FREE TEMPLATE
Vendor and Third-Party Management Policy
Your security is partly your suppliers' security. What to ask before you sign, what access a vendor gets, and how that access ends.
[COMPANY NAME]
Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change
Purpose
Your security is partly your suppliers’ security. The vendor with the weakest login is your weakest login, and the breach that takes you offline is increasingly somebody else’s breach.
This policy defines how [COMPANY NAME] chooses third parties, what access they get, and how that access ends.
Scope
Applies to any third party that holds company or customer data, can log into a company system, or provides something the business cannot operate without. That includes software-as-a-service providers, the IT provider, the accountant, the payroll bureau, contractors and freelancers.
It is not limited to vendors you pay. A free tool holding company data is in scope.
The inventory
You cannot manage what you have not listed. Most companies discover half of this the first time they try.
| Vendor | What they hold or can reach | Critical? | Contract ends | Last reviewed |
|---|---|---|---|---|
“Critical” means the business stops, or a regulatory obligation is missed, if they fail. Be strict — if everything is critical, nothing gets the attention it needs.
Before signing
Proportionate to what they get access to. A design freelancer and a payroll provider do not warrant the same questions.
For anything holding company or customer data, [POLICY OWNER] establishes and records:
- Whether MFA is available and enforced for our accounts
- Whether they will notify us of a breach, and within how many days
- Where the data is stored, and who else they pass it to
- What happens to our data when we leave — returned, deleted, and on what timescale
- Whether they hold a current SOC 2, ISO 27001 or equivalent, and their most recent report date
No formal certification is a finding to record, not automatically a disqualification. Plenty of good small vendors have none. An evasive answer is the real warning.
Contract terms that actually matter
When there is a written agreement, [COMPANY NAME] looks for:
Breach notification with a stated number of days. “Promptly” means nothing.
Data return and deletion on exit, with confirmation.
Notice of subprocessors — who else touches the data.
Right to evidence — an audit report or questionnaire response on request.
Liability that bears some relationship to the damage they could cause.
You will not win all five with a large provider on standard terms. Record which ones you did not get and accept that knowingly.
Access
Vendors get named accounts, never shared ones. “The IT login” used by four people at a supplier is untraceable and cannot be revoked selectively.
Vendor accounts are subject to the same rules as staff accounts under the Access Control Policy: least privilege, MFA enforced, reviewed on the same schedule, and removed the day the engagement ends.
Standing administrative access is granted only where the work genuinely requires it. Where a vendor needs elevated access occasionally, it is granted for the task and removed after.
Ongoing review
| Tier | Review |
|---|---|
| Critical | Annually — access, contract, security posture, whether they are still the right choice |
| Everything else | At renewal, or when what they access changes |
Reviews are recorded. “We reviewed it” without a date is not a review.
When a vendor fails or is breached
If a vendor reports a breach, [POLICY OWNER] establishes what data of ours was involved and notifies [NAME, TITLE] and the cyber insurance carrier. A supplier breach can trigger your own notification obligations — assume it might until you have established that it does not.
If a critical vendor fails outright, that is a disruption and the Business Continuity Plan applies.
Offboarding
When an engagement ends, [POLICY OWNER] records that each of these is done:
- All accounts disabled, including any the vendor created for their own staff
- API keys, integrations and app passwords revoked
- Company data returned in a usable format
- Deletion confirmed in writing
- Any hardware returned
The day the invoice stops is not the day the access stops. They are separate tasks and only one of them happens automatically.
Responsibilities
[POLICY OWNER] maintains the inventory, runs reviews, and controls vendor access.
Business owner approves critical vendors and accepts risks recorded under ‘Contract terms that actually matter’.
Everyone routes new tools through [POLICY OWNER] before putting company data into them. A free trial is how most shadow IT starts.
Review
Reviewed at least annually by [POLICY OWNER], after any vendor breach, and whenever a critical vendor is added or replaced.
Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your retention obligations. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.
EDITABLE VERSION
Want the Word version you can edit?
The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked and every table ready to complete, in our formatting. Tell us where to send it.
Free. About 20 seconds.
Where should we send it?
THE REST OF THE SET
Nine more, and someone to run them.
This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.
A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.
