Policy templates/Third-Party Risk/Version 1.0

Third-Party Management Policy Template

Summary

Defines requirements for managing vendors, suppliers, consultants, contractors, and service providers that access data or affect security and continuity. Covers onboarding, due diligence, contracts, SLAs, subcontractors, monitoring, cost oversight, offboarding, and risk treatment.

Purpose

The purpose of this policy is to establish consistent requirements for due diligence, contracting, monitoring, and termination of third-party relationships to mitigate risks associated with external service providers.

Scope

This policy applies to all third parties, including vendors, suppliers, consultants, contractors, and service providers, that access, process, transmit, or store the organization's data, or otherwise impact information security or business continuity.

Framework Mapping

Appendix A includes mappings to common security and compliance frameworks for this template.
ISO/IEC 27002:2022
5.19 Information Security in Supplier Relationships5.20 Addressing Security in Supplier Agreements
SOC 2 TSC
CC9.2: Vendor risk managementCC1.2: Board oversight of vendors
NIST CSF v2.0
ID.SC-4: Vendor risk managementGV.SC-1: Supply chain risk
NIST SP 800-53 Rev. 5
SA-12: Supply Chain ProtectionSR-3: Supply Chain Controls and Processes

Complete table of contents

This preview shows the full structure of the template. Create an account or sign in to download the complete editable policy.
  1. 1. Purpose
  2. 2. Scope
  3. 3. Policy Statement
  4. 3.1 Third-Party Onboarding and Documentation
  5. 3.2 Due Diligence and Risk Assessment
  6. 3.3 Contractual Requirements
  7. 3.4 Ongoing Monitoring and Performance Reviews
  8. 3.4.1 Fourth-Party Risk Management
  9. 3.5 Cloud Cost Management
  10. 3.6 Corrective Actions and Remediation
  11. 3.7 Termination and Offboarding
  12. 3.8 Record-Keeping and Documentation
  13. 4. Roles and Responsibilities
  14. 5. References and Related Policies
  15. 6. Definitions
  16. 7. Policy Exceptions
  17. 8. Compliance and Monitoring
  18. 9. Policy Review
  19. Appendix A: Framework Control Mapping
  20. Appendix B: Revision History
  21. Appendix C: Approvals

Download the complete third-party management policy template

Use the full editable template as a starting point, then adapt it to your organization.