On this page
- Quick Reference (60 Seconds)
- What the Standard Actually Requires
- Why Information Security in Supplier Relationships Matters
- Scope and Applicability
- Key Definitions and Terminology
- Relationship to Other Controls
- Implementation Roadmap (Week-by-Week)
- Detailed Implementation Guidance
- Tools, Technologies, and Solutions
- Policy and Procedure Templates
- Risk Assessment and Treatment
- Audit and Compliance Checklist
- Metrics and KPIs
- Common Pitfalls and How to Avoid Them
- Illustrative Scenarios
- Multi-Framework Mapping
- Regulatory and Industry Context
- Roles and Responsibilities (RACI)
- Documentation and Evidence Requirements
- Continuous Improvement
- FAQ
- References and Further Reading
Quick Reference (60 Seconds)
ISO 27001:2022 Annex A 5.19 requires organizations to establish and maintain processes for managing information security in supplier relationships, ensuring that suppliers and their services, products, and personnel do not introduce unacceptable risk to the organization's information and systems.
| Element | What You Need to Know |
|---|---|
| Standard Reference | ISO/IEC 27001:2022, Annex A, Control 5.19 |
| 27002 Guidance | ISO/IEC 27002:2022, Clause 5.19, Information security in supplier relationships |
| Objective | Ensure information security is managed throughout the lifecycle of supplier relationships |
| Key Requirement | Risk assessment, security requirements in contracts, monitoring, auditing, incident management, change control, termination |
| Who It Applies To | All suppliers with access to information, systems, or premises: IT vendors, cloud providers, consultants, cleaners, security guards, managed services, outsourced development, SaaS |
| Audit Focus | Supplier inventory, risk assessments, contractual security clauses, monitoring records, audit rights, incident history, change management |
| Typical Failures | No supplier inventory, no security clauses, no risk assessment, no monitoring, no audit rights, no termination procedure |
| Singahi's Role | Supplier risk framework, contract security clauses, TPRM program, vendor audits, continuous monitoring, DPDP compliance |
The Bottom Line: You can have the strongest internal security in the world, but one vulnerable supplier can destroy it all. Supplier security is your security. If you don't manage it, you don't own your risk.
What the Standard Actually Requires
The ISO 27001:2022 Text
Annex A 5.19 states:
ISO 27001:2022 Annex A 5.19 asks organizations to define and apply processes and controls to manage the security risks of using suppliers' products and services.
What ISO 27002:2022 Adds
The implementation guidance requires:
- Identification of all suppliers and their access to information/assets
- Risk assessment of suppliers based on access, data handled, criticality, and location
- Security requirements defined and communicated to suppliers before engagement
- Security requirements included in contracts and agreements (A.5.14)
- Monitoring and review of supplier security performance
- Right to audit suppliers and their subcontractors
- Incident notification requirements in contracts
- Change management for supplier services, personnel, and locations
- Termination and return/destruction of information on contract end
- Supplier access revocation procedures
- Due diligence for new suppliers and periodic reassessment
- Management of supplier personnel changes and access
The Six Mandatory Components
| Component | Evidence Required | Common Failure |
|---|---|---|
| 1. Supplier inventory | Complete list of all suppliers with access to information | No inventory; shadow suppliers |
| 2. Supplier risk assessment | Risk assessment per supplier or supplier category | No assessment; generic template |
| 3. Security requirements in contracts | Security clauses in all supplier agreements | Generic contracts; no security clauses |
| 4. Supplier monitoring | Evidence of ongoing monitoring and review | No monitoring after contract signing |
| 5. Audit rights | Contractual right to audit; audit execution records | No audit clause; never exercised |
| 6. Termination procedure | Return/destruction of data; access revocation | Data left with supplier; access not revoked |
Why Information Security in Supplier Relationships Matters
The Supplier Risk Reality
| Statistic | Source | Impact |
|---|---|---|
| 62% of data breaches involve a supplier or third party | Verizon DBIR 2024 | Suppliers are the majority attack vector |
| 53% of organizations experienced a third-party data breach in 12 months | SecureLink / Ponemon Institute | More than half of organizations hit |
| 75% of Indian enterprises do not conduct regular supplier security assessments | Singahi internal research 2024 | Massive systemic gap in India |
| 44% of supplier breaches take 6+ months to detect | Verizon DBIR 2024 | Extended dwell time due to poor visibility |
| Average organization has 5,800+ supplier relationships | SecurityScorecard | Complexity makes management difficult |
| Only 34% of organizations have a formal Third-Party Risk Management (TPRM) program | Gartner 2024 | Majority fly blind on supplier risk |
The Indian Context
India's digital economy is deeply intertwined with global and local suppliers. Key factors amplifying supplier risk in India:
- IT/ITES Hub: India hosts thousands of IT service providers, BPOs, and KPOs handling global customer data. A breach at one Indian supplier can expose data from 50+ international clients.
- DPDP Act 2023: The Act makes the "data fiduciary" (your organization) liable for breaches, even if caused by a supplier. Section 8(5)'s "reasonable security safeguards" obligation extends to your supply chain.
- RBI, SEBI, IRDAI mandates: Financial regulators explicitly require vendor risk management. RBI's Master Direction on Digital Payment Security mandates vendor assessments, contractual controls, and incident reporting.
- Offshoring and outsourcing: Many Indian companies are suppliers to global enterprises, subject to stringent client audits (SOC 2, ISO 27001, PCI DSS). Failing supplier security means losing contracts.
- SMB supplier ecosystem: Indian SMEs often rely on small local IT vendors, website developers, and accountants who lack security awareness. These are the weakest links.
Scope and Applicability
What Suppliers Are Covered
A.5.19 applies to any external party that has access to the organization's information, systems, or premises. This includes:
| Supplier Category | Examples | Security Risk Level | Typical Access |
|---|---|---|---|
| IT service providers | Managed IT services, system integrators, IT consultants, MSPs | High | Systems, networks, admin credentials |
| Cloud and SaaS providers | AWS, Azure, Google Cloud, Salesforce, Zoho, Freshworks | High | Data, infrastructure, APIs |
| Software development vendors | Offshore development centers, custom software shops, app developers | High | Source code, databases, customer data |
| Data processors | Payroll processors, CRM managers, analytics providers, data cleansing services | High | Personal data, financial data, employee records |
| Professional services | Auditors, legal firms, management consultants, marketing agencies | Medium-High | Confidential reports, strategy documents, customer data |
| Facilities and physical services | Security guards, cleaning staff, facility management, maintenance | Medium | Premises, devices, physical documents |
| Logistics and courier | Document couriers, warehouse operators, delivery services | Medium | Physical documents, devices, media |
| Recruitment and staffing | Temp agencies, background check providers, headhunters | Medium | Employee data, candidate PII |
| Outsourced business functions | BPO, KPO, customer support, accounting, HR administration | High | Customer data, financial data, employee data |
| Subcontractors | Your supplier's suppliers, often invisible | High (indirect) | Data passed through primary supplier |
| Hardware and software vendors | OEMs, resellers, implementation partners | Medium | Systems, licenses, support access |
| Research and academic partners | Universities, research institutes, joint venture partners | Medium-High | Research data, IP, confidential findings |
| Government and regulatory | Tax consultants, compliance auditors, regulatory filers | Medium | Financial data, regulatory submissions |
| Freelancers and individual contractors | Individual developers, designers, content creators | Medium-High | Systems, content, customer data |
Supplier Access Types
| Access Type | Description | Examples | Risk Implications |
|---|---|---|---|
| Logical access | Remote or on-premise access to systems, networks, applications | VPN, RDP, SSH, cloud console, admin portal | High risk of data breach, lateral movement |
| Physical access | Access to buildings, data centers, offices, secure areas | ID card, biometric, visitor pass | Risk of theft, espionage, unauthorized device access |
| Data access | Access to data stored in supplier systems or transferred to supplier | Cloud storage, email, file transfer, database replication | Risk of data leakage, unauthorized processing, DPDP violation |
| Personnel access | Supplier personnel working on your premises or as part of your team | Embedded developers, consultants, managed service staff | Insider threat, credential sharing, knowledge leakage |
| Subcontractor access | Access granted to your supplier's subcontractors | Offshore development partner of your main vendor | Invisible risk; often no direct contract |
| Integration access | API, webhook, or system-to-system integration access | Payment gateway, CRM integration, logistics API | Risk of API abuse, data interception, supply chain attack |
Organizational Scope
| Entity Type | Applicability | Special Considerations |
|---|---|---|
| Startups and SMEs | All vendors with data access: cloud, dev, accounting, payroll | Lightweight process; focus on high-risk suppliers; use standardized contract clauses |
| Growing companies (250-5000 employees) | All IT, professional services, facilities, and outsourced functions | Formal TPRM program; risk tiers; quarterly reviews; annual audits for Critical suppliers |
| Large enterprises (5000+ employees) | All suppliers including indirect/subcontractors; global supply chain | Enterprise TPRM platform; automated risk scoring; continuous monitoring; on-site audits |
| Government and PSUs | All vendors for e-governance, citizen data, and infrastructure | CERT-In compliance; additional security clearances; make-in-India preferences |
| BFSI sector | All vendors handling financial data, payment systems, customer data | RBI/SEBI/IRDAI mandates; PCI DSS for payment suppliers; data localization |
| Healthcare | All vendors handling patient data, clinical records, insurance claims | DPDP Act sensitive personal data; HIPAA-alignment for US partnerships |
| IT/ITES and SaaS | All client-facing suppliers; development partners; cloud providers | Client audits; SOC 2 alignment; ISO 27001 certification of suppliers |
| Manufacturing | ERP vendors, OT system integrators, IoT device suppliers, logistics | IEC 62443 for OT; supply chain integrity; counterfeiting risk |
| Retail and E-commerce | Payment gateways, logistics, marketplace vendors, marketing tech | PCI DSS for all payment touchpoints; DPDP for customer data |
Key Definitions and Terminology
| Term | Definition | Source/Context |
|---|---|---|
| Supplier | An external organization or individual that provides a product, service, or information to the organization | ISO 27001:2022, adapted |
| Third-Party Risk Management (TPRM) | The process of identifying, assessing, and controlling risks arising from relationships with external parties | Industry standard term |
| Vendor Risk Management (VRM) | Synonym for TPRM; often used in IT procurement contexts | Industry standard term |
| Supplier Risk Assessment | The evaluation of a supplier's potential to introduce information security risk based on access, data, criticality, and controls | ISO 27002:2022 guidance |
| Security Clause / Security Addendum | Contractual provisions that specify information security requirements, obligations, and remedies | Contract law / ISO 27001 practice |
| Data Processing Agreement (DPA) | A contract or clause that governs how a supplier processes personal data on behalf of the organization | GDPR Art. 28 / DPDP Act 2023 |
| Right to Audit | A contractual provision allowing the organization to audit the supplier's security controls | ISO 27002:2022, Clause 5.19 |
| Subcontractor / Sub-supplier | A supplier engaged by your primary supplier to deliver part of the contracted service | ISO 27001:2022 context |
| Supplier Security Questionnaire (SSQ) | A standardized set of questions used to assess a supplier's security posture | TPRM best practice |
| Security Rating / Score | A numerical or categorical assessment of a supplier's security posture, often based on external telemetry | SecurityScorecard, BitSight, etc. |
| Due Diligence | The investigation and verification of a supplier's security capabilities before engagement | ISO 27002:2022 guidance |
| Continuous Monitoring | Ongoing assessment of supplier security posture through automated tools, alerts, and periodic reviews | TPRM best practice |
| Offboarding / Termination | The process of ending a supplier relationship, including data return/destruction and access revocation | ISO 27002:2022, Clause 5.19 |
| Supply Chain Attack | A cyberattack that targets a less-secure supplier to gain access to the primary target organization | Industry threat terminology |
| Fourth-Party Risk | Risk introduced by your supplier's suppliers (subcontractors), indirect supply chain risk | TPRM advanced concept |
| Data Residency | The requirement that data must be stored and processed within a specific geographic boundary | DPDP Act 2023; regulatory requirement |
| Service Level Agreement (SLA) | A contract that defines the expected level of service, including security-related metrics | IT service management |
| Business Associate Agreement (BAA) | A HIPAA-specific contract for healthcare suppliers handling protected health information | USA healthcare regulation |
| Incident Notification Clause | A contractual requirement for the supplier to notify the organization of security incidents within a defined timeframe | ISO 27002:2022, Clause 5.19 |
Relationship to Other Controls
Control A.5.19 is a central organizational control that intersects with nearly every other control in ISO 27001:2022. Supplier relationships are conduits for risk, and their management must be coordinated across the entire standard.
