# Vendor / Third-Party Management Policy

> **Template — adapt before use.** Replace `[bracketed]` placeholders and have an owner approve it. Not legal or compliance advice.

| | |
|---|---|
| **Owner** | [Role] | **Approved** | [YYYY-MM-DD] | **Review** | Annual | **Version** | 1.0 |

Maps to: ISO 27001 A.5.19–5.23 · SOC 2 CC9.2 · PCI DSS Req 12.8 · HIPAA §164.308(b).

## 1. Purpose & scope
Governs how [Company Name] selects, assesses, contracts with, and monitors third parties that handle company or customer data or provide critical services.

## 2. Risk tiering
Classify each vendor by the sensitivity of data they access and their criticality:
| Tier | Criteria | Diligence |
|---|---|---|
| Critical | Handles sensitive/customer data or is business-critical | Full security review + contract + annual re-review |
| Moderate | Limited data access | Questionnaire + contract |
| Low | No sensitive data | Basic checks |

## 3. Onboarding diligence
- Security review proportional to tier (e.g. SOC 2 report, ISO cert, security questionnaire).
- Contract with appropriate clauses: confidentiality, security obligations, breach notification, and a DPA where personal data is processed.
- For card data: confirm the vendor's PCI DSS status and document responsibilities (Req 12.8.5).

## 4. Ongoing monitoring
- Maintain a current vendor inventory with tier, data accessed, owner, and contract/review dates.
- Re-review critical vendors at least annually (refresh attestations, review incidents).
- Reassess on material change (new data access, breach, ownership change).

## 5. Offboarding
On termination, revoke access, confirm return/deletion of data, and record the closure.

## Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | [YYYY-MM-DD] | [Name] | Initial issue |
