Vendor and Third-Party Management Policy Template

FREE TEMPLATE

Vendor and Third-Party Management Policy

Your security is partly your suppliers' security. What to ask before you sign, what access a vendor gets, and how that access ends.

[COMPANY NAME]

Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change

Purpose

Your security is partly your suppliers’ security. The vendor with the weakest login is your weakest login, and the breach that takes you offline is increasingly somebody else’s breach.

This policy defines how [COMPANY NAME] chooses third parties, what access they get, and how that access ends.

Scope

Applies to any third party that holds company or customer data, can log into a company system, or provides something the business cannot operate without. That includes software-as-a-service providers, the IT provider, the accountant, the payroll bureau, contractors and freelancers.

It is not limited to vendors you pay. A free tool holding company data is in scope.

The inventory

You cannot manage what you have not listed. Most companies discover half of this the first time they try.

VendorWhat they hold or can reachCritical?Contract endsLast reviewed

“Critical” means the business stops, or a regulatory obligation is missed, if they fail. Be strict — if everything is critical, nothing gets the attention it needs.

Before signing

Proportionate to what they get access to. A design freelancer and a payroll provider do not warrant the same questions.

For anything holding company or customer data, [POLICY OWNER] establishes and records:

  • Whether MFA is available and enforced for our accounts
  • Whether they will notify us of a breach, and within how many days
  • Where the data is stored, and who else they pass it to
  • What happens to our data when we leave — returned, deleted, and on what timescale
  • Whether they hold a current SOC 2, ISO 27001 or equivalent, and their most recent report date

No formal certification is a finding to record, not automatically a disqualification. Plenty of good small vendors have none. An evasive answer is the real warning.

Contract terms that actually matter

When there is a written agreement, [COMPANY NAME] looks for:

Breach notification with a stated number of days. “Promptly” means nothing.

Data return and deletion on exit, with confirmation.

Notice of subprocessors — who else touches the data.

Right to evidence — an audit report or questionnaire response on request.

Liability that bears some relationship to the damage they could cause.

You will not win all five with a large provider on standard terms. Record which ones you did not get and accept that knowingly.

Access

Vendors get named accounts, never shared ones. “The IT login” used by four people at a supplier is untraceable and cannot be revoked selectively.

Vendor accounts are subject to the same rules as staff accounts under the Access Control Policy: least privilege, MFA enforced, reviewed on the same schedule, and removed the day the engagement ends.

Standing administrative access is granted only where the work genuinely requires it. Where a vendor needs elevated access occasionally, it is granted for the task and removed after.

Ongoing review

TierReview
CriticalAnnually — access, contract, security posture, whether they are still the right choice
Everything elseAt renewal, or when what they access changes

Reviews are recorded. “We reviewed it” without a date is not a review.

When a vendor fails or is breached

If a vendor reports a breach, [POLICY OWNER] establishes what data of ours was involved and notifies [NAME, TITLE] and the cyber insurance carrier. A supplier breach can trigger your own notification obligations — assume it might until you have established that it does not.

If a critical vendor fails outright, that is a disruption and the Business Continuity Plan applies.

Offboarding

When an engagement ends, [POLICY OWNER] records that each of these is done:

  • All accounts disabled, including any the vendor created for their own staff
  • API keys, integrations and app passwords revoked
  • Company data returned in a usable format
  • Deletion confirmed in writing
  • Any hardware returned

The day the invoice stops is not the day the access stops. They are separate tasks and only one of them happens automatically.

Responsibilities

[POLICY OWNER] maintains the inventory, runs reviews, and controls vendor access.

Business owner approves critical vendors and accepts risks recorded under ‘Contract terms that actually matter’.

Everyone routes new tools through [POLICY OWNER] before putting company data into them. A free trial is how most shadow IT starts.

Review

Reviewed at least annually by [POLICY OWNER], after any vendor breach, and whenever a critical vendor is added or replaced.

Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your retention obligations. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.

EDITABLE VERSION

Want the Word version you can edit?

The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked and every table ready to complete, in our formatting. Tell us where to send it.

Free. About 20 seconds.

THE REST OF THE SET

Nine more, and someone to run them.

This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.

A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.

Book 20 Minutes