A vendor list that lives in one person's inbox is not a roster. It is a memory with a backup problem.
A real roster is one shared record of every vendor, every document they owe, and where each one stands, maintained as part of the work rather than reconstructed before each audit. Here is how to build one from a typical starting point: a certificate folder, a contract drawer, and an accounts payable report.
Step 1: Decide who belongs on it
Pull two years of accounts payable. Every payee is a candidate, but not every payee is a vendor for compliance purposes. The one-time speaker fee and the utility company do not owe you certificates. The rule of thumb: anyone who performs work, enters your property or public spaces, or could create liability for you belongs on the roster. When in doubt, include them with minimal requirements rather than leaving them off.
Step 2: Set requirements by category, not by vendor
Requirements set vendor-by-vendor drift into inconsistency, and inconsistency is what an aggrieved bidder or an auditor notices. Set them by category instead: construction contractors owe one document set, professional services another, suppliers a third. Write the categories down with their document lists. Then assigning a new vendor is a one-word decision, and the requirements follow automatically.
This is also where you apply the most useful filter in the whole exercise: only require documents the vendor actually holds or can obtain. A requirement no vendor can satisfy produces permanent chasing and no protection.
Step 3: Structure the record
One row per vendor per required document. Columns: vendor, category, document, expiration or renewal date, status, owner, last contact date. Resist adding more columns at the start; every extra field is maintenance, and a roster dies of maintenance before it dies of missing data.
Two entries deserve special care. Record the vendor's primary contact and, separately, the document source if papers come from an insurance agent or broker; requests go to the vendor, copies go to the agent, and a reply from either counts. And record the exact legal entity name that should appear on insurance paperwork, because "close enough" entity names are where certificates quietly go wrong.
Step 4: Set the cadence
Requests go out 45 to 60 days before expiration. Follow up on silence at 14 days, again at 7. After the second follow-up, the item goes to a person as an exception rather than getting a tenth identical email. Log every touch in the last-contact column as you go. A cadence that depends on someone remembering to run it is not a cadence; put the review on a recurring calendar slot, monthly at minimum.
Step 5: Keep it alive at the front door
Rosters do not decay from neglect of old rows. They decay at the front door, when new vendors start work before their documents were requested. The fix is procedural: the roster entry is created at contract signing, and the first document request goes out the same week. If your office signs the contract, your office holds the trigger.
The test of a working roster
You should be able to answer three questions in under a minute, on any day, without research: which documents expire in the next 60 days, which vendors have gone silent past your follow-up window, and when you last contacted any given vendor. If the roster answers those, it is working. If answering them requires opening six files, you have a records collection, not a roster.