Vendor risk management policy
**Document control**
| Field | Value | |---|---| | Organization | [COMPANY NAME] | | Policy owner | [OWNER NAME / ROLE] | | Approver | [APPROVER NAME / ROLE] | | Version | [VERSION] | | Effective date | [YYYY-MM-DD] | | Next review | [YYYY-MM-DD] |
**Mapped themes:** ISO/IEC 27001:2022 Annex A.5.19–A.5.23; SOC 2 vendor/risk themes (e.g. CC9.2 where used). GDPR Art. 28 / HIPAA BAA tracks are legal overlays — coordinate with counsel.
1. Purpose
This policy defines how [COMPANY NAME] identifies, assesses, contracts, and monitors suppliers that can affect the security of company or customer information.
2. Scope
Applies to vendors and subprocessors that process, store, or can access in-scope data or that provide critical availability dependencies for in-scope services.
3. Tiering (customize)
| Tier | Criteria (examples) | Diligence | |---|---|---| | Critical | Customer data access or production dependency | Security review + assurance report / questionnaire + contract security terms | | High | Sensitive internal data or material availability impact | Questionnaire + contract terms | | Low | No sensitive data; replaceable | Lightweight review / terms check |
4. Policy statements
- A vendor inventory lists in-scope suppliers with tier, owner, and data types.
- New Critical/High vendors complete security diligence before production use proportionate to tier.
- Agreements for Critical/High vendors address security, incident notice, and data return/deletion as applicable.
- Critical vendors are re-reviewed at least annually or after material incidents/changes.
- Shadow IT discovered in use is inventoried and brought into this process or removed.
- Cloud shared-responsibility notes are documented for material infrastructure providers.
5. Related documents
Information security policy; Privacy / DPA playbook [LINK]; Incident response policy.
---
**Disclaimer:** Educational template only — not legal advice. Processor/BAA language requires counsel. ComplianceBase is vendor-neutral and independent.