Third-Party Security Policy
States the mandatory security requirements applying to supplier selection, contracting, monitoring and termination.
Available soon
- Format
- Word
- Size
- 52 KB
- Length
- 11 pages
- Version
- 1.0
- Updated
What's inside
- Purpose
- Scope
- Policy statements
- Roles and responsibilities
- Compliance and consequences
- Exceptions
- Related documents
- Definitions
- Document control
- Adapting this template
- Framework references
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
Purpose
This policy sets out how [[Organisation Name]] manages the information security risk that comes from its suppliers, so that the services, systems and data it entrusts to others are protected to the same standard as its own, and so that it can show customers, auditors and regulators that it knows which suppliers it depends on and how well they are protected. It applies the effort in proportion to each supplier's criticality: most assessment effort goes to the few suppliers the organisation could not do without.
Scope
This policy applies to:
- Suppliers: every third party that provides [[Organisation Name]] with a product or service, including cloud and software-as-a-service providers, managed IT and security service providers, processors of personal data, outsourced business services, logistics and other operational partners, and their subcontractors where they deliver part of the service to us.
- Stages: selection, contracting, renewal, changes to the service, monitoring during the contract, and exit.
- People: everyone who selects, buys, contracts with, manages or relies on a supplier, and the roles named in this policy.
Excluded: [[anything deliberately left out, and where it is covered instead, e.g. intra-group services covered by the group's own policy — or "None"]]. A supplier with no service dependency, no access and no data is still screened at intake (TP-01); the screening places it in the lowest tier, where no further assessment is needed.
Guidance — delete before approval
Keep the scope wide and let the tier do the work. A narrow scope ("IT suppliers only") misses the payroll bureau, the contact centre and the logistics partner that hold your customers' data. Screening every supplier takes a few minutes for a supplier that turns out to be Tier 4.
Policy statements
The Supplier Criticality & Tiering Model sets the criteria, overrides, questionnaire sets, evidence and reassessment intervals the statements refer to; the Supplier Security Assessment Procedure sets the steps.
Selection and tiering
TP-01 No supplier may be engaged, and no contract renewed, until intake screening is done and a tier is recorded.
Evidence: an intake record and a tier for every supplier in the Supplier Security Risk Register, dated before its contract or renewal was signed.
TP-02 The tier must be the highest any criterion reaches, and never below an override's minimum.
Evidence: the criteria scores and any override recorded with each tier, as the Supplier Criticality & Tiering Model sets them.
Assessment and decision
TP-03 Each supplier must be sent the questionnaire set and evidence request for its tier, and never a set above it.
Evidence: the questionnaire set issued, from the Tiered Supplier Security Questionnaire, matching the supplier's tier.
TP-04 Evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy.
Evidence: the Supplier Due Diligence Evidence Checklist, completed for each assessment, showing scope, dates and supplier name checked.
TP-05 Every assessment must end in a documented decision (Approve, Approve with conditions, Escalate, Reject), signed by the business owner.
Evidence: a signed decision in each Supplier Security Review Report Template.
TP-06 Residual supplier risk must be scored on the P05 scale; a supplier outside appetite must be entered in the risk register.
Evidence: the residual score and band on every assessment; for a supplier outside appetite, its entry in the Information Security Risk Register.
Contracting
TP-07 Contracts must carry the security clauses for the supplier's tier and data type before they are signed.
Evidence: the clauses selected from the Supplier Contract Security Clause Library for the tier and data type, in the signed contract.
Monitoring
TP-08 Every finding must have an owner and a deadline set by its severity; a High finding past its deadline must be escalated to the business owner.
Evidence: an owner and a deadline on every open finding; for each High finding past its deadline, the record that the business owner was told.
TP-09 Suppliers must be reassessed within their tier's interval, and on any material change, incident or breach at the supplier.
Evidence: the last assessment date and the next due date in the register, and a reassessment record after each material change, incident or breach.
Incidents and continuity
TP-10 Critical suppliers must be part of incident response and continuity plans, with named contacts and notification duties.
Evidence: named supplier contacts and notification duties in the incident response and continuity plans for every Tier 1 (Critical) supplier.
