Skip to content
compliancebase

Vendor risk management policy template

SaaS vendor / supplier security policy template for tiering, diligence, and reviews — maps to ISO A.5.19–A.5.22 themes.

Download .docx

Vendor risk management policy

**Document control**

| Field | Value | |---|---| | Organization | [COMPANY NAME] | | Policy owner | [OWNER NAME / ROLE] | | Approver | [APPROVER NAME / ROLE] | | Version | [VERSION] | | Effective date | [YYYY-MM-DD] | | Next review | [YYYY-MM-DD] |

**Mapped themes:** ISO/IEC 27001:2022 Annex A.5.19–A.5.23; SOC 2 vendor/risk themes (e.g. CC9.2 where used). GDPR Art. 28 / HIPAA BAA tracks are legal overlays — coordinate with counsel.

1. Purpose

This policy defines how [COMPANY NAME] identifies, assesses, contracts, and monitors suppliers that can affect the security of company or customer information.

2. Scope

Applies to vendors and subprocessors that process, store, or can access in-scope data or that provide critical availability dependencies for in-scope services.

3. Tiering (customize)

| Tier | Criteria (examples) | Diligence | |---|---|---| | Critical | Customer data access or production dependency | Security review + assurance report / questionnaire + contract security terms | | High | Sensitive internal data or material availability impact | Questionnaire + contract terms | | Low | No sensitive data; replaceable | Lightweight review / terms check |

4. Policy statements

  • A vendor inventory lists in-scope suppliers with tier, owner, and data types.
  • New Critical/High vendors complete security diligence before production use proportionate to tier.
  • Agreements for Critical/High vendors address security, incident notice, and data return/deletion as applicable.
  • Critical vendors are re-reviewed at least annually or after material incidents/changes.
  • Shadow IT discovered in use is inventoried and brought into this process or removed.
  • Cloud shared-responsibility notes are documented for material infrastructure providers.

5. Related documents

Information security policy; Privacy / DPA playbook [LINK]; Incident response policy.

---

**Disclaimer:** Educational template only — not legal advice. Processor/BAA language requires counsel. ComplianceBase is vendor-neutral and independent.

Framework versions referenced in this page:

Last verified: July 2026 · Primary sources linked above