A Practical Vendor Risk Register for Game Art Outsourcing
-
Written byDenys Zadoienyi
-
Updated on14.08.2026
-
Time to read13 min
- Definition: what a vendor risk register actually is
- Why generic vendor risk frameworks don’t fit game art
- The vendor risk register: four risks, tracked and controlled
- Single-vendor dependency: the risk nobody budgets for until it happens
- Vendor-side staff turnover: a real risk, not a hypothetical one
- Missed deadlines: catching the signal before the deadline itself
- Style drift: why this risk gets a short answer here
- How this differs from choosing a vendor in the first place
- Setting this up without over-building it
- A note on where this fits in the contract itself
- Comparable engagements
- How we approach this at Nasty Rodent
Vendor risk management in game art outsourcing usually gets skipped for the same reason seatbelts get skipped on a five-minute drive: nothing has gone wrong yet, so the extra step feels unnecessary. Then the vendor’s lead artist leaves mid-milestone, or the studio you depend on for every character asset takes on a bigger client and your project quietly slides down their priority list, and the absence of a plan becomes the most expensive part of the engagement.

“Editorial illustration created for visual reference purposes. It does not represent a real project, client work, or official software screenshot unless stated otherwise.”
None of the risks below are exotic. They’re the same handful of things that go wrong in most outsourcing relationships, in any industry – concentration, turnover, schedule slip, quality drift. What’s missing in most game art outsourcing engagements isn’t awareness that these risks exist. It’s a written register that names them before signing, rates how likely and how damaging each one actually is for your specific engagement, and assigns a control mechanism to each one instead of hoping the vendor relationship just works out.
Definition: what a vendor risk register actually is
A vendor risk register is a short, working document – not a compliance exercise – that lists the specific ways an outsourcing engagement can go wrong, notes when each risk’s exposure is highest for your production, and names the concrete control that reduces it. This isn’t a complete enterprise vendor-risk framework covering every category a corporate procurement team tracks – financial due diligence, data security, regulatory exposure, and IP terms are real risk categories too, and largely belong in the RFP evaluation and SOW and governing contract language rather than in this register. What follows is a production-delivery register: four recurring risks that most directly determine whether outsourced game art actually ships on schedule and on style.
Why generic vendor risk frameworks don’t fit game art
Most vendor risk management content online is written for IT procurement – cloud providers, SaaS vendors, data processors. It’s built around categories like regulatory exposure, data breach liability, and financial viability reviews. Some of that transfers to game art outsourcing; financial instability at a vendor is a real risk, for instance, and belongs in RFP-stage due diligence. Most of the generic framework doesn’t transfer well, and importing it wholesale produces a document nobody actually uses, because half the rows don’t apply to a creative production pipeline and the rows that do apply get one generic line instead of the specific mechanism a producer or vendor manager needs.
Game art outsourcing has its own risk shape on the delivery side. For producers managing day-to-day production, the most visible failure modes are often not abstract financial ratios but operational breakdowns: a style guide drifting across forty assets because nobody defined a source of truth, or a lead artist leaving three weeks before a milestone with no documented handoff. This register starts from those delivery failure modes.
The vendor risk register: four risks, tracked and controlled
The table below is the working structure. “When Exposure Is Highest” describes the production conditions that raise each risk, not a statistical probability – there’s no dataset behind these ratings, and the register should be filled in against your specific engagement rather than treated as a universal scorecard.
| Risk | When Exposure Is Highest | Early-Warning Signal | Primary Control | Typical Owner |
| Single-vendor dependency | Multi-year engagements where one vendor owns a critical asset category and no transition package exists | Vendor mentions capacity strain, a new large client, or ownership/leadership change | Documented exit plan (source-file format, style guide ownership, realistic transition timeline) before signing; dual-sourcing for critical categories on high-stakes engagements | Producer / vendor manager |
| Vendor-side staff turnover | Industry-wide hiring booms or layoff cycles; engagements depending on one named senior artist | Vendor slower to confirm a specific artist’s continued involvement; a style guide that hasn’t been re-confirmed after a milestone gap | Staffing bench depth confirmed for the specific discipline and seniority before signing; documentation robust enough to survive a personnel change | Producer / vendor manager |
| Missed deadlines | Multi-milestone engagements with tight downstream dependencies (QA, publishing, marketing) | A milestone check-in pushed back; feedback arriving without a clear resolution plan; capacity commitments made without a visible resourcing plan | Milestone buffer, capacity validation before commitment, intermediate acceptance gates, and a written recovery-plan trigger at the first missed check-in – buffer alone only absorbs impact, it doesn’t address the causes below it | Producer |
| Style drift | Rising asset count, multiple artists on the vendor’s side, or more than one vendor working to the same visual target | New deliveries pass individual review but read as inconsistent side by side with earlier milestones | The full governance system – documented visual target, review gates, named reviewer – covered in depth in our guide to visual consistency across an AAA pipeline; the short version here is a single source of truth and a named reviewer checking every milestone, not just final delivery | Art director |
Two of these risks compound: a vendor losing a key artist (turnover) is often what triggers a missed deadline, and a rushed replacement hire is a common cause of style drift showing up mid-project. The register works best read as a set of connected risks, not four independent boxes.