Exit
TP-11 Every Tier 1 and Tier 2 contract must have an exit plan: data return or deletion, access removal, and a transition period.
Evidence: an exit plan for every Tier 1 and Tier 2 contract; at exit, a record of data returned or deleted and access removed.
Reporting
TP-12 Coverage, overdue reviews, open findings and concentration must be reported to executive management every quarter.
Evidence: the quarterly report to executive management, with TPM-01, TPM-02, TPM-03, TPM-04.
Guidance — delete before approval
The statements keep the rule IDs TP-01 to TP-12 that every document in the Third-Party Security Risk Management pack cites. Do not renumber them. If you remove one, keep its number and mark it "Withdrawn in version x.y", so records that cite it still point to the right text.
The tiers are Tier 1 (Critical), Tier 2 (Important), Tier 3 (Standard), Tier 4 (Minimal). The overrides set a minimum tier whatever the criteria say: an ICT service supporting a critical or important function of a DORA financial entity is at least Tier 1; a processor of personal data under GDPR Article 28 is at least Tier 2. They belong in the Supplier Criticality & Tiering Model, not here, so they can change without a new policy version.
Roles and responsibilities
Role | Responsibilities under this policy |
|---|---|
Executive management [[e.g. Executive Committee]] | Approves this policy; receives the quarterly report (TP-12); decides on supplier risks escalated to it and on exits from Tier 1 suppliers. |
Business owner [[the manager who buys and relies on the service]] | Raises the intake before engaging or renewing a supplier (TP-01); signs the assessment decision (TP-05); owns the supplier's findings and is told of High findings past deadline (TP-08); keeps the exit plan current (TP-11). |
Procurement [[e.g. Procurement Manager]] | Makes sure no contract or renewal is signed without a tier (TP-01) and the tier's clauses (TP-07); tells the assessor of renewals and changes to a service (TP-09). |
Assessor [[e.g. Information Security Manager]] | Tiers suppliers (TP-02); sends questionnaires and validates evidence (TP-03, TP-04); records findings and residual risk (TP-06, TP-08); keeps the register and reassessment dates (TP-09). |
Head of Information Security [[e.g. Head of Information Security or CISO]] | Owns this policy; settles disputed tiers and ratings; makes sure critical suppliers are in the incident response and continuity plans (TP-10); prepares the quarterly report (TP-12). |
Legal [[in-house or external counsel]] | Keeps the clause library current and approves changes to its clauses in a contract (TP-07). |
Data Protection Officer [[where one is appointed]] | Advises on suppliers that process personal data, and on the processor terms in their contracts. |
Suppliers | Answer the questionnaire and provide evidence for their tier; meet their contract's security clauses; notify incidents and material changes as their contract requires. |
Guidance — delete before approval
Replace each [[example]] with the role that does it in your organisation. The business owner is the manager who buys and relies on the service, not the security team: the security team advises, the business owner decides and signs (TP-05).
Compliance and consequences
How compliance is checked. The Head of Information Security checks compliance with this policy every quarter: by comparing the contracts signed or renewed in the quarter with the intake and tier records in the Supplier Security Risk Register (TP-01, TP-07); by checking assessments and reassessments against their due dates (TP-09); and by checking findings against their deadlines (TP-08). [[Internal audit]] tests a sample of [[5]] supplier files [[every year]]. The results are reported to executive management every quarter (TP-12) with these measures:
Measure | Target |
|---|---|
TPM-01 Tier 1 suppliers assessed | All Tier 1 by [[year end]] |
TPM-02 Reassessments overdue | Zero Tier 1; none more than 90 days overdue |
TPM-03 High findings past deadline | Zero |
TPM-04 Concentration | Each one known, with an exit plan (TP-11) |
Consequences of not complying. A supplier engaged without intake and a tier, or a contract signed without the clauses for its tier, is reported to [[executive management]] and assessed at once; [[no further orders are placed until the assessment is complete]]. Staff who do not follow this policy may face action under the [[disciplinary procedure]]. For a supplier, not meeting the security clauses of its contract is a breach of that contract, handled under its terms.
