Most organisations believe vendor risk is managed through audits, but in reality the level of risk is often locked in much earlier, before QA is even involved. Across preclinical, clinical, and CSV environments, a consistent pattern is emerging: vendors are selected under operational pressure, and audits are carried out later as a formality rather than a true decision point. At that stage, the question is no longer whether the vendor is appropriate, but how to make the situation work. This article challenges the assumption that audits are a control mechanism and reframes them as feedback on decisions that have already been made. It introduces the idea that vendor oversight is fundamentally a decision-making problem, not an auditing problem, and sets the stage for exploring how organisations can take a more deliberate, risk-based approach to choosing when and how they assess their vendors.