Vendor & Third-Party Risk
Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal
1. Purpose
Suppliers that touch our data or underpin our operations extend our risk beyond our own walls. This policy sets out how {{COMPANY_LEGAL_NAME}} evaluates, contracts with, and monitors third parties so that the security of {{DATA_TYPES}} is preserved wherever a vendor operates across {{GEO_SCOPE}}.
2. Scope
This covers every SaaS, cloud, consulting, and data-processing vendor we rely on, including any downstream suppliers that in turn support our services. Where a vendor processes personal information on our behalf, we remain accountable for it regardless of where the vendor is located.
3. Policy statements
3.1 Vendor inventory and tiering
We keep a central list of active vendors, each with a named owner and contact. Every vendor is tiered by the risk it carries: critical where the business cannot run without it, high where it handles customer or restricted data, medium for internal tools, and low where there is no data access. For vendors that process personal information, we record what data they hold, whether it crosses borders, and the safeguards applied.
3.2 Security due diligence
Before a critical or high-risk vendor is engaged, we obtain an independent assurance report or a completed security questionnaire and record our findings and approval decision. Medium-risk vendors warrant at least a basic questionnaire or a review of their published security posture. Where an independent report is not available, we collect alternate evidence (a certification, a penetration test summary, or a detailed questionnaire) and document a risk-based acceptance with compensating controls and a timeline to close the gap.
3.3 Contractual safeguards
Vendor contracts include confidentiality, breach-notification, right-to-audit, and data-return terms. Where a vendor processes personal information, we execute a data-processing agreement that limits use to documented purposes, requires equivalent protection for any subprocessors, obliges the vendor to notify us of incidents without undue delay, and requires the return or secure destruction of data at termination. Critical and high-tier vendors provide current assurance evidence annually.
3.4 Ongoing monitoring
We revisit the attestations or questionnaires of critical and high-risk vendors at least annually (more often for the most critical) and re-review after any material change, incident, ownership or hosting change, or scope change involving sensitive data. We watch for breach disclosures and regulatory actions affecting our vendors and open an assessment whenever an incident is reported.
3.5 Off-boarding and data return
When a contract ends, we confirm the vendor has returned or deleted our data and obtain written confirmation, ideally a certificate of destruction. Integrations, API keys, and OAuth tokens are revoked promptly, and we keep timestamps as evidence. Where a vendor used its own subcontractors to handle our data, we confirm those arrangements are terminated too.
3.6 Compliance measurement
We aim for every high-risk vendor to hold current due-diligence evidence, and we reconcile the vendor inventory each quarter. Missing evidence or expired contracts are surfaced for immediate action.
4. Roles and responsibilities
| Role | Responsibility |
|---|---|
| Executive sponsor | Accountable for the program; approves this policy |
| {{POLICY_OWNER_ROLE}} | Maintains this policy and its procedures |
| Managers | Enforce the policy within their teams |
| All personnel | Comply; report issues promptly |
5. Compliance and exceptions
Missing evidence or expired contracts are flagged to procurement and security for immediate action. Urgent onboarding without full diligence is permitted only with executive sign-off, a short-term risk acceptance, compensating controls, and a plan to obtain the missing assurance within a defined window. Exceptions require documented risk acceptance by {{APPROVER_TITLE}} and are time-limited and reviewed.
6. Review
This policy is reviewed at least annually and when significant change occurs. Each review is a chance to streamline our questionnaire, add automation, and refine the tiering criteria based on what we have learned.
Aligned to ISO/IEC 27001:2022. {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by the relevant standards body; full standard text is copyrighted and is not reproduced here.