Organizational Controls (5.x)
| Control | Relationship | How They Work Together |
|---|---|---|
| A.5.1 Policies for information security | Parent policy | The supplier security policy is a topic-specific policy under the overall information security policy |
| A.5.4 Management responsibilities | Governance | Senior management ensures resources and authority for TPRM |
| A.5.5 Information security roles and responsibilities | Role definition | Supplier security roles (Vendor Risk Manager, Supplier Security Officer) are defined |
| A.5.10 Information security acceptance | Supplier acceptance | New systems/services from suppliers must pass security acceptance before production use |
| A.5.14 Information transfer agreements | Contractual basis | Supplier agreements are a subset of information transfer agreements; A.5.14 governs the agreement structure; A.5.19 governs the security management within that agreement |
| A.5.20 Information security in project management | Project suppliers | Projects involving suppliers must apply both A.5.20 (project security) and A.5.19 (supplier security) |
| A.5.30 ICT readiness for business continuity | Supplier resilience | Supplier business continuity must be verified to ensure organizational resilience |
| A.5.37 Documented operating procedures | Operational handover | Supplier-delivered systems must have documented operating procedures |
People Controls (6.x)
| Control | Relationship | How They Work Together |
|---|---|---|
| A.6.1 Screening | Supplier personnel screening | Supplier personnel with access may need background verification |
| A.6.3 Information security awareness, education and training | Supplier training | Supplier personnel must be trained on the organization's security requirements |
| A.6.4 Disciplinary process | Supplier enforcement | Supplier contract must allow for consequences of security breaches |
| A.6.7 Remote working | Supplier remote access | Supplier personnel working remotely must comply with the organization's remote work policy |
| A.6.8 Information security event reporting | Supplier incident reporting | Supplier must report security events to the organization per contract |
Physical Controls (7.x)
| Control | Relationship | How They Work Together |
|---|---|---|
| A.7.1 Physical security perimeters | Supplier physical access | Supplier personnel accessing premises must comply with physical security controls |
| A.7.4 Physical security monitoring | Supplier activity monitoring | Supplier personnel on premises are subject to physical monitoring |
| A.7.8 Equipment siting and protection | Supplier equipment | Supplier equipment on premises must be secured and accounted for |
| A.7.9 Security of assets off-premises | Supplier off-site assets | Assets provided to suppliers (laptops, documents) must be secured off-premises |
Technological Controls (8.x)
| Control | Relationship | How They Work Together |
|---|---|---|
| A.8.1 User endpoint devices | Supplier devices | Supplier devices connecting to your network must meet endpoint security standards |
| A.8.5 Secure authentication | Supplier access | Supplier accounts must use strong authentication (MFA) |
| A.8.8 Management of technical vulnerabilities | Supplier patching | Supplier must maintain vulnerability management for their systems touching your data |
| A.8.9 Configuration management | Supplier systems | Supplier systems must be configured securely |
| A.8.15 Access control | Supplier access rights | Supplier access must be controlled, minimized, and reviewed |
| A.8.16 Capacity management | Supplier capacity | Supplier must maintain capacity for security operations (logging, monitoring) |
| A.8.18 Use of privileged utility programs | Supplier admin access | Supplier admin access must be controlled and monitored |
| A.8.24 Use of cryptography | Supplier encryption | Supplier must encrypt data in transit and at rest per your requirements |
| A.8.25 Secure development lifecycle | Supplier development | Software development suppliers must follow secure development practices |
| A.8.28 Secure coding | Supplier code | Code from suppliers must meet your secure coding standards |
| A.8.29 Security testing in development and acceptance | Supplier testing | Supplier must conduct security testing before delivery |
| A.8.31 Separation of development, test and production environments | Supplier environments | Supplier must maintain environment separation |
| A.8.32 Change management | Supplier changes | Supplier changes affecting your systems must be controlled and approved |
| A.8.33 Test data | Supplier test data | Supplier must not use your production data for testing without anonymization |
| A.8.34 Protection of information systems during audit testing | Supplier audit | Auditing suppliers must not disrupt their operations or your services |
The A.5.14 ↔ A.5.19 ↔ A.5.9 (Legacy) Triad
In the 2013 version of ISO 27001, supplier relationships were covered by A.15.1 (Information security in supplier relationships) and A.15.2 (Supplier service delivery management). In 2022, these were consolidated and reorganized:
- A.5.14 (Information transfer agreements): Governs the agreement itself, what must be in the contract
- A.5.19 (Information security in supplier relationships): Governs the ongoing management of supplier security, risk assessment, monitoring, auditing, termination
A.5.19 references A.5.14 for the contractual foundation, but focuses on the process of managing the relationship after the contract is signed. For full compliance, both controls must be implemented together.
Implementation Roadmap (Week-by-Week)
Standard Implementation: 10 Weeks
The following roadmap is designed for growing companies (250-5000 employees) with 50-200 active suppliers. Adjust for smaller or larger organizations.
| Week | Phase | Activities | Deliverables | Owner |
|---|---|---|---|---|
| Week 1 | Discovery & Inventory | Inventory all suppliers; categorize by access type and data handled; identify shadow suppliers; assess current contracts | Supplier inventory (initial); shadow supplier report; contract gap analysis | Procurement / IT / Security |
| Week 2 | Risk Framework Design | Define supplier risk tiers; design risk assessment methodology; create risk scoring matrix; define risk treatment options | Supplier risk framework; risk scoring matrix; tier definitions | Vendor Risk Manager / CISO |
| Week 3 | Policy & Template Development | Draft Supplier Security Policy; create Security Questionnaire; design contract security clauses; build monitoring checklist | Policy draft; SSQ template; contract clause library; monitoring checklist | Legal / Security / Procurement |
| Week 4 | Assessment Execution (Critical) | Send SSQ to all Critical suppliers; review responses; conduct follow-up calls; rate each supplier | Critical supplier risk assessments; risk register entries | Vendor Risk Manager |
| Week 5 | Assessment Execution (High/Medium) | Send SSQ to High and Medium suppliers; review responses; rate suppliers; identify gaps | High/Medium supplier risk assessments; consolidated risk register | Vendor Risk Manager |
| Week 6 | Contract Remediation | Review all supplier contracts; identify missing security clauses; negotiate amendments with Critical/High suppliers; execute new contracts for new suppliers | Amended contracts; new contract templates; contract tracking report | Legal / Procurement |
| Week 7 | Monitoring & Audit Setup | Define monitoring frequency per tier; schedule annual audits for Critical suppliers; set up security rating service (if budget allows); configure alert thresholds | Monitoring schedule; audit calendar; security rating baseline | Vendor Risk Manager / Security Operations |
| Week 8 | Termination & Offboarding | Document termination procedures; create data return/destruction checklist; design access revocation workflow; test with 1-2 departing suppliers | Termination procedure; offboarding checklist; access revocation workflow | IT / Security / Vendor Risk Manager |
| Week 9 | Training & Communication | Train procurement on security clauses; train IT on supplier access provisioning; train security on TPRM process; communicate policy to all suppliers | Training records; communication log; policy acknowledgment | HR / Security / Procurement |
| Week 10 | Audit & Refinement | Conduct internal audit of TPRM implementation; verify supplier inventory completeness; sample contract reviews; test offboarding workflow; refine templates | Internal audit report; refined templates; continuous improvement plan | Internal Auditor / CISO |
Accelerated Implementation: 5 Weeks
For organizations with urgent certification deadlines or fewer than 50 suppliers:
| Week | Focus | Key Actions |
|---|---|---|
| Week 1 | Inventory + Risk Framework | Complete supplier inventory; define 3 risk tiers; create SSQ |
| Week 2 | Assess Critical + Policy | Assess all Critical suppliers; draft policy; create contract clauses |
| Week 3 | Contract Remediation + High Assessment | Amend Critical contracts; assess High suppliers |
| Week 4 | Monitoring + Offboarding + Training | Set up monitoring; document offboarding; train key staff |
| Week 5 | Audit + Harden | Internal audit; fix gaps; finalize documentation |
Enterprise Implementation: 16 Weeks
For large organizations with 500+ suppliers, global operations, multiple procurement teams, and complex subcontractor chains:
| Phase | Weeks | Focus |
|---|---|---|
| Phase 1: Foundation | 1-4 | Multi-region supplier inventory; enterprise risk framework; tool selection (TPRM platform); governance structure |
| Phase 2: Policy & Standards | 5-6 | Global policy; regional addenda (India DPDP, EU GDPR, US state laws); contract clause library; standard operating procedures |
| Phase 3: Assessment at Scale | 7-10 | Automated SSQ distribution; external security ratings integration; risk scoring automation; Critical supplier deep-dive assessments |
| Phase 4: Contract Remediation | 11-12 | Bulk contract review; negotiation with Critical/High; new contract template rollout; procurement system integration |
| Phase 5: Monitoring & Audit | 13-14 | Continuous monitoring setup; annual audit program; quarterly business reviews with Critical suppliers; automated alert configuration |
| Phase 6: Optimization | 15-16 | Fourth-party risk visibility; AI-assisted risk prediction; integration with ERM and GRC; external pre-certification audit |
Detailed Implementation Guidance
Step 1: Supplier Inventory, Know Your Suppliers
You cannot manage what you do not know. The first step is a complete inventory of all suppliers with access to your information, systems, or premises.
Inventory Sources:
- Accounts payable / finance records (all paid vendors)
- Procurement system / contract database
- IT system access logs (who has VPN, RDP, admin accounts?)
- Cloud admin consoles (who has IAM access?)
- Physical access logs (visitor management, security passes)
- Email domain analysis (who is on your distribution lists?)
- Department interviews (ask each department who they share data with)
- SaaS subscription discovery (use tools like Productiv, Torii, or manual survey)
Inventory Attributes:
| Attribute | Purpose | Example Values |
|---|---|---|
| Supplier Name | Unique identification | Accenture India Pvt. Ltd. |
| Supplier ID | Internal tracking | SUP-2024-0147 |
| Category | Risk grouping | IT Services, Cloud, Professional Services, Facilities |
| Data Accessed | Risk determination | Customer PII, Financial Data, Employee Records, Public Data |
| System Access | Technical risk scope | VPN, Cloud Console, API, Email, Physical Only |
| Access Type | Control design | Admin, User, Read-Only, Physical |
| Personnel Count | Scale of exposure | 5 developers, 2 admins, 10 support staff |
| Location | Regulatory/geographic risk | India, USA, Philippines, EU |
| Subcontractors | Fourth-party risk | Yes, 2 offshore dev vendors |
| Contract Start/End | Lifecycle management | 2024-01-15 to 2026-01-14 |
| Annual Spend | Business criticality | |
| Risk Tier | Management priority | Critical |
| Last Assessment Date | Monitoring frequency | 2024-06-10 |
| Security Certifications | Evidence of controls | ISO 27001, SOC 2 Type II, PCI DSS |
| Key Contact | Escalation | Vendor Security Officer |
Shadow Supplier Discovery:
Shadow suppliers are vendors engaged by individual departments without procurement or security knowledge. Common examples:
- Marketing team using a freelance designer with Google Drive access to brand assets
- Sales team using a personal CRM subscription with customer data
- Developer using a personal GitHub account for company code
- HR using a free survey tool for employee feedback with PII
Discovery techniques:
- Expense report analysis (look for SaaS subscriptions, freelance payments)
- Email domain analysis (which external domains appear in internal distribution lists?)
- Cloud access logs (which external IPs access your cloud?)
- Department surveys ("List all external parties with access to your data")
- Network traffic analysis (which SaaS APIs are your systems calling?)
Step 2: Supplier Risk Classification, Tier Your Suppliers
Not all suppliers are equal. Risk-based tiering ensures you focus your limited resources on the suppliers that matter most.
Tiering Criteria:
| Factor | Weight | Scoring |
|---|---|---|
| Data sensitivity | 30% | Secret/Confidential = 5; Internal = 3; Public = 1 |
| System access level | 25% | Admin/root = 5; User/write = 4; Read-only = 2; None = 0 |
| Business criticality | 20% | Business cannot operate without = 5; Major disruption = 3; Minor inconvenience = 1 |
| Supplier security maturity | 15% | No certifications/unknown = 5; ISO 27001/SOC 2 = 2; Enterprise-grade + audit = 1 |
| Subcontractor complexity | 10% | Multiple unknown subcontractors = 5; Known subcontractors = 3; No subcontractors = 1 |
Risk Tier Definitions:
| Tier | Risk Score | Proportion of Suppliers | Management Intensity | Example |
|---|---|---|---|---|
| Critical | 18-25 | Top 5-10% | Deep due diligence before contract; annual on-site audit; quarterly business reviews; continuous monitoring; dedicated relationship manager | Core banking system integrator; cloud provider with all customer data; payment processor |
| High | 12-17 | Next 15-20% | Standard due diligence; annual SSQ review; semi-annual review; monitoring for security news | CRM vendor; payroll processor; major IT consultant |
| Medium | 6-11 | Next 30-40% | Lightweight SSQ; biennial review; ad-hoc monitoring for incidents | Marketing agency; cleaning service; hardware vendor |
| Low | 0-5 | Remaining 30-50% | Minimal assessment; triennial review; incident-driven monitoring | Courier service; office supplies; training provider |
Step 3: Supplier Security Assessment, Evaluate Before You Trust
The Security Questionnaire (SSQ):
A well-designed SSQ covers 8 domains:
| Domain | Key Questions | Evidence Requested |
|---|---|---|
| 1. Governance and Policy | Do you have an information security policy? Is it approved by management? How often is it reviewed? | Policy document, review records |
| 2. Risk Management | Do you conduct risk assessments? How often? What methodology? | Risk assessment report, methodology document |
| 3. Access Control | How do you manage user access? Is MFA enforced? How often are access reviews conducted? | Access control policy, MFA configuration evidence, review records |
| 4. Data Protection | How do you classify data? Is encryption used? What are your data retention and destruction policies? | Data classification policy, encryption configuration, retention policy |
| 5. Incident Management | Do you have an incident response plan? What is your notification timeframe? Do you conduct post-incident reviews? | IR plan, incident records (sanitized), notification SLA |
| 6. Business Continuity | What is your RTO/RPO? Do you conduct DR drills? Are backups tested? | BCP/DR plan, test records, RTO/RPO documentation |
| 7. Compliance and Audit | What certifications do you hold? When was your last audit? Are audit reports available? | Certificates, SOC 2 report, pen test report, audit reports |
| 8. Subcontractor Management | Do you use subcontractors? How do you manage their security? Do you disclose all subcontractors? | Subcontractor list, their security assessments, contractual clauses |
SSQ Response Evaluation:
| Score | Rating | Meaning | Action |
|---|---|---|---|
| 90-100% | Excellent | Mature security program; enterprise-grade | Proceed with standard monitoring |
| 70-89% | Good | Adequate security; some gaps | Proceed with gap remediation plan; monitor closely |
| 50-69% | Fair | Significant gaps; immature program | Conditional approval with mandatory remediation; increased monitoring |
| 30-49% | Poor | Major gaps; high risk | Do not proceed unless critical and no alternatives; require major investment in controls; consider risk transfer (insurance, liability caps) |
| <30% | Unacceptable | No meaningful security program | Do not engage; find alternative supplier |
Alternative Assessment Methods:
| Method | When to Use | overhead | Depth |
|---|---|---|---|
| Security Questionnaire (SSQ) | All suppliers | Low | Medium |
| External Security Rating | All suppliers for baseline; Critical for continuous monitoring | Medium (-10L/year for platform) | Medium (external telemetry) |
| On-site Audit | Critical suppliers; high-risk suppliers with poor SSQ | High (-2L per audit) | High |
| Virtual Audit / Video Walkthrough | High suppliers; remote suppliers; pandemic/travel constraints | Medium (-75K) | Medium-High |
| Third-Party Certification Review | All certified suppliers | Low (request report) | Medium (trust but verify) |
| Penetration Test of Supplier | Critical suppliers handling highly sensitive data | Very High (-5L) | Very High |
| Financial and Background Check | Critical suppliers; suppliers with physical access | Medium | Low-Medium (business risk) |
Step 4: Contractual Security Requirements, Put It in Writing
Security requirements that are not in the contract are not enforceable. Every supplier contract must include a security addendum or embedded security clauses.
