Free policy template ISO 27001

Vendor & Third-Party Risk Policy

How you assess suppliers before granting access and set security expectations in agreements and on an ongoing basis.

Download the Markdown

Free and ungated, no email required. The full template is below and in the download. Authored in Keel's own words and mapped to ISO 27001 by clause; replace the {{PLACEHOLDER}} tokens with your details.

How to use it

  1. Download the template. Grab the Markdown file, or copy the full text from this page.
  2. Fill in the placeholders. Replace every {{PLACEHOLDER}} token (company name, owner, approver, dates, version) with your details.
  3. Tailor it to how you operate. Adjust the statements so they describe what your organization actually does. A policy you do not follow is worse than none.
  4. Approve and publish. Have an accountable owner approve it, set an effective date and a review date, and share it where staff can find it.
  5. Keep it current. Review on the schedule you set (or when things change), and keep evidence that it is followed. In Keel this is tracked for you.

Related

Vendor & Third-Party Risk

Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal


1. Purpose

Suppliers that touch our data or underpin our operations extend our risk beyond our own walls. This policy sets out how {{COMPANY_LEGAL_NAME}} evaluates, contracts with, and monitors third parties so that the security of {{DATA_TYPES}} is preserved wherever a vendor operates across {{GEO_SCOPE}}.

2. Scope

This covers every SaaS, cloud, consulting, and data-processing vendor we rely on, including any downstream suppliers that in turn support our services. Where a vendor processes personal information on our behalf, we remain accountable for it regardless of where the vendor is located.

3. Policy statements

3.1 Vendor inventory and tiering

We keep a central list of active vendors, each with a named owner and contact. Every vendor is tiered by the risk it carries: critical where the business cannot run without it, high where it handles customer or restricted data, medium for internal tools, and low where there is no data access. For vendors that process personal information, we record what data they hold, whether it crosses borders, and the safeguards applied.

3.2 Security due diligence

Before a critical or high-risk vendor is engaged, we obtain an independent assurance report or a completed security questionnaire and record our findings and approval decision. Medium-risk vendors warrant at least a basic questionnaire or a review of their published security posture. Where an independent report is not available, we collect alternate evidence (a certification, a penetration test summary, or a detailed questionnaire) and document a risk-based acceptance with compensating controls and a timeline to close the gap.

3.3 Contractual safeguards

Vendor contracts include confidentiality, breach-notification, right-to-audit, and data-return terms. Where a vendor processes personal information, we execute a data-processing agreement that limits use to documented purposes, requires equivalent protection for any subprocessors, obliges the vendor to notify us of incidents without undue delay, and requires the return or secure destruction of data at termination. Critical and high-tier vendors provide current assurance evidence annually.

3.4 Ongoing monitoring

We revisit the attestations or questionnaires of critical and high-risk vendors at least annually (more often for the most critical) and re-review after any material change, incident, ownership or hosting change, or scope change involving sensitive data. We watch for breach disclosures and regulatory actions affecting our vendors and open an assessment whenever an incident is reported.

3.5 Off-boarding and data return

When a contract ends, we confirm the vendor has returned or deleted our data and obtain written confirmation, ideally a certificate of destruction. Integrations, API keys, and OAuth tokens are revoked promptly, and we keep timestamps as evidence. Where a vendor used its own subcontractors to handle our data, we confirm those arrangements are terminated too.

3.6 Compliance measurement

We aim for every high-risk vendor to hold current due-diligence evidence, and we reconcile the vendor inventory each quarter. Missing evidence or expired contracts are surfaced for immediate action.

4. Roles and responsibilities

Role Responsibility
Executive sponsor Accountable for the program; approves this policy
{{POLICY_OWNER_ROLE}} Maintains this policy and its procedures
Managers Enforce the policy within their teams
All personnel Comply; report issues promptly

5. Compliance and exceptions

Missing evidence or expired contracts are flagged to procurement and security for immediate action. Urgent onboarding without full diligence is permitted only with executive sign-off, a short-term risk acceptance, compensating controls, and a plan to obtain the missing assurance within a defined window. Exceptions require documented risk acceptance by {{APPROVER_TITLE}} and are time-limited and reviewed.

6. Review

This policy is reviewed at least annually and when significant change occurs. Each review is a chance to streamline our questionnaire, add automation, and refine the tiering criteria based on what we have learned.


Aligned to ISO/IEC 27001:2022. {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by the relevant standards body; full standard text is copyrighted and is not reproduced here.

This template is authored by Keel in its own words. Clause references to ISO 27001 are factual identifiers; Keel is not affiliated with or endorsed by the standards bodies named. It is a starting point, not legal advice, review and adapt it for your organization.

Manage this policy in Keel

Keel ships this template in-product, fills the placeholders, maps it to your controls, and tracks approvals and reviews, so the policy stays live evidence, not a file in a drive. Start free.

Start free Browse all templates