Guidance — delete before approval
EXAMPLE, from the example organisation used across the pack (a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders), as at 30 Sept 2026: TPM-01 stands at 9 of 14 Tier 1 suppliers assessed in the last 12 months — the board measure "critical suppliers assessed" in the Board Cybersecurity Reporting pack. TPM-03 stands at 1: finding F-01 at SUP-004, due 20 Jul 2026, is still open, so the business owner has been told (TP-08). Replace these with your own figures, as at the date of your report.
Exceptions
Any deviation from this policy must be requested, assessed and approved under the Security Exception & Waiver Standard [[document ID]], using the Security Exception Request & Approval Form, before the deviation begins. An exception is time-limited and recorded in the Security Exception Register. Agreement by email, in a meeting or by a manager is not an exception.
An exception is for a rule that cannot be met — for example, a Tier 1 supplier that will not accept a clause its tier requires. A supplier whose residual risk is outside appetite is not an exception: it is escalated and entered in the Information Security Risk Register (TP-06). Where an exception leaves a supplier risk outside appetite, or scored Critical, the approver the Information Security Risk Management pack requires for that position also signs the exception: the stricter of the two always applies.
Guidance — delete before approval
Keep the first paragraph as it is; change only the document reference. Suppliers that refuse a clause are the most common source of exceptions: record each one, with its expiry date, rather than accepting the refusal informally at signature.
Related documents
Document | Relationship |
|---|---|
Supplier Security Assessment Procedure | The steps that carry out TP-01 to TP-11, for each tier |
Supplier Criticality & Tiering Model | The criteria, overrides, questionnaire sets, evidence and reassessment intervals (TP-02, TP-03, TP-09) |
Tiered Supplier Security Questionnaire | The questionnaire set for each tier (TP-03) |
Supplier Due Diligence Evidence Checklist | What evidence to ask for, and how to validate it (TP-04) |
Supplier Contract Security Clause Library | The security clauses for each tier and data type (TP-07, TP-10, TP-11) |
Supplier Security Risk Register | Every supplier's tier, decision, residual risk, findings and next reassessment (TP-01, TP-08, TP-09) |
Supplier Security Review Report Template | The record of one assessment and its signed decision (TP-05) |
Third-Party Risk Dashboard | The quarterly report to executive management (TP-12) |
Risk Assessment Methodology & Scoring Model; Information Security Risk Register | The scale supplier risk is scored on, and where a supplier outside appetite is recorded (TP-06); Information Security Risk Management pack |
Security Exception & Waiver Standard | The route for every exception to this policy; Security Exception, Waiver & Segregation of Duties pack |
[[Information Security Policy]] | [[Parent policy]] |
[[Incident management policy; business continuity plan]] | [[Where critical suppliers' contacts and duties are recorded (TP-10)]] |
Definitions
Term | Meaning in this policy |
|---|---|
Supplier | Any third party that provides the organisation with a product or service, including its subcontractors for that service. |
Tier | One of four levels of supplier criticality — Tier 1 (Critical), Tier 2 (Important), Tier 3 (Standard), Tier 4 (Minimal) — set by the Supplier Criticality & Tiering Model. |
Intake screening | The short set of questions about a supplier's service, data and access that sets its tier. |
Critical or important function | Under DORA, a function whose disruption would materially impair a financial entity's performance, soundness or continuity of services, or its compliance. |
Processor | Under the GDPR, a party that processes personal data on the organisation's behalf. |
Finding | A gap found in an assessment, with a severity (High, Medium or Low) that sets its remediation deadline. |
P05 scale | The 4 × 4 impact × likelihood scale and its four bands in the Risk Assessment Methodology & Scoring Model (Information Security Risk Management pack, P05). A supplier's residual score is compared with the organisation's appetite for third-party risk. |
Residual risk | The supplier risk left with the supplier's and our own controls in place, scored on the Information Security Risk Management pack's scale. |
Material change | A change in what the supplier does for us, the data or access it has, its ownership, its location or its subcontractors that could change its tier or risk. |
Exit plan | How data is returned or deleted, access removed and the service moved when a contract ends (TP-11). |
Concentration | Dependence of two or more critical services on one provider (TPM-04). |
Document control
Approval record
Version | Approved by | Date | Evidence of approval | Next review by |
|---|---|---|---|---|
[[1.0]] | [[Executive management (the management body, or its delegate for the top policy)]] | [[YYYY-MM-DD]] | [[e.g. minutes of meeting, reference and item]] | [[YYYY-MM-DD]] |
Review. This policy is reviewed at least every 12 months, and sooner after: a major incident, or an incident the document should have prevented; a material change to the organisation's activities, systems or suppliers; a change in law, regulation or a contract the document supports; an audit or assessment finding against the document; a significant change in the threats the document addresses. The revision history is at the front of this document.