Mandatory Contract Clauses for Critical/High Suppliers:
| Clause | Minimum Requirement | Purpose |
|---|---|---|
| 1. Security Standard Compliance | Supplier must comply with ISO 27001 or equivalent; maintain certification; notify of certification lapses | Baseline security assurance |
| 2. Data Protection | Encryption (AES-256 at rest, TLS 1.3 in transit); data minimization; purpose limitation; no unauthorized processing | Data confidentiality and integrity |
| 3. Data Residency | All data must be stored and processed in India (or specified region); no cross-border transfer without consent and safeguards | DPDP Act 2023 compliance; regulatory adherence |
| 4. Access Control | MFA for all admin access; principle of least privilege; quarterly access reviews; no shared accounts | Prevent unauthorized access |
| 5. Incident Notification | Notify within 24 hours of discovery; provide detailed incident report within 72 hours; cooperate with investigation | Timely incident response |
| 6. Right to Audit | Organization may audit supplier's security controls annually with 30 days' notice; supplier must cooperate and provide evidence | Verification of compliance |
| 7. Subcontractor Disclosure and Control | Supplier must disclose all subcontractors; subcontractor must meet same security standards; supplier remains liable for subcontractor breaches | Fourth-party risk management |
| 8. Change Management | Supplier must notify of material changes (location, personnel, technology, subcontractors) 30 days in advance; organization may reassess | Risk control during relationship |
| 9. Vulnerability Management | Supplier must patch Critical vulnerabilities within 7 days; High within 30 days; annual penetration testing | Technical security maintenance |
| 10. Business Continuity | Supplier must maintain BCP/DR plan with RTO ≤ 4 hours; annual DR test; evidence of backup restoration | Operational resilience |
| 11. Personnel Security | Background checks for personnel with access to organization data; security awareness training; confidentiality agreements | Human risk mitigation |
| 12. Data Return and Destruction | Return all data within 30 days of termination; certify destruction; allow verification | Data lifecycle control |
| 13. Access Revocation | Revoke all access within 24 hours of termination; return all credentials, devices, and materials | Immediate risk removal |
| 14. Liability and Insurance | Supplier must maintain cyber insurance (minimum ); liability for breaches caused by supplier negligence; indemnification | Financial risk transfer |
| 15. Termination for Security Cause | Organization may terminate immediately for material security breach; pro-rata refund if applicable | Enforcement mechanism |
Clause Library by Supplier Type:
| Supplier Type | Additional Clauses |
|---|---|
| Cloud/SaaS | SOC 2 Type II report; data portability; API security; multi-tenant isolation; customer data segregation |
| Software Development | Secure development lifecycle (SDL); source code escrow; IP ownership; no open-source with viral licenses; security testing before delivery |
| Data Processor | DPIA cooperation; data subject rights support; breach notification to data protection authority; processing records |
| Professional Services | Confidentiality of client data; no use of data for AI training; return of all work product; conflict of interest disclosure |
| Facilities/Physical | Background checks; no photography in secure areas; visitor escort; incident reporting; key/card return |
| Logistics/Courier | Chain of custody; tamper-evident packaging; GPS tracking; no subcontracting without approval; incident reporting |
| Managed Security Services | SOC 2 Type II; 24/7 monitoring; SLA for detection and response; dedicated CISO contact; threat intelligence sharing |
Step 5: Supplier Monitoring, Trust but Verify
Signing a contract with security clauses is not enough. You must monitor the supplier's ongoing compliance.
Monitoring Methods by Tier:
| Tier | Frequency | Methods | Evidence |
|---|---|---|---|
| Critical | Monthly | Security metrics review; vulnerability scan of supplier-facing assets; log review; quarterly business review (QBR) with security agenda; annual on-site audit | QBR minutes; scan reports; audit reports; metrics dashboard |
| High | Quarterly | SSQ refresh; security news alert monitoring; certificate validity check; semi-annual review meeting | Updated SSQ; news alerts; certificate checks; meeting minutes |
| Medium | Bi-annually | SSQ refresh; incident inquiry; ad-hoc monitoring for major security news | SSQ; incident records; news alerts |
| Low | Annually | Light SSQ or attestation; incident-driven inquiry | Attestation letter; incident records |
Continuous Monitoring Techniques:
-
Security Rating Services: BitSight, SecurityScorecard, UpGuard, or Panorays provide daily security ratings based on external telemetry (open ports, malware, SSL certificates, breach history). Use for all Critical and High suppliers.
-
Certificate Monitoring: Track ISO 27001, SOC 2, PCI DSS certification expiry dates. Set alerts 90 days before expiry.
-
Security News Monitoring: Google Alerts, Feedly, or vendor-specific threat intelligence for supplier breach news. A supplier breach may expose your data even if they don't notify you proactively.
-
Log Monitoring: If suppliers have VPN or system access, monitor their access logs for anomalies: unusual hours, geolocation changes, excessive data download, privilege escalation.
-
Vulnerability Scanning: Scan supplier-facing assets (APIs, portals, integrations) for vulnerabilities. If their infrastructure is weak, your connection is at risk.
-
Dark Web Monitoring: Monitor for leaked credentials, data, or intellectual property related to your supplier relationships.
-
Quarterly Business Reviews (QBR): For Critical suppliers, include a standing security agenda: incident review, patch status, access review, certification status, subcontractor changes.
Step 6: Supplier Audit, See for Yourself
Audit Planning:
| Element | Critical Supplier | High Supplier |
|---|---|---|
| Frequency | Annual | Every 2 years |
| Notice | 30 days | 30 days |
| Duration | 2-3 days | 1 day |
| Scope | Full ISMS review; technical controls; personnel; physical; subcontractors | Key controls; data protection; access control; incident management |
| Team | Internal auditor + security architect + compliance officer | Internal auditor + security analyst |
| overhead | - | - |
| Follow-up | CAP for findings; re-audit in 6 months if major findings | CAP for findings; evidence review in 3 months |
Audit Checklist (Critical Supplier):
| # | Area | Audit Questions | Evidence |
|---|---|---|---|
| 1 | Governance | Is there a documented security policy? Approved by management? | Policy document, approval record |
| 2 | Governance | Is there a security organization chart? Roles defined? | Org chart, job descriptions |
| 3 | Risk | Is there a risk register? Last updated? Methodology? | Risk register, methodology doc |
| 4 | Access | Is MFA enforced for all admin access? | Configuration screenshot, policy |
| 5 | Access | When was the last access review? Findings? | Access review report, minutes |
| 6 | Data | Is data encrypted at rest? Algorithm? Key management? | Configuration, encryption policy |
| 7 | Data | Is data encrypted in transit? TLS version? | SSL Labs scan, configuration |
| 8 | Incident | Is there an incident response plan? Tested? | IR plan, test records |
| 9 | Incident | What incidents occurred in the last 12 months? | Incident log (sanitized) |
| 10 | BC/DR | What is the RTO/RPO? Last DR test? | BCP, DR test report |
| 11 | Subcontractors | List all subcontractors. Assessments available? | Subcontractor list, assessments |
| 12 | Personnel | Background checks for staff with access? | Sample background check records |
| 13 | Physical | Secure area for our data? Access control? | Site walkthrough, photos |
| 14 | Technical | Vulnerability scan results? Pen test results? | Scan report, pen test report |
| 15 | Compliance | ISO 27001 certificate? SOC 2 report? Audit findings? | Certificates, reports, CARs |
Step 7: Incident Management with Suppliers
Supplier Incident Response Protocol:
-
Detection: Your SOC detects anomalous activity from a supplier account, or you receive a supplier breach notification, or you read about a supplier breach in the news.
-
Notification Verification: Contact the supplier's security team immediately. Verify the scope: what data, what systems, what timeframe, what is the root cause.
-
Impact Assessment: Determine if your data, systems, or customers are affected. Classify the incident internally per your incident response plan.
-
Containment:
- Disable supplier accounts if compromise is confirmed
- Revoke API keys, certificates, or VPN access
- Isolate supplier-connected systems if necessary
- Engage the supplier's incident response team for joint containment
-
Eradication: Work with the supplier to ensure the root cause is fixed. Require evidence of remediation before re-enabling access.
-
Recovery: Re-enable access under heightened monitoring. Conduct a security review of the supplier's improved controls.
-
Post-Incident:
- Update the supplier risk assessment
- Consider contract termination if the breach was due to gross negligence
- Update your incident response playbook with lessons learned
- Notify regulators if required (DPDP Act: 72 hours; RBI: 6 hours for payment incidents)
- Notify affected customers if personal data was compromised
Step 8: Change Management, When Suppliers Change
Supplier changes that must trigger a reassessment:
| Change Type | Risk Implication | Action Required |
|---|---|---|
| New subcontractor | Unknown fourth-party risk | Require disclosure; conduct assessment; update contract |
| Change in data processing location | DPDP/data residency violation | Verify new location compliance; update DPA; reassess |
| Change in key personnel | Loss of institutional knowledge; new insider risk | Verify background checks; update access; conduct handover |
| Change in technology stack | New vulnerabilities; integration risks | Architecture review; security testing; update monitoring |
| Merger or acquisition | New entity; unknown security posture | Full reassessment; contract novation; integration review |
| Certification lapse | Unverified security claims | Demand immediate recertification or enhanced monitoring |
| Service scope expansion | More data, more access, more risk | Update risk assessment; amend contract; additional controls |
Step 9: Termination and Offboarding, Close Securely
Termination Triggers:
- Contract natural expiry
- Early termination for convenience
- Termination for breach (including security breach)
- Supplier insolvency or business closure
- Service consolidation or replacement
Offboarding Checklist:
| # | Task | Owner | Timeline | Evidence |
|---|---|---|---|---|
| 1 | Notify supplier of termination (official) | Procurement | Day 0 | Termination letter/email |
| 2 | Revoke all system access (VPN, RDP, cloud, API, email) | IT / Security | Day 0 | Access revocation log |
| 3 | Disable supplier accounts in all systems | IT / Security | Day 0 | Account disablement log |
| 4 | Change shared passwords/credentials if any | IT / Security | Day 0 | Password change log |
| 5 | Revoke physical access (ID cards, biometrics, keys) | Facilities / Security | Day 0 | Access revocation record |
| 6 | Collect all company assets (laptops, devices, documents) | IT / Facilities | Day 1-7 | Asset return receipt |
| 7 | Request return of all data | Procurement / Data Owner | Day 1-7 | Data transfer log |
| 8 | Request certificate of data destruction | Procurement / Security | Day 14-30 | Destruction certificate |
| 9 | Verify data destruction (sample audit if possible) | Security / Internal Audit | Day 30-45 | Verification report |
| 10 | Remove supplier from monitoring and alert systems | Security Operations | Day 0 | Configuration change |
| 11 | Update supplier inventory status to "Terminated" | Vendor Risk Manager | Day 0 | Updated inventory |
| 12 | Retain termination records for audit/evidence | Vendor Risk Manager | Permanent | Archive record |
| 13 | Conduct post-termination review (lessons learned) | Vendor Risk Manager | Day 30-45 | Lessons learned log |
| 14 | Notify relevant stakeholders (legal, compliance, audit) | Procurement | Day 0 | Communication log |
| 15 | Update incident response plan (remove supplier references) | Security Operations | Day 7 | Updated IR plan |
Data Destruction Verification:
For Critical suppliers handling sensitive data, do not trust a self-signed certificate of destruction. Require:
- Detailed destruction methodology (NIST 800-88 Clear, Purge, or Destroy)
- Third-party attestation or audit of destruction
- Sample verification (if contract allows, request proof for a sample of records)
- Chain of custody documentation for data transfer before destruction
Tools, Technologies, and Solutions
Third-Party Risk Management (TPRM) Platforms
| Platform | Key Features | licensing Range | Best For |
|---|---|---|---|
| BitSight | External security ratings; continuous monitoring; portfolio analytics; benchmarking | Subscription | Large enterprises; portfolio risk management |
| SecurityScorecard | Security ratings; automated assessments; workflow automation; integrations | Subscription | Growing companies to enterprise; automated TPRM |
| UpGuard | Security ratings; vendor questionnaires; data leak detection; breach history | Subscription | Growing companies; data leak focus |
| Panorays | Automated security assessments; AI-driven risk analysis; remediation tracking | Subscription | Automated assessment; AI features |
| OneTrust Vendorpedia | Full TPRM lifecycle; regulatory compliance; DPIA; contract management | Subscription | Enterprise; privacy + security combo |
| Archer (RSA) | Enterprise GRC with TPRM module; deep customization; complex workflows | Enterprise licensing (custom) | Large enterprise; existing Archer GRC |
| MetricStream | GRC + TPRM; integrated risk management; regulatory mapping | Enterprise licensing (custom) | Large enterprise; integrated GRC |
| Sprinto (India) | Indian SaaS; ISO 27001 + TPRM; vendor assessments; continuous monitoring | Subscription | Indian SMEs; efficient; local support |
| Scrut Automation (India) | Indian SaaS; automated vendor assessments; security ratings; compliance | Subscription | Indian startups and SMEs; budget-friendly |
| Vanta | SOC 2 + ISO 27001 + TPRM; automated evidence collection; integrations | Subscription | US-market focused SaaS; fast certification |
| Drata | Compliance automation; vendor management; continuous control monitoring | Subscription | SaaS companies; compliance-first |
Contract and Procurement Tools
| Tool | Purpose | Integration with TPRM |
|---|---|---|
| Ironclad | Contract lifecycle management; clause library; approval workflows | API integrations with TPRM platforms |
| DocuSign CLM | Contract management; e-signature; template management | Integrations with Salesforce, GRC tools |