Single-vendor dependency: the risk nobody budgets for until it happens
Depending on one studio for a large share of a production’s art output is efficient – one point of contact, one style guide to maintain, one relationship to manage. It’s also the risk with the most severe downside of the four: if that vendor becomes unavailable – financial trouble, a larger client absorbing their capacity, a dispute that ends the relationship – the affected asset pipeline can slow sharply or stop altogether, depending on how much scope and undocumented knowledge sit with that studio.

“Editorial illustration created for visual reference purposes. It does not represent a real project, client work, or official software screenshot unless stated otherwise.”
The control isn’t necessarily “always use two vendors.” For a short, single-milestone engagement, dual-sourcing adds coordination overhead that isn’t worth the risk it prevents. The control that matters at any engagement length is a documented exit plan: what format asset source files need to be delivered in, who owns the style guide documentation, and how long a transition to a new vendor would realistically take mid-project. This is exactly what a well-drafted SOW’s termination section is for – our RFP and SOW guide covers the specific termination-for-cause, termination-for-convenience, and kill-fee language that turns “we should have an exit plan” into an enforceable clause. Many teams don’t formalize this until a transition is already underway – at which point it’s a negotiation happening under pressure instead of a plan made in advance.
For longer, higher-stakes engagements – a multi-year live-service title, a AAA production with hundreds of assets riding on one vendor – dual-sourcing critical categories (splitting characters and environments between two studios, for example) is the more defensible control, even at the cost of an extra relationship to manage.
Vendor-side staff turnover: a real risk, not a hypothetical one
It’s tempting to treat vendor staff turnover as the outsourcing partner’s internal problem, invisible from the client side until it isn’t. It isn’t invisible if you ask the right question before signing, and it isn’t hypothetical – the game industry has been through a genuinely volatile few years on the employment side. GDC’s 2026 State of the Game Industry report found that 28% of respondents had personally been laid off in the past two years; among respondents specifically at AAA studios, two-thirds said their companies had conducted layoffs in that window. Those are two different measures of the same underlying volatility, but both point the same direction: staffing at any studio, including an outsourcing vendor, is less stable than a portfolio review alone would suggest. That volatility runs in both directions for a vendor – layoffs can thin a bench, and a hiring boom at a larger studio can pull senior artists away mid-engagement.
The control isn’t asking a vendor to guarantee zero turnover – no studio can promise that honestly. It’s asking, before signing, how deep their staffing bench actually is for the specific discipline and seniority level your project needs – a general headcount number doesn’t help if what you need is a senior character artist and the available bench is environment generalists – and confirming that style guides and reference material are documented well enough that a new artist can pick up the work without a multi-week ramp-up eating into your milestone buffer. A vendor that answers this concretely, with a specific process rather than a reassurance, is telling you something real about how they’ve built their production pipeline.

“Editorial illustration created for visual reference purposes. It does not represent a real project, client work, or official software screenshot unless stated otherwise.”
Missed deadlines: catching the signal before the deadline itself
By the time a deadline is actually missed, the useful window for controlling the risk has already closed – what’s left is damage control. The control that works is watching for the signals that precede a missed deadline: a milestone check-in that gets pushed back, feedback that arrives without a clear resolution plan, or a pattern of responses arriving near the limit of the agreed SLA window rather than comfortably within it – especially when combined with delayed check-ins or unresolved production questions elsewhere. How that SLA window gets defined in the first place is its own topic; the point here is treating a pattern of near-limit responses as a signal worth acting on, not proof of a problem on its own.
