Third-Party Management Policy Template
Summary
Defines requirements for managing vendors, suppliers, consultants, contractors, and service providers that access data or affect security and continuity. Covers onboarding, due diligence, contracts, SLAs, subcontractors, monitoring, cost oversight, offboarding, and risk treatment.
Purpose
The purpose of this policy is to establish consistent requirements for due diligence, contracting, monitoring, and termination of third-party relationships to mitigate risks associated with external service providers.
Scope
This policy applies to all third parties, including vendors, suppliers, consultants, contractors, and service providers, that access, process, transmit, or store the organization's data, or otherwise impact information security or business continuity.
Framework Mapping
Appendix A includes mappings to common security and compliance frameworks for this template.
ISO/IEC 27002:2022
5.19 Information Security in Supplier Relationships5.20 Addressing Security in Supplier Agreements
SOC 2 TSC
CC9.2: Vendor risk managementCC1.2: Board oversight of vendors
NIST CSF v2.0
ID.SC-4: Vendor risk managementGV.SC-1: Supply chain risk
NIST SP 800-53 Rev. 5
SA-12: Supply Chain ProtectionSR-3: Supply Chain Controls and Processes
Complete table of contents
This preview shows the full structure of the template. Create an account or sign in to download the complete editable policy.
- 1. Purpose
- 2. Scope
- 3. Policy Statement
- 3.1 Third-Party Onboarding and Documentation
- 3.2 Due Diligence and Risk Assessment
- 3.3 Contractual Requirements
- 3.4 Ongoing Monitoring and Performance Reviews
- 3.4.1 Fourth-Party Risk Management
- 3.5 Cloud Cost Management
- 3.6 Corrective Actions and Remediation
- 3.7 Termination and Offboarding
- 3.8 Record-Keeping and Documentation
- 4. Roles and Responsibilities
- 5. References and Related Policies
- 6. Definitions
- 7. Policy Exceptions
- 8. Compliance and Monitoring
- 9. Policy Review
- Appendix A: Framework Control Mapping
- Appendix B: Revision History
- Appendix C: Approvals
Download the complete third-party management policy template
Use the full editable template as a starting point, then adapt it to your organization.