| Icertis | Enterprise contract management; AI-powered clause extraction | TPRM module available |
| Conga Contracts | Contract automation; template management; compliance tracking | CRM and ERP integrations |
| Zoho Contracts (India) | Affordable CLM for Indian SMEs; India-specific templates | Zoho ecosystem integration |
Discovery and Monitoring Tools
| Tool | Purpose | licensing Range |
|---|---|---|
| Productiv | SaaS application discovery; usage analytics; renewal management | Subscription |
| Torii | SaaS management; shadow IT discovery; spend optimization | Subscription |
| Netskope | Cloud access security broker (CASB); shadow IT discovery; DLP | Subscription |
| Obsidian Security | SaaS security; identity threat detection; configuration monitoring | Subscription |
| Google Alerts / Feedly | Free security news monitoring for suppliers | Free /Subscription |
| Recorded Future / Flashpoint | Threat intelligence; supplier risk monitoring; dark web | Subscription |
Indian Market Considerations
| Consideration | Guidance |
|---|---|
| Data residency | Ensure TPRM platforms store assessment data in India or comply with DPDP Act 2023 |
| GST and billing | Indian vendors (Sprinto, Scrut) bill in INR with GST, simplifying compliance |
| Local support | India-based support teams provide faster response and understand local regulatory context |
| Regional compliance | Indian TPRM platforms often include RBI, SEBI, IRDAI, and DPDP compliance templates |
| overhead efficiency | Indian TPRM platforms are typically 40-60% cheaper than US counterparts with comparable features |
| Language | Some platforms offer Hindi or regional language support for supplier communication |
Policy and Procedure Templates
Supplier Security Policy (Template Outline)
1. Purpose and Scope
1.1 Purpose: Define requirements for managing information security in all supplier relationships
1.2 Scope: All suppliers with access to information, systems, or premises
1.3 Applicability: All procurement, IT, security, facilities, and business teams
2. Roles and Responsibilities
2.1 CISO: Accountable for supplier security framework; approves Critical supplier engagements
2.2 Vendor Risk Manager: Responsible for TPRM program execution; assessments; monitoring; audits
2.3 Procurement: Responsible for including security clauses in contracts; enforcing procurement process
2.4 Legal: Responsible for contract security clause drafting; enforcement; termination
2.5 IT / Security Operations: Responsible for supplier access provisioning; monitoring; revocation
2.6 Data Owners: Responsible for defining data protection requirements for suppliers
2.7 Business Units: Responsible for identifying and registering all suppliers
3. Supplier Classification and Risk Tiering
3.1 Classification criteria (data, access, criticality, maturity, subcontractors)
3.2 Four-tier system: Critical, High, Medium, Low
3.3 Classification authority and review frequency
4. Supplier Security Assessment
4.1 Timing: Before contract signing; periodic reassessment
4.2 Methodology: SSQ + external ratings + audits
4.3 Evaluation criteria and scoring
4.4 Exception handling and risk acceptance
5. Contractual Security Requirements
5.1 Mandatory clauses for each tier
5.2 Data protection addendum requirements
5.3 Subcontractor control clauses
5.4 Right to audit and inspection
5.5 Incident notification and response
5.6 Termination and data return
6. Supplier Monitoring and Review
6.1 Monitoring frequency by tier
6.2 Continuous monitoring techniques
6.3 Quarterly business review requirements
6.4 Security news and alert monitoring
7. Supplier Audit Program
7.1 Audit frequency by tier
7.2 Audit planning and notification
7.3 Audit scope and checklist
7.4 Finding remediation and follow-up
8. Supplier Change Management
8.1 Changes requiring notification
8.2 Reassessment triggers
8.3 Contract amendment process
9. Supplier Incident Management
9.1 Incident notification requirements
9.2 Joint response protocol
9.3 Root cause analysis and remediation
9.4 Contract termination for security cause
10. Supplier Termination and Offboarding
10.1 Termination triggers
10.2 Offboarding checklist and timeline
10.3 Data return and destruction verification
10.4 Access revocation procedures
10.5 Post-termination review
11. Subcontractor and Fourth-Party Risk
11.1 Disclosure requirements
11.2 Assessment obligations
11.3 Liability and control
12. Training and Awareness
12.1 Procurement training on security clauses
12.2 Business unit training on supplier registration
12.3 Security team training on TPRM
13. Compliance and Audit
13.1 Internal audit requirements
13.2 Evidence retention
13.3 Non-conformance handling
14. Policy Review
14.1 Annual review cycle
14.2 Trigger-based review (incident, regulation, breach)
Supplier Security Procedure (Template Outline)
Procedure: SUP-SEC-001 Supplier Security Management Lifecycle
1. Supplier Identification and Registration
Step 1: Business unit identifies supplier need
Step 2: Procurement requests supplier registration
Step 3: Supplier completes registration form with access and data details
Step 4: Supplier added to inventory with unique ID
Step 5: Initial classification (Low default until assessment)
2. Pre-Engagement Assessment
Step 6: Vendor Risk Manager classifies supplier based on registration data
Step 7: For Critical/High: Full SSQ + external rating + certification review
Step 8: For Medium: Standard SSQ + certification review
Step 9: For Low: Light attestation or certification check
Step 10: Risk assessment completed and scored
Step 11: Risk treatment plan defined if gaps exist
Step 12: Security approval obtained before contract
3. Contracting
Step 13: Legal includes security clauses based on tier
Step 14: Data Owner confirms data protection requirements
Step 15: CISO approves Critical/High supplier contracts
Step 16: Contract signed and archived with security addendum
4. Onboarding and Access Provisioning
Step 17: IT provisions access per least privilege principle
Step 18: MFA enforced for all logical access
Step 19: Physical access provisioned (if applicable) with escort/area restrictions
Step 20: Supplier personnel complete security awareness training
Step 21: Supplier added to monitoring and alert systems
5. Ongoing Monitoring
Step 22: Monthly QBR for Critical suppliers (security agenda)
Step 23: Quarterly review for High suppliers
Step 24: Bi-annual review for Medium suppliers
Step 25: Annual light review for Low suppliers
Step 26: Continuous monitoring via security ratings and news alerts
Step 27: Access reviews quarterly for Critical/High suppliers
6. Audit
Step 28: Annual on-site audit for Critical suppliers
Step 29: Bi-annual virtual audit for High suppliers
Step 30: Audit findings documented; CAP issued; follow-up scheduled
7. Change Management
Step 31: Supplier notifies of material change
Step 32: Vendor Risk Manager evaluates change impact
Step 33: Reassessment conducted if required
Step 34: Contract amended if required
Step 35: Updated monitoring scope applied
8. Incident Response
Step 36: Incident detected or reported by supplier
Step 37: Impact assessment conducted
Step 38: Containment actions executed (access revocation if needed)
Step 39: Joint investigation with supplier
Step 40: Root cause analysis and remediation verification
Step 41: Risk assessment updated; contract termination considered if negligence
9. Termination and Offboarding
Step 42: Termination triggered (expiry, convenience, breach)
Step 43: Termination notice issued
Step 44: All access revoked within 24 hours
Step 45: Data return requested and verified
Step 46: Destruction certificate obtained and verified
Step 47: Assets collected and accounted for
Step 48: Supplier removed from inventory and monitoring
Step 49: Lessons learned captured
Supplier Security Questionnaire (SSQ) Template (Excerpt)
SUPPLIER SECURITY QUESTIONNAIRE
Supplier Name: _________________________
Assessment Date: _________________________
Assessed By: _________________________
Risk Tier: _________________________
SECTION A: GOVERNANCE AND POLICY (10 points)
A1. Do you have a documented information security policy?
□ Yes, approved by management, reviewed annually
□ Yes, but not reviewed recently
□ No
A2. Do you have a dedicated security function or CISO?
□ Yes, full-time CISO or security team
□ Yes, part-time or outsourced
□ No
A3. Have you achieved any of the following certifications?
□ ISO 27001 (current) — provide certificate
□ SOC 2 Type II (current) — provide report
□ PCI DSS (if applicable) — provide AOC
□ None
SECTION B: ACCESS CONTROL (15 points)
B1. Do you enforce Multi-Factor Authentication (MFA) for all administrative access?
□ Yes, for all admin accounts
□ Yes, for some admin accounts
□ No
B2. How frequently do you review user access rights?
□ Quarterly or more frequently
□ Annually
□ Ad-hoc or never
B3. Do you maintain a principle of least privilege for all users?
□ Yes, enforced and audited
□ Yes, but not formally audited
□ No
SECTION C: DATA PROTECTION (20 points)
C1. Is our data encrypted at rest? Algorithm?
□ AES-256 or equivalent
□ AES-128 or equivalent
□ No encryption
C2. Is our data encrypted in transit? Protocol?
□ TLS 1.3 or equivalent
□ TLS 1.2
□ Unencrypted or TLS 1.0/1.1
C3. Do you have a data retention and destruction policy?
□ Yes, documented and enforced
□ Yes, but not enforced
□ No
SECTION D: INCIDENT MANAGEMENT (15 points)
D1. Do you have an incident response plan?
□ Yes, documented, tested, and maintained
□ Yes, but not tested
□ No
D2. What is your incident notification timeframe to customers?
□ Within 24 hours
□ Within 72 hours
□ Within 1 week
□ No defined timeframe
D3. How many security incidents did you experience in the last 12 months?
□ 0
□ 1-2
□ 3-5
□ More than 5
SECTION E: BUSINESS CONTINUITY (10 points)
E1. What is your Recovery Time Objective (RTO)?
□ < 4 hours
□ < 24 hours
□ < 72 hours
□ > 72 hours or no RTO
E2. When was your last disaster recovery test?
□ Within 6 months
□ Within 12 months
□ > 12 months ago
□ Never
SECTION F: SUBCONTRACTORS (10 points)
F1. Do you use subcontractors for services related to our data?
□ No
□ Yes — list attached
□ Yes — but not disclosed
F2. Do you assess your subcontractors' security?
□ Yes, same standard as our own
□ Yes, but less rigorously
□ No
SECTION G: COMPLIANCE AND AUDIT (10 points)
G1. When was your last external security audit?
□ Within 12 months
□ Within 24 months
□ > 24 months ago
□ Never
G2. Are you willing to provide audit reports or undergo our audit?
□ Yes, fully cooperative
□ Yes, with restrictions
□ No
SECTION H: REGULATORY (10 points)
H1. Are you familiar with the Digital Personal Data Protection Act 2023 (India)?
□ Yes, and we comply
□ Yes, but not fully compliant
□ No
H2. Can you store and process all our data within India?
□ Yes
□ Yes, with some exceptions (specify)
□ No
SCORING:
Total Score: ___ / 100
Rating: □ Excellent (90-100) □ Good (70-89) □ Fair (50-69) □ Poor (30-49) □ Unacceptable (<30)
Risk Assessment and Treatment
Supplier Risk Assessment Methodology
Step 1: Inherent Risk Assessment
Inherent risk is the risk before considering the supplier's controls. It is determined by what the supplier does, not how well they do it.
| Factor | Score | Rationale |
|---|---|---|
| Data sensitivity | 1-5 | What data will the supplier access? |
| System access | 1-5 | What level of access to your systems? |
| Business criticality | 1-5 | How important is the service to operations? |
| Supplier location | 1-5 | Geographic risk (sanctions, data residency, cybercrime rate) |
| Subcontractor complexity | 1-5 | How many layers of subcontractors? |
| Inherent Risk Score | Sum of above | 5-25 scale |
Step 2: Control Effectiveness Assessment
Evaluate the supplier's security controls based on SSQ, certifications, and external ratings.
| Control Area | Weight | Supplier Score (1-5) | Weighted Score |
|---|---|---|---|
| Governance and policy | 15% | ___ | ___ |
| Access control | 20% | ___ | ___ |
| Data protection | 25% | ___ | ___ |
| Incident management | 10% | ___ | ___ |
| Business continuity | 10% | ___ | ___ |
| Subcontractor management | 10% | ___ | ___ |
| Compliance and audit | 10% | ___ | ___ |
| Control Effectiveness Score | 100% | ___ / 5 |
Step 3: Residual Risk Calculation
Residual Risk = Inherent Risk × (1 - Control Effectiveness/5)
| Residual Risk Score | Risk Level | Action |
|---|---|---|
| >15 | Critical | Do not engage unless no alternative; board-level risk acceptance; enhanced monitoring; contract termination clause |
| 10-15 | High | Conditional engagement with mandatory remediation; quarterly monitoring; annual audit |
| 5-9 | Medium | Standard engagement with standard monitoring; biennial review |
| <5 | Low | Standard engagement with lightweight monitoring; triennial review |
Sample Supplier Risk Register
| Supplier ID | Supplier Name | Category | Inherent Risk | Control Score | Residual Risk | Tier | Treatment | Status |
|---|---|---|---|---|---|---|---|---|
| SUP-001 | CloudServe India | Cloud Hosting | 20 | 4.2 | 3.2 | Critical | Standard + enhanced monitoring | Active |
| SUP-002 | DevTech Solutions | Software Dev | 18 | 3.0 | 7.2 | High | Conditional + remediation plan | Active |
| SUP-003 | PaySecure Gateway | Payment Processing | 22 | 4.5 | 2.4 | Critical | Standard + PCI DSS validation | Active |
| SUP-004 | CleanPro Services | Facilities | 8 | 2.5 | 4.0 | Medium | Standard | Active |
| SUP-005 | MarketBoost Agency | Marketing | 12 | 3.5 | 4.2 | Medium | Standard | Active |
| SUP-006 | GlobalLogistics | Courier | 10 | 2.0 | 6.0 | High | Conditional + access restriction | Active |
| SUP-007 | OffshoreDev Ltd | Development | 20 | 1.5 | 14.0 | Critical | Termination planned | Terminating |
| SUP-008 | BackupVault | Data Backup | 16 | 4.0 | 3.2 | High | Standard + encryption verification | Active |
| SUP-009 | TaxConsult Partners | Professional Services | 10 | 3.0 | 4.0 | Medium | Standard | Active |
| SUP-010 | TempStaff Agency | Staffing | 12 | 2.5 | 6.0 | High | Conditional + background checks | Active |
Risk Treatment Options
| Treatment | When to Use | Example | overhead |
|---|---|---|---|
| Avoid | High inherent risk with no compensating value | Do not engage OffshoreDev Ltd due to unacceptable security | Opportunity overhead |
| Mitigate | Supplier has potential but gaps exist | Require DevTech to implement MFA, SAST, and annual pen test | - |
| Transfer | Risk cannot be fully mitigated; supplier is necessary | Require cyber insurance; liability cap; indemnification clause | Insurance premium; legal overhead |
| Accept | Low residual risk; impact of treatment exceeds benefit | Accept CleanPro's medium risk with standard monitoring | Monitoring overhead only |
| Share | Joint venture or partnership where risk is mutual | Co-develop security controls; shared audit overhead; mutual liability | Shared investment |
Audit and Compliance Checklist
Use this checklist during internal audits, certification audits, and customer audits. Each question should be answered with evidence.