Each of those signals, alone, isn’t a crisis. As a pattern across two or three consecutive check-ins, it’s the point where a written recovery plan – a specific adjustment to timeline, resourcing, or scope for that milestone – still has room to change the outcome. A clear escalation chain makes that response concrete instead of ad hoc: first missed check-in triggers a written recovery plan from the vendor; a second miss on the same milestone escalates to a named senior contact on both sides; if the pattern continues, the conversation moves to the transition provisions already defined in the exit plan above, rather than being negotiated for the first time under deadline pressure.
Buffer time absorbs the impact of a slip once it’s already happening – it’s necessary but not sufficient on its own. The causes underneath a missed deadline are usually one of: the vendor took on more capacity than they had available, acceptance criteria weren’t specific enough to avoid a late-stage rejection, or a dependency on another team (yours or a second vendor’s) wasn’t mapped before the milestone was scheduled. Capacity validation before committing to a date, intermediate acceptance gates instead of one review at the end, and clear scope-change rules address the causes; buffer just gives you room to recover once they’ve happened anyway.
Style drift: why this risk gets a short answer here
Style drift is the quietest risk on this list, because it doesn’t announce itself the way a missed deadline does – it accumulates asset by asset until an art director notices that character forty doesn’t quite match the visual target character three nailed.

“Editorial illustration created for visual reference purposes. It does not represent a real project, client work, or official software screenshot unless stated otherwise.”
The full control system for this – documented visual targets, review gates at specific production checkpoints, ownership rules for when more than one vendor works to the same target – is enough of a topic that it has its own dedicated guide on this site: visual consistency across an AAA production pipeline. For the purposes of this register, the short version is the control that matters: one documented visual target as the source of truth, and a named reviewer checking new deliveries against it at every milestone, not only at final delivery when a full-batch correction is the only option left.
How this differs from choosing a vendor in the first place
It’s worth being direct about what this register is not. Deciding whether to hire a freelance artist, build in-house, or outsource to a studio is a different question, answered before a contract exists, weighing cost structure and operational fit against your production’s specific needs. This register assumes that decision is already made – you’ve chosen to outsource to a studio – and addresses a different question: now that the relationship exists, what can go wrong inside it, and what controls each of those risks for as long as the engagement runs.
Setting this up without over-building it
A full risk register with a governance meeting attached makes sense for a multi-year AAA engagement with hundreds of assets riding on one vendor relationship. It’s overkill for a two-week concept art batch. The right-sized version scales with engagement length and how much production depends on a single vendor relationship, not with contract value alone.
What doesn’t scale down, even for a short engagement: knowing before signing what happens if the vendor becomes unavailable mid-project, and having a style guide documented well enough that it survives a personnel change on either side. Both are far less expensive to formalize in advance than to reconstruct during an active transition – and those two gaps, left unaddressed, cause the most expensive kind of surprise: the kind that shows up mid-milestone with no plan already in place to handle it.
A note on where this fits in the contract itself
Build the first version of this register between vendor selection and contract signature, then maintain it through delivery – it’s a working document for your own production planning, not a substitute for the contract language that gives the risks legal weight. An RFP is a pre-selection document: it’s where you test a vendor’s staffing depth, revision policy, and process maturity before choosing them, but it doesn’t itself govern the engagement. That’s the role of the SOW, typically under or alongside an MSA – our RFP and SOW guide covers the specific exit, IP handoff, and milestone-remedy clauses that make the risks in this register enforceable rather than just documented. The register tells you what to test in the RFP and what to formalize in the SOW; the signed agreement is what makes it stick.
Comparable engagements
Long-running engagements are where this register earns its keep. Our work with The Bearded Ladies on Miasma Chronicles, published by 505 Games, involved delivering weapons, props, and environment assets to the project’s technical and visual standards – the kind of vendor relationship where dependency and style-drift risk are worth planning for in advance, not discovering mid-production.
How we approach this at Nasty Rodent
Nasty Rodent structures engagements with a documented style guide as the source of truth from the first milestone, a named point of contact who owns quality outcomes, and a staffing model built to absorb artist rotation without a project stopping. If vendor dependency or turnover risk is part of what’s holding your outsource decision back, we run a free vendor capability assessment against your brief or RFP: within 48 hours, a read on staffing depth, realistic risk profile, and the controls worth building into the contract before you sign – no obligation attached.
Send your brief to nastyrodent.com/services → Send Request, or book a call directly with our production team to talk through the specific risk profile of your engagement.