Publication. The current approved version is published at [[location everyone in scope can reach]], and suppliers are given the parts that apply to them [[with the contract]].
Guidance — delete before approval
This is a Policy-tier document: approved by executive management (the management body, or its delegate for the top policy). Nobody approves a document they own or wrote: if the owner sits on the approving body, the rest of it approves.
Adapting this template
Guidance — delete before approval
Small organisation: keep all twelve statements; the tiers keep the effort small. Start by tiering the suppliers you already have and assessing the Tier 1 ones; most small organisations have fewer than [[ten]]. The assessor and the Head of Information Security may be one person, but that person does not also sign decisions as business owner. Tier 3 and Tier 4 suppliers need little more than the intake answers.
Regulated entity (NIS2, DORA, GDPR): NIS2 Article 21(2)(d) makes supply chain security one of the required measures, and Article 21(3) asks you to take account of each direct supplier's vulnerabilities and the quality of its products and security practices: TP-02 to TP-06 do this. A DORA financial entity must manage ICT third-party risk proportionately and remains fully responsible for outsourced functions (Article 28(1)); it needs a strategy on ICT third-party risk, including a policy on the use of ICT services that support critical or important functions, with the management body regularly reviewing the risks of those arrangements (Article 28(2)), a register of information on all ICT contracts (Article 28(3)), an assessment of concentration risk (Article 29) and the contract content in Article 30. Name this policy as that policy, set the override that makes such providers Tier 1, and keep the register in the form your supervisor asks for. Under the GDPR, use only processors that give sufficient guarantees (Article 28(1)); the GDPR override sets every processor at Tier 2 or above.
IT run by a service provider: your managed IT provider is usually a Tier 1 supplier itself, with privileged access to everything. Assess it first, and require it to apply this policy's intake and tiering to the subcontractors it uses to serve you. It may help run assessments, but the tier, the decision and the business owner's signature stay with your organisation.
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR).
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Annex A 5.19 — Information security in supplier relationships | Whole policy: supplier risk managed from selection to exit (TP-01 to TP-11) |
ISO/IEC 27001:2022 | Annex A 5.20 — Addressing information security within supplier agreements | Contracting: the tier's security clauses in every contract (TP-07, TP-10, TP-11) |
ISO/IEC 27001:2022 | Annex A 5.22 — Monitoring, review and change management of supplier services | Monitoring: findings, reassessment on interval and change (TP-08, TP-09) |
NIST CSF 2.0 | GV.SC-01 — “A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders” | Whole policy: the programme's rules, approved by executive management |
NIST CSF 2.0 | GV.SC-02 — “Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally” | Roles and responsibilities, including suppliers' |
NIS2 — Directive (EU) 2022/2555 | Article 21(2)(d) — “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers” | Whole policy; regulated-entity tailoring |
DORA — Regulation (EU) 2022/2554 | Article 28(1) — ICT third-party risk managed as part of ICT risk, proportionately; the financial entity remains fully responsible | Proportionate tiering (TP-02, TP-03); regulated-entity tailoring |
DORA — Regulation (EU) 2022/2554 | Article 28(2) — a strategy on ICT third-party risk, including a policy on ICT services supporting critical or important functions | The policy on ICT services supporting critical or important functions; regulated-entity tailoring |
GDPR — Regulation (EU) 2016/679 | Article 28(1) — use only processors providing sufficient guarantees of appropriate technical and organisational measures | Processors assessed before use (TP-01 to TP-05); GDPR override to Tier 2 |