Policy and Governance (5 questions)
| # | Audit Question | Evidence Required | Pass Criteria |
|---|---|---|---|
| 1 | Is there a documented policy for managing information security in supplier relationships? | Policy document, version controlled, approved | Policy exists; covers all supplier types; approved within 12 months |
| 2 | Does the policy define roles and responsibilities for supplier security management? | Policy section or RACI matrix | Roles defined for procurement, security, legal, IT, business units |
| 3 | Is there a complete inventory of all suppliers with access to information/systems/premises? | Supplier inventory; procurement records; access logs | Inventory complete; no shadow suppliers; includes subcontractors |
| 4 | Are suppliers classified by risk tier (Critical, High, Medium, Low)? | Classification records; risk scoring methodology | All suppliers classified; methodology documented; review frequency defined |
| 5 | Does senior management review supplier security performance? | Meeting minutes; dashboard reports; management review records | At least quarterly review for Critical suppliers; actions documented |
Risk Assessment and Contracting (6 questions)
| # | Audit Question | Evidence Required | Pass Criteria |
|---|---|---|---|
| 6 | Is a security risk assessment conducted before engaging new suppliers? | Risk assessment records for new suppliers | 100% of sampled new suppliers have pre-engagement assessment |
| 7 | Are security requirements included in all supplier contracts? | Contract samples; clause library; redlined contracts | Security clauses in 100% of sampled contracts; clause library exists |
| 8 | Do contracts include data protection requirements (encryption, residency, DPA)? | Contract addenda; DPA templates | DPA for all personal data processors; encryption requirements present |
| 9 | Do contracts include incident notification requirements (timeframe, contact, cooperation)? | Contract clauses; incident response records | Notification clause in 100% of contracts; SLA defined (≤24 hours for Critical) |
| 10 | Do contracts include right to audit and inspect supplier controls? | Audit clause in contracts; audit records | Audit clause in Critical/High contracts; audits conducted per schedule |
| 11 | Do contracts include termination and data return/destruction clauses? | Termination clauses; offboarding records | Data return clause in 100% of contracts; destruction verification evidenced |
Monitoring and Audit (6 questions)
| # | Audit Question | Evidence Required | Pass Criteria |
|---|---|---|---|
| 12 | Is there a defined monitoring frequency for each supplier tier? | Monitoring schedule; calendar records | Schedule exists; aligns with tier definitions; executed as planned |
| 13 | Are Critical suppliers monitored at least quarterly? | QBR minutes; monitoring reports; metric reviews | Evidence of quarterly reviews for all Critical suppliers |
| 14 | Are security ratings or external assessments used for continuous monitoring? | Security rating platform subscription; rating reports | Platform in use for Critical/High; ratings reviewed; alerts acted upon |
| 15 | Are supplier security incidents monitored and tracked? | Incident log; supplier incident records; tracking system | Supplier incidents logged; impact assessed; corrective actions tracked |
| 16 | Are on-site or virtual audits conducted for Critical/High suppliers? | Audit plan; audit reports; CAPs; follow-up records | Critical: annual audit; High: biennial audit; evidence of execution |
| 17 | Are supplier access rights reviewed periodically? | Access review records; IAM logs | Quarterly for Critical/High; evidence of review and remediation |
Change and Incident Management (5 questions)
| # | Audit Question | Evidence Required | Pass Criteria |
|---|---|---|---|
| 18 | Are suppliers required to notify of material changes (subcontractors, location, technology)? | Change notification records; contract clauses | Notification clause exists; changes tracked; reassessments triggered |
| 19 | Is there a joint incident response protocol with Critical suppliers? | IR plan; joint response records; contact lists | Protocol documented; tested at least annually; contacts current |
| 20 | Are supplier-caused incidents investigated and root cause analyzed? | Incident reports; RCA documents; supplier CARs | Investigations conducted; supplier accountability enforced; CAPs tracked |
| 21 | Can the organization terminate supplier relationships for security cause? | Contract clauses; termination records | Termination for security cause clause exists; executed if needed |
| 22 | Are supplier incidents reported to regulators when required? | Regulatory filings; incident notification records | DPDP 72-hour notification; RBI 6-hour for payment; evidence of compliance |
Termination and Offboarding (5 questions)
| # | Audit Question | Evidence Required | Pass Criteria |
|---|---|---|---|
| 23 | Is there a documented offboarding procedure for suppliers? | Offboarding procedure; checklists; workflow | Procedure documented; covers access, data, assets, monitoring |
| 24 | Is all supplier access revoked within 24 hours of termination? | Access revocation logs; IAM records | 100% of sampled terminations: access revoked within 24 hours |
| 25 | Is data returned or destroyed upon termination, with verification? | Data return log; destruction certificate; verification evidence | Return/destruction evidenced; certificate obtained; verification conducted for Critical |
| 26 | Are supplier termination records retained for audit purposes? | Archive records; retention policy | Retained per policy (minimum 7 years); accessible for audit |
| 27 | Are lessons learned from supplier incidents and terminations captured? | Lessons learned log; knowledge base updates | Captured within 30 days; fed into policy/template updates |
Subcontractor and Fourth-Party Risk (3 questions)
| # | Audit Question | Evidence Required | Pass Criteria |
|---|---|---|---|
| 28 | Are all subcontractors disclosed by primary suppliers? | Subcontractor lists; contract clauses; disclosure records | Disclosure clause in contracts; lists obtained for Critical/High |
| 29 | Are subcontractors assessed for security risk? | Subcontractor assessments; risk registers | Assessments conducted for subcontractors of Critical suppliers |
| 30 | Does the primary supplier remain liable for subcontractor security breaches? | Contractual liability clauses; incident records | Liability clause in 100% of contracts; enforced in incidents |
Metrics and KPIs
Supplier Security KPIs
| KPI ID | KPI Name | Formula | Target | Measurement Frequency | Data Source |
|---|---|---|---|---|---|
| KPI-01 | Supplier Inventory Coverage | (Suppliers in inventory / Total known suppliers) × 100 | 100% | Monthly | Inventory vs. finance/AP records |
| KPI-02 | Risk Assessment Completion | (Suppliers with completed risk assessment / Total active suppliers) × 100 | 100% | Monthly | Risk register |
| KPI-03 | Critical Supplier Assessment Rate | (Critical suppliers with current assessment / Total Critical suppliers) × 100 | 100% | Monthly | Risk register |
| KPI-04 | Security Clause Coverage | (Contracts with security clauses / Total active contracts) × 100 | 100% | Quarterly | Contract review sample |
| KPI-05 | Audit Execution Rate | (Audits completed per plan / Audits planned) × 100 | 100% | Quarterly | Audit calendar |
| KPI-06 | Supplier Incident Count | Number of security incidents caused by or involving suppliers | 0 for Critical; trend downward | Monthly | Incident management system |
| KPI-07 | Incident Notification Compliance | (Supplier incidents notified within SLA / Total supplier incidents) × 100 | 100% | Per incident | Incident records |
| KPI-08 | Access Review Completion | (Supplier access reviews completed on schedule / Total scheduled reviews) × 100 | 100% | Quarterly | Access review records |
| KPI-09 | Termination Offboarding Compliance | (Terminations with complete offboarding / Total terminations) × 100 | 100% | Per termination | Offboarding records |
| KPI-10 | Security Rating Trend | Average security rating of Critical suppliers (month-over-month) | Improving or stable | Monthly | Security rating platform |
| KPI-11 | Shadow Supplier Discovery | Number of unregistered suppliers discovered per month | 0 | Monthly | Discovery process |
| KPI-12 | DPA Coverage for Data Processors | (Data processors with signed DPA / Total data processors) × 100 | 100% | Quarterly | Contract review |
| KPI-13 | Supplier Change Notification Compliance | (Supplier changes notified per contract / Total observed changes) × 100 | >90% | Quarterly | Change records |
| KPI-14 | Subcontractor Disclosure Rate | (Critical suppliers with disclosed subcontractors / Total Critical suppliers) × 100 | 100% | Quarterly | Subcontractor lists |
| KPI-15 | Supplier Security Training Completion | (Procurement staff completing supplier security training / Total procurement staff) × 100 | 100% | Annual | Training records |
KPI Dashboard Layout
SUPPLIER SECURITY DASHBOARD — June 2026
========================================
Active Suppliers: 187
Critical: 12 | High: 34 | Medium: 78 | Low: 63
New This Month: 5 | Terminated This Month: 2
COVERAGE METRICS
- Inventory Coverage: 100% (187/187) ✓
- Risk Assessment Completion: 98% (183/187) ⚠️
- Security Clause Coverage: 97% (181/187) ⚠️
- DPA Coverage: 100% (45/45) ✓
QUALITY METRICS
- Audit Execution Rate: 100% (8/8) ✓
- Access Review Completion: 100% (46/46) ✓
- Offboarding Compliance: 100% (2/2) ✓
RISK METRICS
- Supplier Incidents (MTD): 1 (Medium severity, contained) ⚠️
- Security Rating Trend: Stable (avg 78/100)
- Shadow Suppliers Discovered: 0 ✓
ACTIONS
1. Complete risk assessment for 4 pending Medium suppliers (SUP-184 to SUP-187)
2. Renegotiate security clauses with 6 suppliers missing data residency terms
3. Schedule Q3 audit for SUP-012 (CloudServe India) — certificate expiry approaching
Common Pitfalls and How to Avoid Them
The 15 Most Common Pitfalls
| # | Pitfall | Why It Happens | Impact | How to Avoid |
|---|---|---|---|---|
| 1 | No supplier inventory | Procurement and IT do not coordinate; shadow IT proliferates | Unknown risk exposure; audit failure | Mandatory registration process; finance cross-check; SaaS discovery tools |
| 2 | Generic security clauses in all contracts | Legal uses one template for all vendors | Inadequate protection for Critical suppliers; unenforceable terms | Tiered clause library; Critical/High get full clauses; Low gets lightweight |
| 3 | No pre-engagement assessment | Business urgency; "we need them now" | Engaging high-risk suppliers without knowing it | Security approval gate before contract signature; no exceptions for Critical |
| 4 | Assessment never revisited after initial engagement | "We assessed them last year; they must be fine" | Supplier security degrades; certifications lapse; incidents missed | Calendar-driven reassessment; expiry alerts; continuous monitoring |
| 5 | No monitoring of supplier security news | No process to track supplier breaches | Breach discovered months late; customer data already leaked | Google Alerts; security rating platform; threat intelligence feed |
| 6 | Subcontractors ignored | Primary supplier does not disclose; organization does not ask | Fourth-party risk is invisible; major breach vector | Mandatory disclosure clause; request subcontractor lists; assessment for Critical |
| 7 | Access not revoked promptly on termination | HR/procurement delays; IT not informed; "we might need them again" | Former supplier retains access; data exposure; audit failure | Automated offboarding workflow; 24-hour SLA; checklist with sign-offs |
| 8 | Data left with supplier after termination | No data return requirement; no verification | Supplier retains your data indefinitely; DPDP violation | Data return clause; destruction certificate; sample verification |
| 9 | Supplier incidents not investigated | "It's their problem, not ours" | Recurrence; liability; regulatory penalty | Joint investigation protocol; root cause analysis; contract enforcement |
| 10 | No right to audit exercised | Audit clause exists but never used; "we trust them" | Unverified security claims; false assurance | Annual audit calendar; budget for audits; treat as non-negotiable |
| 11 | Over-reliance on certifications | "They have ISO 27001, so they're secure" | Certification does not mean perfect security; scope may not cover your data | Trust but verify; certification + SSQ + monitoring + audit |
| 12 | Small suppliers exempted | "They're too small to matter" | Small vendors are often the weakest link; used as attack vector | All suppliers assessed; lightweight process for Low tier; no exemptions |
| 13 | Physical security suppliers ignored | Focus on IT; cleaning/security guards "not technical" | Physical theft; dumpster diving; tailgating; device access | Include facilities suppliers in inventory; background checks; physical access controls |
| 14 | No integration between procurement and security | Procurement buys; security finds out later | Security as afterthought; renegotiation overhead; delays | Security approval workflow in procurement system; security checkpoint before PO |
| 15 | DPDP Act requirements ignored in supplier contracts | Legal unaware of DPDP; "we'll add it later" | Regulatory violation; fine exposure; customer trust loss | DPDP clause library; legal training; mandatory DPA for all personal data processors |
Illustrative Scenarios
Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.
Illustrative Scenario 1: Indian Growing SaaS Company, Building TPRM from Scratch
Organization: CloudCraft Solutions Pvt. Ltd., a Hyderabad-based SaaS company with 320 employees, providing project management software to 4,000+ SMB customers in India and Southeast Asia. Annual revenue: .
Challenge:
- 85 active suppliers, but no formal inventory; estimated 30+ shadow suppliers
- Preparing for first SOC 2 Type II audit and ISO 27001 certification
- No security clauses in 60% of contracts
- Customer audit from a large enterprise client identified supplier security gaps
- Budget: for TPRM program setup
Implementation Steps:
Step 1, Supplier Discovery (Week 1): Singahi conducted a complete discovery:
- Finance record analysis: 87 paid vendors in last 12 months
- IT access log analysis: 23 external accounts with system access
- Cloud IAM analysis: 12 external IAM users in AWS
- Department survey: 15 additional suppliers not in finance records
- Total discovered: 107 suppliers (22 more than initially known)
Step 2, Classification and Tiering (Week 2): Using the risk framework:
- Critical: 8 (cloud hosting, payment gateway, core development vendor, customer support BPO)
- High: 18 (CRM, email, backup, legal, accounting, major IT consultants)
- Medium: 35 (marketing tools, recruitment, training, minor consultants)
- Low: 46 (office supplies, couriers, travel, minor services)
Step 3, Policy and Templates (Week 3): Singahi delivered:
- Supplier Security Policy (aligned with DPDP Act 2023, SOC 2, and ISO 27001)
- Tiered contract clause library (Critical: 15 clauses; High: 12 clauses; Medium: 8 clauses; Low: 4 clauses)
- Standard Supplier Security Questionnaire (SSQ) with 80 questions across 8 domains
- Offboarding checklist with 15 tasks and evidence requirements
Step 4, Critical Supplier Assessment (Weeks 4-5): All 8 Critical suppliers assessed:
- Cloud hosting provider (AWS India): ISO 27001 + SOC 2; score 94/100, Excellent
- Payment gateway (Razorpay): PCI DSS Level 1; score 91/100, Excellent
- Core development vendor (Bengaluru ODC): No ISO 27001; score 58/100, Fair
- Customer support BPO (Chennai): No certifications; score 45/100, Poor
- Backup provider: ISO 27001; score 88/100, Good
- Email/SaaS provider (Google Workspace): SOC 2; score 95/100, Excellent
- CDN/WAF provider (Cloudflare): SOC 2; score 92/100, Excellent
- Penetration testing vendor (Astra Security): ISO 27001; score 89/100, Good
Step 5, Remediation and Contract Amendments (Weeks 6-8):
- Core development vendor: Required to achieve ISO 27001 within 12 months; interim: enhanced monitoring, quarterly SSQ, mandatory SAST/DAST on all deliverables, secure coding training for 20 developers. Contract amended with security addendum and liability cap.
