Vendor security usually means a folder of returned questionnaires, a spreadsheet of contract dates, and a vague sense of which suppliers would actually hurt if they went down. The DPAs are in legal's drive, the sub-processor list is on someone's laptop, and when DORA or NIS2 asks for a register of ICT providers, you assemble it from scratch under deadline. The information exists; it just never lives in one place.
A supplier is not one risk, it is several at once. They hold your data, they sit in your recovery path, and they carry their own sub-processors behind them. Track those facts in separate tools and a contract change quietly breaks your GDPR position while your continuity plan still assumes the old setup. One record per vendor, linked to the assets and processes that depend on them, is the only way the picture stays straight.