work stayed within that authorization, and the risks the work carried were governed and closed on a defensible record. The finding appears where a vendor is authorized, but no responsible party is accounting for the risk.

The Recurring Obligation

A vendor is
authorized once.
The risk must be
evaluated again.

Contracted services are not outside the organization’s governance structure. Joint Commission leadership standards require contracted care, treatment, and services to be provided safely and effectively. CMS holds the governing body accountable for services furnished under contract and expects contracted services to be addressed through the organization’s quality oversight structure.

Petronus recommends applying that discipline across the vendor population, not only to clinical contractors. The reason is simple: vendor risk is determined by the work performed, the space entered, and the systems affected — not by whether the contract is labeled clinical or non-clinical.

A utility contractor who disturbs air pressure near a surgical area, a software vendor who affects downtime readiness, or a facilities contractor who opens a ceiling can create patient-care exposure even when the contract itself is not clinical. Annual vendor evaluation gives leadership a recurring point to confirm that each relationship remains authorized, controlled, and defensible.

Leadership Output

The deliverable is the risk record.

Leadership receives the risk record: where vendor exposure is forming, where the evidence supports control, and what must be corrected next.

Priority risks

The vendor pathways most likely to create exposure: high-risk spaces, responsible sponsors, and work that triggers additional control requirements.

Evidence status

Where authorization, access evidence, service documentation, and closeout records align — and where the record does not support the control being presented.

Correction path

What must be assigned, restricted, corrected, or retained so the organization can defend the vendor pathway under leadership review, survey scrutiny, or post-event investigation.

The First Step

Start with a Risk Signal Assessment.

Every Vendor & Contractor Oversight engagement begins with a Risk Signal Assessment, a focused diagnostic review of the highest-risk requirements in the domain. Petronus tests the signal, identifies the exposure, and defines the correction path before risk becomes consequence.