- Customer support BPO: Required to implement MFA, quarterly access reviews, incident notification within 24 hours, and annual pen test. Contract amended with security milestones and right to audit. Score improved to 68/100 within 6 months.
- All 8 Critical suppliers: Contract amendments signed with new security clauses.
- High suppliers: Batch contract review; 14 of 18 amended successfully; 4 in negotiation.
Step 6, Monitoring Setup (Week 9):
- Subscribed to SecurityScorecard for 8 Critical + 10 High suppliers (/year)
- Configured Google Alerts for all 107 suppliers
- Quarterly Business Review (QBR) calendar established for Critical suppliers
- Access review calendar: quarterly for Critical/High; bi-annual for Medium
Step 7, Offboarding Test (Week 10): Tested offboarding with 1 departing Low supplier:
- Access revoked in 4 hours (exceeded 24-hour target)
- Data return: 500 GB of backup logs transferred and verified
- Destruction certificate obtained
- Lessons learned: improve asset collection process for remote suppliers
Step 8, Training and Rollout (Week 11):
- Procurement team trained on security clause library and approval workflow (4 hours)
- IT team trained on access provisioning and revocation procedures (2 hours)
- Business unit heads trained on supplier registration requirement (1 hour)
- Policy communicated to all 107 suppliers via email with acknowledgment request
Outcome:
- SOC 2 Type II audit (Month 6): zero exceptions in the vendor management trust services criteria
- ISO 27001 Stage 2 audit (Month 8): zero major non-conformities in A.5.19; one minor (missing access review for 1 Medium supplier, fixed in 48 hours)
- Customer audit from large enterprise client: passed with commendation for "mature TPRM for company size"
- Total investment: (under budget)
- Supplier security incidents in first 12 months: 1 (supplier phishing attempt; contained within 2 hours due to monitoring)
- Core development vendor achieved ISO 27001 certification in Month 10
- CloudCraft's TPRM program became a reference model for 3 peer companies in their Hyderabad tech cluster
Key Lessons:
- Growing SaaS companies can build effective TPRM in 10-12 weeks with focused effort and templates
- Shadow supplier discovery is critical, 20% of suppliers were invisible before the program
- Tiered contract clauses are essential, one-size-fits-all contracts leave gaps or create unnecessary burden
- Security rating platforms provide continuous visibility at reasonable overhead for growing companies
- Customer audits are powerful motivators, use them to justify TPRM investment to management
Illustrative Scenario 2: Large Indian Enterprise Bank, Enterprise TPRM Transformation
Organization: Bharat National Bank (BNB), a Mumbai-headquartered public sector bank with 28,000 employees, 4,500 branches, 12,000 ATMs, and total assets of . Regulated by RBI under the Banking Regulation Act.
Challenge:
- 2,400+ active suppliers across IT, facilities, professional services, BPO, ATM maintenance, cash logistics, and consulting
- RBI Master Direction on Digital Payment Security mandates complete vendor risk management
- 200+ Critical suppliers with access to core banking systems, payment networks, and customer data
- Legacy TPRM process was manual, spreadsheet-based, and conducted annually, inadequate for current threat landscape
- Multiple audit findings: inconsistent supplier assessments, missing security clauses, no continuous monitoring, delayed incident notification
- Budget: for TPRM transformation over 18 months
Implementation Steps:
Step 1, Program Establishment (Months 1-2): Singahi established a dedicated Vendor Risk Management (VRM) function:
- Hired Vendor Risk Manager (reporting to CISO)
- 4 Vendor Risk Analysts (2 for Critical, 2 for High)
- Governance: Monthly VRM Committee with CISO, CIO, CRO, Head of Procurement, and Head of Legal
- Policy: Complete rewrite of Supplier Security Policy with RBI-specific requirements
Step 2, Enterprise Inventory and Discovery (Months 2-4):
- Migrated from spreadsheets to OneTrust Vendorpedia TPRM platform (/year)
- Integrated with SAP Ariba (procurement) for automatic supplier registration
- Integrated with Active Directory and VPN logs for access-based supplier discovery
- Integrated with AWS, Azure, and GCP IAM for cloud-based supplier discovery
- Final inventory: 2,847 suppliers (447 more than previously known)
- Shadow supplier reduction: 78% of newly discovered suppliers registered within 60 days
Step 3, Risk Classification at Scale (Months 3-5):
- Automated risk scoring based on: data sensitivity, system access, annual spend, certification status, location
- Critical: 247 (up from 200 due to better visibility)
- High: 512
- Medium: 1,034
- Low: 1,054
Step 4, Assessment Automation (Months 4-8):
- Automated SSQ distribution via OneTrust to all 2,847 suppliers
- 78% response rate within 30 days; follow-up for non-responders
- External security ratings (BitSight) integrated for all Critical and High suppliers
- Automated risk score calculation: inherent risk × control effectiveness
- 312 suppliers flagged for remediation; 18 flagged for potential termination
Step 5, Contract Remediation at Scale (Months 6-12):
- Legal team engaged in largest contract remediation effort in bank history
- 2,100 contracts reviewed; 1,680 required amendment
- Critical suppliers: 100% amended with full security addendum (15 clauses + RBI-specific requirements)
- High suppliers: 85% amended; 15% in negotiation or replacement
- New contract template: Security addendum is mandatory; no PO issued without security sign-off from VRM
- Data residency clause: All customer financial data must remain in India; no cross-border processing without RBI approval and explicit customer consent
Step 6, Continuous Monitoring (Months 8-14):
- BitSight ratings reviewed daily for Critical; weekly for High
- Automated alerts for: certification expiry, rating drop >20 points, breach news, dark web mentions
- Monthly QBRs for all 247 Critical suppliers with standard security agenda
- Quarterly access reviews for all Critical/High supplier accounts
- Penetration testing of supplier-facing APIs and portals: quarterly
Step 7, Audit Program (Months 10-16):
- 50 on-site audits conducted for Critical suppliers (ATM maintenance, cash logistics, core banking integrators, cloud providers)
- 120 virtual audits conducted for High suppliers
- Average audit overhead: per on-site; per virtual
- Total audit findings: 340; 98% closed within 90 days; 2% escalated to contract termination
- Subcontractor audits: 15 audits of subcontractor facilities (primarily offshore development centers and BPOs)
Step 8, Incident Response Integration (Months 12-16):
- Joint incident response protocol established with top 20 Critical suppliers
- 24/7 security contact matrix with escalation paths
- Supplier incident tabletop exercise: conducted quarterly with 3 suppliers rotating per quarter
- Actual incident during Month 14: BPO supplier detected unauthorized access attempt; notified BNB within 4 hours; joint containment within 2 hours; no data exposure; supplier's access suspended for 48 hours pending investigation; root cause: supplier employee credential phishing; supplier enhanced MFA and training; relationship continued with enhanced monitoring
Step 9, Termination and Offboarding Hardening (Months 14-16):
- Automated offboarding workflow in ServiceNow: termination trigger → access revocation tickets → data return tracking → certificate verification
- 12 suppliers terminated during program (security cause: 3; business: 9)
- Average offboarding time: 18 hours for access revocation; 14 days for data return/destruction
- 100% of terminations completed with full evidence package
Step 10, Regulatory Compliance and Certification (Months 16-18):
- RBI inspection (Month 17): VRM program reviewed; zero adverse findings; commended for "strong vendor risk management among public sector banks"
- ISO 27001 surveillance audit (Month 18): zero non-conformities in A.5.19 and A.5.14
- Internal audit: VRM program maturity rated Level 4 (Managed) on the CMMI scale
Outcome:
- Supplier security incidents: 3 in 18 months (all detected and contained within 4 hours due to monitoring)
- Estimated breach overhead avoided: (based on average financial sector breach overhead in India)
- Audit findings pre-program: 47 annually; post-program: 3 annually (93% reduction)
- Customer trust: 2 major enterprise clients renewed contracts citing "strong supplier security governance" as a factor
- Total investment: (under budget); ROI: 13x based on avoided breach overhead alone
- BNB's VRM program became a illustrative scenario in RBI's industry guidance circular on vendor risk management
Key Lessons:
- Enterprise TPRM requires dedicated technology, manual spreadsheets do not scale beyond 100 suppliers
- Procurement system integration is essential for preventing shadow suppliers and enforcing security gates
- RBI-regulated banks must go beyond ISO 27001 minimums; regulator expectations are higher than standard
- Subcontractor audits are non-negotiable for Critical suppliers in BFSI, 15% of audit findings were in subcontractor facilities
- Automated offboarding is critical at scale, manual processes fail under volume and time pressure
- The investment in TPRM () is insignificant compared to the impact of a single supplier-related breach in banking (+ Crore)
Multi-Framework Mapping
ISO 27001:2022 ↔ SOC 2 ↔ PCI DSS ↔ NIST 800-53 ↔ CIS Controls ↔ COBIT 2019 ↔ GDPR/DPDP
| ISO 27001:2022 A.5.19 | SOC 2 Trust Service Criteria | PCI DSS v4.0 | NIST 800-53 Rev 5 | CIS Controls v8 | COBIT 2019 | GDPR / DPDP Act 2023 |
|---|---|---|---|---|---|---|
| Information security in supplier relationships | CC9.1, Risk identification and management; CC9.2, Vendor management; CC3.2, Risk assessment for third parties; CC7.2, System operations for vendor access | Req 12.8, Security impact of third-party personnel; Req 12.8.1, Third-party due diligence; Req 12.8.2, Third-party agreements; Req 12.8.3, Third-party due diligence evidence; Req 12.8.4, Third-party security policy; Req 12.8.5, Third-party PCI DSS compliance; Req 12.9, Incident response for third parties; Req 12.10, Incident response procedures | SA-9, External Information System Services; SA-10, Developer Configuration Management; SA-11, Developer Security Testing and Evaluation; SA-12, Supply Chain Protection; SA-15, Development Process, Standards, and Tools; SA-17, Developer Security Architecture and Design; RA-3, Risk Assessment; PS-7, Personnel Termination (for supplier staff); IR-7, Incident Response Assistance; IR-8, Incident Response Plan; CA-2, Security Assessments | CIS 1.0, Inventory and Control of Enterprise Assets; CIS 2.0, Inventory and Control of Software Assets; CIS 15.0, Service Provider Management; CIS 16.0, Application Software Security; CIS 17.0, Incident Response Management | APO10.01, Manage vendors; APO10.02, Manage vendor risk; APO10.03, Manage vendor contracts; APO10.04, Manage vendor performance; APO12.01, Manage risk; APO13.01, Manage security; BAI03.02, Manage projects (supplier involvement); DSS05.01, Manage security services; MEA01.01, Monitor and evaluate performance | GDPR Art. 28, Processor obligations and contract requirements; GDPR Art. 32, Security of processing (extends to processors); GDPR Art. 33, Breach notification (processor must notify controller); GDPR Art. 35, DPIA (processor cooperation); DPDP Act 2023 Section 8(5), Security safeguards (applies to data processors); DPDP Act 2023 Section 8(2), Obligations of data fiduciaries regarding processors (as prescribed); DPDP Act 2023 Section 9, Additional safeguards for children's data (processor obligations) |
Detailed Control Mapping
ISO 27001 A.5.19 → NIST 800-53 Rev 5:
| A.5.19 Requirement | NIST 800-53 Control | NIST Control Description |
|---|---|---|
| Supplier risk assessment | RA-3, Risk Assessment | Assess risk from external services and supply chain |
| Security requirements in contracts | SA-9, External Information System Services | Establish security requirements for external providers |
| Supplier monitoring | CA-2, Security Assessments | Periodically assess external provider controls |
| Right to audit | SA-9(1), External Information System Services | Require external providers to meet organizational security requirements |
| Incident notification | IR-7, Incident Response Assistance | Establish agreements for incident response support |
| Subcontractor management | SA-12, Supply Chain Protection | Protect against supply chain risks |
| Termination and data return | PS-7, Personnel Termination | Terminate access for external personnel when relationship ends |
| Change management | SA-9(2), External Information System Services | Address changes in external services |
ISO 27001 A.5.19 → CIS Controls v8:
| A.5.19 Requirement | CIS Control | CIS Safeguard |
|---|---|---|
| Supplier inventory and risk assessment | CIS 15.1 | Establish and Maintain an Inventory of Service Providers |
| Security requirements in contracts | CIS 15.2 | Establish and Maintain a Service Provider Management Policy |
| Supplier monitoring | CIS 15.3 | Classify and Track Service Providers |
| Risk-based monitoring | CIS 15.4 | Assess Service Providers |
| Incident management with suppliers | CIS 15.5, (implied in CIS 17.0) | Manage Security Incidents |
| Data return on termination | CIS 15.6 | Ensure Service Providers Have a Secure Development Lifecycle |
ISO 27001 A.5.19 → COBIT 2019:
| A.5.19 Requirement | COBIT Domain | COBIT Practice |
|---|---|---|
| Supplier relationship management | APO10 | Managed Vendors |
| Supplier risk assessment | APO12 | Manage Risk |
| Supplier security requirements | APO13 | Managed Security |
| Supplier monitoring | MEA01 | Monitor, Evaluate and Assess Performance |
| Supplier incident management | DSS05 | Managed Security Services |
| Supplier change management | BAI06 | Managed Change |
| Supplier termination | APO10.04 | Manage Vendor Performance |
Regulatory and Industry Context
India-Specific Regulations
| Regulation | Relevance to A.5.19 | Key Supplier Requirements | Penalty for Non-Compliance |
|---|---|---|---|
| DPDP Act 2023 | Critical | Data fiduciary remains liable for processor breaches; processors must meet security safeguards; data localization; DPA mandatory; breach notification by processor to fiduciary | Up to for data fiduciary; processor liability under contract and potential direct liability under future rules |
| IT Act 2000 (Section 43A) | High | Body corporate liable for negligence by "any person who has access to sensitive personal data", includes suppliers | Compensation claims; no statutory cap |
| RBI Master Direction on Digital Payment Security | Critical for BFSI | Vendor due diligence; contractual security controls; vendor access management; incident reporting; vendor audit rights; data localization | License conditions; restrictions; penalties; business shutdown in extreme cases |
| RBI Master Circular on Cyber Security | Critical for banks | Third-party risk management; vendor security assessments; continuous monitoring; subcontractor control; vendor incident reporting | Same as above |
| SEBI Circular CIR/MIRSD/2/2011 | Critical for market infrastructure | Vendor risk management for stock exchanges, depositories, clearing corporations; security clauses; audit rights; incident reporting | SEBI enforcement; trading restrictions; penalties |
| SEBI Circular for AMCs/KRAs | Critical for asset management | Vendor risk management; cybersecurity framework; data protection; vendor assessments | SEBI enforcement; license conditions |
| IRDAI Guidelines on Information and Cyber Security | Critical for insurance | Vendor security management; third-party risk assessments; contractual controls; incident reporting | License conditions; business restrictions |
| CERT-In Directions 2022 | High for all | Incident reporting obligations extend to supplier-caused incidents; data localization for certain sectors; log retention | Service blocking; legal action; directions |
| MeitY Intermediary Rules 2021 | High for platforms | Security measures must extend to vendors; data retention; traceability; grievance redressal | Safe harbour loss; blocking; liability |
| Companies Act 2013 (Section 134) | Moderate for all | Board responsibility for internal financial controls; auditor independence; related party transactions | Director liability; fines; imprisonment for fraud |
| IBC (Insolvency and Bankruptcy Code) | Moderate | Supplier insolvency can disrupt business continuity; security of data during insolvency proceedings | Operational disruption; data exposure risk |
International Regulations
| Regulation | Jurisdiction | Supplier Security Relevance |
|---|---|---|
| GDPR (Regulation 2016/679) | EU + EEA | Art. 28: Processor must meet security requirements; written contract/DPA mandatory; processor liability; sub-processor consent and control; breach notification to controller within 24 hours |
| CCPA/CPRA | California, USA | "Service provider" and "contractor" definitions with security obligations; third-party data sales restrictions; breach notification |
| HIPAA Security Rule | USA healthcare | Business Associate Agreement (BAA) mandatory; business associate liable for breaches; security safeguards; subcontractor control |
| NIS2 Directive | EU | Supply chain security; ICT product and service security; third-party risk management; incident reporting; security by design for critical entities |
| SOX Section 404 | USA public companies | Third-party service organizations in internal controls; SOC 1 Type II reports for financial process vendors; auditor reliance on vendor controls |
| PCI DSS v4.0 | Global | Req 12.8: Third-party due diligence; contractual security requirements; third-party PCI DSS compliance; evidence of compliance; incident management |
| FedRAMP | USA federal cloud | Third-party assessment organizations (3PAOs); continuous monitoring; security controls for cloud service providers; agency ATO dependencies |
| APPI (Japan) | Japan | Third-party supervision obligation; personal information protection in outsourcing; data transfer restrictions |
| PDPA (Singapore) | Singapore | Protection obligation extends to data intermediaries; contractual security requirements; data breach notification; DPIA for high-risk processing |
| LGPD (Brazil) | Brazil | Security measures for processing; data processor obligations; contractual requirements; breach notification; DPIA |
| POPIA (South Africa) | South Africa | Information officer responsible for operator security; written contract with operators; breach notification; data subject rights |
Industry-Specific Context
| Industry | Supplier Security Considerations | Key Standards/Best Practices |
|---|---|---|
| Banking and Financial Services | RBI-mandated vendor management; payment processor PCI DSS; core banking vendor security; ATM/cash logistics physical security; fintech partnerships | RBI Master Directions, PCI DSS, ISO 27001, NIST CSF, COBIT |
| Insurance | IRDAI-mandated vendor controls; claim processing BPO security; policy data protection; agent/broker access management | IRDAI guidelines, ISO 27001, COBIT |
| Healthcare and Pharma | Patient data protection (sensitive personal data); clinical trial vendor management; drug safety data; medical device security (MDR/IVDR) | HIPAA, DPDP Act, GxP, ISO 27001, IEC 62304 |
| IT/ITES and SaaS | Client-mandated supplier audits; multi-tenant isolation; API security; development vendor security; cloud shared responsibility | SOC 2, ISO 27001, ISO 27017, CSA STAR, OWASP |
| Manufacturing | OT/IT supplier security; ICS system integrators; IoT device supply chain integrity; counterfeit prevention; Industry 4.0 | IEC 62443, NIST SP 800-82, ISO 27001, supply chain integrity frameworks |
| Retail and E-commerce | Payment gateway security; marketplace vendor access; logistics partner data; customer data protection; loyalty program security | PCI DSS, DPDP Act, ISO 27001 |
| Education (EdTech) | Children's data protection (DPDP); student privacy; third-party content providers; online assessment security; international student data | DPDP Act, COPPA (USA), FERPA (USA), ISO 27001 |
| Government and Public Sector | CERT-In compliance; e-governance vendor security; citizen data protection; national security considerations; make-in-India preferences | CERT-In directions, ISO 27001, GIGW, additional security clearances |
| Telecom | Network equipment vendor security (5G, Huawei/ZTE considerations); subscriber data protection; lawful interception vendor controls; tower infrastructure | DoT security requirements, 3GPP, ISO 27001, GSMA security guidelines |
| Energy and Utilities | Critical infrastructure protection; SCADA/ICS vendor security; smart grid supply chain; renewable energy IoT; NERC CIP (USA equivalent) | CERC guidelines, IEC 62351, NERC CIP, ISO 27001, NIST CSF |
Roles and Responsibilities (RACI)
Supplier Security Activities RACI Matrix
| # | Activity | Board / CEO | CISO | CIO | Head of Procurement | Legal Counsel | Vendor Risk Manager | Vendor Risk Analyst | IT / Security Operations | Data Owner | Business Unit Head | Compliance Officer |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Approve Supplier Security Policy | A | R | C | C | C | C | I | I | I | I | C |
| 2 | Define Supplier Risk Framework | I | A | C | C | C | R | C | I | I | I | C |
| 3 | Maintain Supplier Inventory | I | C | C | R | I | R | R | C | C | C | I |
| 4 | Classify Supplier Risk Tier | I | A | C | C | I | R | C | I | C | C | I |
| 5 | Conduct Supplier Security Assessment | I | C | I | C | I | R | R | C | C | I | I |
| 6 | Review Supplier Certifications/Audits | I | C | I | I | I | R | R | C | I | I | C |
| 7 | Draft Security Contract Clauses | I | C | I | C | R | C | I | I | C | I | C |
| 8 | Negotiate Security Terms with Suppliers | I | C | I | R | R | C | I | I | I | I | I |
| 9 | Approve Critical Supplier Contracts | A | R | C | C | C | C | I | I | I | I | C |
| 10 | Provision Supplier Access | I | C | R | I | I | C | I | R | C | I | I |
| 11 | Monitor Supplier Security Posture | I | A | I | I | I | R | R | R | I | I | C |
| 12 | Conduct Supplier Security Audit | I | A | I | I | I | R | R | C | C | I | C |
| 13 | Manage Supplier Security Incidents | I | A | C | I | I | R | C | R | C | I | C |
| 14 | Execute Supplier Change Reassessment | I | C | I | C | I | R | C | C | C | C | I |
| 15 | Execute Supplier Offboarding | I | C | R | C | C | R | C | R | C | I | I |
| 16 | Verify Data Return/Destruction | I | C | I | I | I | R | C | C | C | I | C |
| 17 | Update Supplier Risk Register | I | C | I | I | I | R | R | C | C | I | I |
| 18 | Report Supplier Security Metrics | I | R | C | C | C | R | C | I | I | I | C |
| 19 | Audit TPRM Program Compliance | I | A | I | I | I | C | I | I | I | I | R |
| 20 | Drive Continuous Improvement | I | A | C | C | C | R | C | C | C | C | C |
| 21 | Approve Subcontractor Engagements | I | A | C | C | C | R | C | I | I | I | C |
| 22 | Define Data Protection Requirements for Suppliers | I | C | I | I | I | C | I | I | R | C | C |
| 23 | Train Business Units on Supplier Registration | I | C | I | C | I | R | C | I | I | C | I |
| 24 | Manage Supplier Security Budget | A | C | C | R | I | C | I | I | I | I | I |
Legend:
- R = Responsible (does the work)
- A = Accountable (ultimately answerable; approves)
- C = Consulted (provides input)
- I = Informed (kept updated)
Role Descriptions
| Role | Key Responsibilities | Typical Designation in Indian Organizations |
|---|---|---|
| Board / CEO | Strategic oversight; policy approval; budget for enterprise TPRM; risk acceptance for catastrophic supplier risks | Managing Director, CEO, Chairman |
| CISO | Accountable for all supplier security; approves Critical supplier engagements; signs off on audits; reports to board | Chief Information Security Officer, Head of Security |
| CIO | Ensures IT systems support TPRM; manages supplier access provisioning; technical architecture for supplier connections | Chief Information Officer |
| Head of Procurement | Ensures security clauses in all contracts; manages supplier onboarding/offboarding; procurement system enforcement | Chief Procurement Officer, VP Procurement, Purchase Head |
| Legal Counsel | Drafts and negotiates security clauses; enforces contract terms; manages termination; handles liability disputes | General Counsel, Legal Head, Company Secretary |
| Vendor Risk Manager | Day-to-day TPRM program management; risk assessments; monitoring; audits; incident coordination; metrics reporting | Vendor Risk Manager, Supplier Security Manager, Third-Party Risk Manager |
| Vendor Risk Analyst | Executes assessments; maintains inventory; analyzes ratings; prepares audit reports; tracks remediation | Vendor Risk Analyst, Supplier Security Analyst |
| IT / Security Operations | Provisions and revokes supplier access; monitors supplier activity; manages SIEM alerts for supplier accounts; executes technical offboarding | IT Operations, Security Operations Center (SOC), IAM Team |
| Data Owner | Defines data protection requirements for suppliers; approves data sharing; verifies data return; assesses data breach impact | Data Owner, Business Unit Head, Function Head |
| Business Unit Head | Identifies and registers all suppliers; ensures business team compliance with TPRM policy; alerts VRM to new supplier needs | Department Head, Business Unit Head, Regional Manager |
| Compliance Officer | Ensures regulatory compliance in supplier contracts; audits TPRM program; manages regulatory reporting; DPDP compliance | Compliance Head, Company Secretary, Regulatory Affairs |
Documentation and Evidence Requirements
Mandatory Evidence by TPRM Lifecycle Phase
| Phase | Document / Evidence | Retention Period | Format | Owner |
|---|---|---|---|---|
| Inventory | Supplier inventory register | Permanent (updated continuously) | Spreadsheet / TPRM platform / Database | Vendor Risk Manager |
| Inventory | Shadow supplier discovery records | 3 years | Email / Survey / Analysis report | Vendor Risk Manager |
| Assessment | Supplier Security Questionnaire (SSQ) responses | 7 years from assessment date | PDF / Platform export | Vendor Risk Manager |
| Assessment | Risk assessment records per supplier | 7 years from assessment date | PDF / Risk register | Vendor Risk Manager |
| Assessment | External security rating reports | 3 years | Platform export / PDF | Vendor Risk Manager |
| Contracting | Supplier contracts with security clauses | Duration of relationship + 7 years | PDF / Contract management system | Legal / Procurement |
| Contracting | Data Processing Agreements (DPAs) | Duration of relationship + 7 years | PDF / Contract management system | Legal / Compliance |
| Contracting | Risk acceptance forms (for gaps) | 7 years | PDF / Workflow record | CISO / Vendor Risk Manager |
| Monitoring | Quarterly Business Review (QBR) minutes | 7 years | PDF / Meeting notes | Vendor Risk Manager |
| Monitoring | Continuous monitoring alerts and actions | 3 years | Platform export / Email / Ticket | Security Operations |
| Monitoring | Supplier access review records | 7 years | PDF / IAM system export | IT / Security Operations |
| Audit | Supplier audit plans | 7 years | PDF / Word | Internal Audit / Vendor Risk Manager |
| Audit | Supplier audit reports | 7 years | Internal Audit / Vendor Risk Manager | |
| Audit | Corrective Action Plans (CAPs) and closure evidence | 7 years | PDF / Excel | Vendor Risk Manager / Supplier |
| Incident | Supplier incident records | 7 years | Incident management system / PDF | Security Operations / Vendor Risk Manager |
| Incident | Joint investigation reports | 7 years | PDF / Word | CISO / Vendor Risk Manager |
| Incident | Regulatory notification records (DPDP, RBI, etc.) | 7 years | PDF / Email / Regulatory portal | Compliance Officer |
| Change | Supplier change notifications | 7 years | Email / Platform record | Vendor Risk Manager |
| Change | Reassessment records triggered by change | 7 years | PDF / Risk register | Vendor Risk Manager |
| Termination | Termination notice | 7 years | PDF / Email / Workflow | Procurement / Legal |
| Termination | Access revocation logs | 7 years | IAM system export / Log files | IT / Security Operations |
| Termination | Data return/destruction certificates | 7 years | PDF / Certificate | Vendor Risk Manager / Data Owner |
| Termination | Asset collection receipts | 7 years | PDF / Signed receipt | IT / Facilities |
| Termination | Post-termination review records | 7 years | PDF / Meeting notes | Vendor Risk Manager |
| Governance | TPRM Committee meeting minutes | 7 years | PDF / Meeting notes | Vendor Risk Manager |
| Governance | Management review records (supplier security) | 7 years | PDF / Meeting notes | CISO |
| Governance | TPRM metrics and dashboards | 3 years | BI tool / Excel / PDF | Vendor Risk Manager |
| Training | Procurement team security training records | 7 years | Training system / Attendance | HR / Vendor Risk Manager |
| Training | Supplier security awareness training records | 7 years | Training system / Certificates | HR / Vendor Risk Manager |
Evidence Organization
For audit readiness, organize evidence in a structured repository:
/TPRM-Evidence/
/YYYY/
/Supplier-Assessments/
/Critical/
- [Supplier-ID]-[Name]-Assessment-YYYY-MM-DD.pdf
/High/
/Medium/
/Low/
/Contracts/
/Critical/
- [Supplier-ID]-[Name]-Contract-vX.pdf
/High/
/Medium/
/Low/
/Monitoring/
/QBR-Minutes/
/Security-Ratings/
/Access-Reviews/
/Audits/
/On-Site/
/Virtual/
/CAPs/
/Incidents/
/YYYY-MM-Incident-[ID]-[Supplier-Name]/
/Terminations/
/YYYY-MM-[Supplier-Name]/
/Governance/
/Committee-Minutes/
/Management-Reviews/
/KPI-Dashboards/
/Training/
/Procurement-Training/
/Supplier-Training/
Continuous Improvement
The Continuous Improvement Cycle for Supplier Security
Plan → Do → Check → Act
Plan:
- Review TPRM metrics quarterly: incident trends, assessment coverage, audit findings, monitoring effectiveness
- Benchmark against industry standards (Gartner TPRM maturity, Shared Assessments SIG, NIST CSF supply chain)
- Identify regulatory changes (DPDP amendments, RBI circulars, new SEBI requirements)
- Update risk framework based on new threat intelligence (supply chain attacks, new vulnerabilities)
Do:
- Deploy updated templates, clauses, and procedures to procurement and security teams
- Train new staff and refresh existing staff on TPRM practices
- Implement new monitoring tools or automation
- Pilot new assessment techniques (e.g., AI-assisted risk scoring, automated evidence collection)
Check:
- Measure KPIs before and after changes
- Conduct internal audit of TPRM program effectiveness
- Gather feedback from suppliers on assessment process (friction vs. value)
- Review post-incident data for supplier root causes
Act:
- Standardize improvements that prove effective
- Eliminate redundant assessments or processes that add no value
- Update knowledge base and playbook
- Report improvements to management and incorporate into governance
Supplier Security Maturity Model
| Level | Name | Characteristics | Evidence | Typical Organization |
|---|---|---|---|---|
| 1, Initial | Ad-hoc | No supplier inventory; no security assessments; no security clauses; reactive incident management; shadow suppliers rampant | No policy; no inventory; contracts without security terms; incident-driven response | Startups; very small businesses; unregulated sectors |
| 2, Developing | Basic TPRM | Basic supplier inventory exists; security clauses in some contracts; lightweight SSQ for some suppliers; no continuous monitoring; manual processes | Inventory (incomplete); some contracts with clauses; basic SSQ; spreadsheet-based | SMEs beginning ISO 27001; 1-2 procurement staff |
| 3, Defined | Standardized | Complete inventory; security clauses in all contracts; risk tiering; scheduled assessments; quarterly monitoring for Critical; defined offboarding | Policy + procedure; 100% clause coverage; tiered assessments; monitoring schedule; documented offboarding | Growing companies; 250-5000 employees; pursuing certification |
| 4, Managed | Measured | Automated inventory; continuous monitoring via security ratings; automated SSQ; risk scoring; annual audits; metrics-driven governance; integration with GRC | TPRM platform; security ratings; automated workflows; KPI dashboard; integrated GRC | Large enterprises; 5000+ employees; mature risk management |
| 5, Optimizing | Strong | Predictive risk analytics; AI-assisted threat intelligence; fourth-party risk visibility; real-time monitoring; automated offboarding; industry leadership; zero trust supply chain | Predictive analytics; AI/ML risk models; real-time supply chain visibility; automated response; industry contributions | Global banks; top tech companies; defence organizations |
Improvement Triggers and Actions
| Trigger | Action | Responsible | Timeline |
|---|---|---|---|
| Supplier incident rate >2 per quarter | Root cause analysis; control enhancement; supplier retraining; potential contract amendments | CISO + Vendor Risk Manager | 2 weeks |
| Audit finding in TPRM program | Corrective action; process update; evidence enhancement; retraining | Internal Audit + Vendor Risk Manager | 4 weeks |
| New regulation (DPDP amendment, RBI circular) | Policy review; contract clause update; regulatory mapping; training | Compliance Officer + Legal + CISO | 6 weeks |
| Major supply chain breach in industry | Industry threat analysis; review of similar suppliers; control enhancement | CISO + Threat Intelligence | 2 weeks |
| Certification lapse of Critical supplier | Immediate escalation; enhanced monitoring; contract enforcement; alternative sourcing evaluation | Vendor Risk Manager + Procurement | 1 week |
| Customer audit finding on supplier security | Immediate corrective action; process update; supplier engagement evidence enhancement | Vendor Risk Manager + CISO | 1 week |
| TPRM platform upgrade or replacement | Process re-engineering; training; data migration; integration testing | IT + Vendor Risk Manager | 8 weeks |
| Annual management review | Full policy and framework review; KPI trend analysis; improvement plan; budget revision | CISO + Vendor Risk Manager + Procurement | Annual |
| Significant business growth (>25% new suppliers) | Scale TPRM resources; automation investment; process optimization | CISO + HR + Procurement | 3 months |
FAQ
General Questions
Q1: Does A.5.19 apply to all suppliers, including small ones like office supply vendors? A: Yes, but with proportionate effort. A.5.19 applies to all suppliers with access to information, systems, or premises. However, a courier service or office supply vendor (Low tier) requires only a lightweight assessment (e.g., a 4-clause contract and basic security awareness). A cloud hosting provider (Critical tier) requires deep due diligence, continuous monitoring, and annual audits. The key is that no supplier is exempt from the inventory and some level of security consideration.
Q2: What is the difference between A.5.19 and A.5.14? A: A.5.14 (Information transfer agreements) governs the contractual structure for information transfers, what must be in the agreement. A.5.19 governs the ongoing management of supplier relationships, risk assessment, monitoring, auditing, incident management, and termination. A.5.19 references A.5.14 for the contractual foundation, but focuses on the process of managing the relationship after the contract is signed. For full compliance, implement both together.
Q3: Do we need to audit every supplier? A: No. Audits are resource-intensive and should be risk-based. Singahi recommends: annual on-site audits for Critical suppliers, biennial virtual audits for High suppliers, and ad-hoc or incident-driven audits for Medium and Low suppliers. If a supplier holds a current ISO 27001 or SOC 2 Type II certification, you can rely on that (with spot checks) rather than conducting a full audit.
Q4: How do we manage fourth-party risk (our supplier's suppliers)? A: Fourth-party risk is managed through: (1) contractual disclosure requirements, your supplier must tell you who their subcontractors are; (2) contractual liability, your supplier remains liable for subcontractor breaches; (3) assessment of subcontractors for Critical suppliers; (4) security ratings that may capture fourth-party telemetry; (5) limiting the subcontractor chain, require approval for new subcontractors. Full fourth-party visibility is difficult but essential for Critical suppliers.
Q5: Can we accept a supplier without ISO 27001 or SOC 2? A: Yes, but with enhanced scrutiny. Certifications are evidence of a mature security program, but they are not mandatory for A.5.19 compliance. If a supplier lacks certifications, require: a detailed SSQ, evidence of equivalent controls, a remediation plan for gaps, increased monitoring, and potentially a shorter contract term with renewal contingent on improvement. For Critical suppliers, consider requiring certification within 12-24 months as a contract milestone.
Q6: How often should we reassess suppliers? A: Reassessment frequency should align with risk tier: Critical suppliers annually (or more frequently if incidents occur); High suppliers every 18-24 months; Medium suppliers every 2-3 years; Low suppliers every 3 years or on renewal. In addition, reassess whenever there is a material change (subcontractor, location, technology, certification lapse, or incident).
Q7: What is a "shadow supplier" and how do we find them? A: A shadow supplier is a vendor engaged by individual employees or departments without procurement or security knowledge. Examples: a marketing manager's personal Canva subscription with company logos, a developer's personal GitHub account with company code, a department's free survey tool with employee feedback. Find them through: expense report analysis, cloud IAM audits, email domain analysis, network traffic monitoring, and department surveys. Shadow suppliers are a major audit failure point because they bypass all security controls.
Q8: How do we handle supplier security for international vendors (e.g., AWS, Google, Salesforce)? A: Global hyperscalers (AWS, Azure, Google Cloud) typically have strong security programs (ISO 27001, SOC 2, PCI DSS). Your assessment should focus on: shared responsibility model clarity (what they secure vs. what you secure), data residency and region selection, IAM configuration, encryption key management, and their incident notification process. For smaller international vendors, apply the same risk-based assessment as domestic vendors, with additional attention to data residency and cross-border transfer compliance (DPDP Act 2023, GDPR).
Q9: Should we include physical security suppliers (guards, cleaning) in our TPRM program? A: Yes. Physical security suppliers have access to your premises, devices, and sometimes documents. They should be in your inventory, classified (typically Medium), and subject to background checks, physical access controls, and confidentiality agreements. A cleaning crew with after-hours access to executive offices can be a significant insider threat if not managed.
Q10: How does A.5.19 relate to DPDP Act 2023 compliance? A: The DPDP Act 2023 makes the "data fiduciary" (your organization) liable for breaches, even if caused by a supplier (data processor). Section 8(5) requires "reasonable security safeguards" that extend to your supply chain. For any supplier processing personal data on your behalf, you must have a Data Processing Agreement (DPA) with security clauses, verify their safeguards, and ensure they can meet breach notification requirements. Failing to manage supplier security under DPDP can result in fines up to .
Q11: What is the minimum viable TPRM process for a 30-person startup? A: For startups, keep it lean: (1) List all suppliers with access to your data/systems (even the free ones), (2) Classify into Critical (cloud, payment, core dev) and Other, (3) Use standardized security clauses for Critical suppliers (use our clause library), (4) Require MFA and data residency for Critical, (5) Revoke access immediately when a supplier is no longer needed, (6) Monitor for breach news. As you grow, add formal assessments, monitoring tools, and audit programs.
Q12: How do we justify TPRM investment to management? A: Use the business case: (1) 62% of breaches involve suppliers, the risk is real, (2) DPDP Act fines up to, regulatory liability is personal and organizational, (3) enterprise clients require supplier security evidence, revenue depends on it, (4) breach overhead averages M for third-party breaches, prevention is cheaper, (5) TPRM program overhead is typically 0.5-2% of IT spend, negligible compared to breach overhead. Use illustrative scenarios (Section 15) to show peer examples.
Q13: Can we use a single security questionnaire for all suppliers? A: A single complete SSQ can be used, but the evaluation should be tiered. All suppliers answer the same questions, but the pass threshold and required evidence vary by tier. For Low suppliers, a score of 50/100 may be acceptable. For Critical suppliers, 80/100 is the minimum. Alternatively, use a lightweight SSQ for Low/Medium and a complete SSQ for Critical/High. The key is consistency and proportionality.
Q14: What should we do if a Critical supplier refuses to allow an audit? A: If a Critical supplier refuses an audit, you have three options: (1) Accept the risk with formal risk acceptance and enhanced monitoring (not recommended for highly sensitive data), (2) Require an alternative assurance (e.g., SOC 2 Type II report from a reputable auditor, ISO 27001 with scope covering your data), (3) Find an alternative supplier. Never allow a Critical supplier to operate without any form of security assurance. Document the refusal and your decision in the risk register.
Q15: How do we manage supplier security in a merger or acquisition? A: M&A introduces massive supplier risk: (1) Immediately inventory all suppliers of the acquired company, (2) Assess them against your security standards before integration, (3) Do not grant access to your systems until assessment is complete, (4) Harmonize contracts to your clause library, (5) Plan termination of redundant suppliers with secure offboarding, (6) Integrate monitoring and access controls. M&A is a high-risk period for supplier security, treat it as a security project (A.5.20 + A.5.19).
Q16: Should we include open-source software and public libraries as "suppliers"? A: Open-source libraries are not traditional suppliers but introduce similar supply chain risks. A.5.19 focuses on contractual relationships, but the broader supply chain risk concept (A.8.25, A.8.28) includes software dependencies. Best practice: use Software Composition Analysis (SCA) tools to track open-source dependencies; monitor for vulnerabilities (CVEs); maintain an SBOM (Software Bill of Materials); have a policy for approved open-source licenses. This is increasingly required by regulations (NIS2, EO 14028 in the USA).
Q17: How do we handle a supplier breach? A: Follow the joint incident response protocol: (1) Verify the breach scope with the supplier immediately, (2) Assess if your data/systems/customers are affected, (3) Contain (revoke access if needed), (4) Investigate jointly, (5) Require root cause analysis and remediation evidence, (6) Update the supplier risk assessment, (7) Consider contract termination if negligence is proven, (8) Notify regulators if required (DPDP: 72 hours; RBI: 6 hours for payment), (9) Notify affected customers if personal data is involved, (10) Update your incident response playbook. Speed and documentation are critical.
Q18: Is there a difference between "vendor," "supplier," and "third party"? A: In practice, these terms are often used interchangeably. ISO 27001:2022 uses "supplier" consistently. "Vendor" is common in procurement and IT. "Third party" is broader and includes non-contractual relationships (e.g., industry partners, regulators). For A.5.19, focus on "suppliers", entities with whom you have a contractual relationship for products or services. The control applies regardless of the term used internally.
Q19: How do we balance security requirements with supplier relationship management? A: Security requirements should not be adversarial. Frame them as "helping us both succeed", your enterprise clients require you to have secure suppliers, so your suppliers must meet those standards. Use tiered requirements (don't overburden a small vendor), provide clear guidance (use our clause library), offer assistance (help them understand DPDP requirements), and recognize good performance (positive reinforcement in QBRs). A supplier that improves its security for your benefit often wins more business from other clients too.
Q20: Can we automate supplier risk assessment? A: Yes, and you should at scale. Automated tools can: send SSQs, collect responses, calculate risk scores, monitor security ratings, alert on certification expiry, and track remediation. However, human judgment remains essential for: architecture reviews, complex risk scenarios, negotiation of security terms, incident investigation, and relationship management. The goal is "augmented TPRM", automation handles volume and consistency; humans handle nuance and decisions.
References and Further Reading
ISO Standards
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection, Information security management systems, Requirements
- ISO/IEC 27002:2022, Information security, cybersecurity and privacy protection, Information security controls, Clause 5.19
- ISO/IEC 27003:2017, Information security management system, Guidance
- ISO/IEC 27005:2022, Information security risk management
- ISO/IEC 27036, Information security for supplier relationships, Multiple parts (27036-1 to 27036-4)
- ISO/IEC 27037:2012, Guidelines for identification, collection, acquisition and preservation of digital evidence (relevant for incident investigation)
Indian Regulations and Guidelines
- Digital Personal Data Protection Act 2023, Government of India, Ministry of Electronics and Information Technology
- Information Technology Act 2000 (as amended in 2008), Government of India
- CERT-In Directions 2022, Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology
- RBI Master Direction on Digital Payment Security Controls, Reserve Bank of India, 2021
- RBI Master Circular on Cyber Security Framework for Banks, Reserve Bank of India
- SEBI Circular CIR/MIRSD/2/2011, Cyber Security and Cyber Resilience framework for Stock Exchanges, Depositories, and Clearing Corporations
- SEBI Circular for Asset Management Companies, Cybersecurity and cyber resilience framework
- IRDAI Guidelines on Information and Cyber Security for Insurers, Insurance Regulatory and Development Authority of India, 2017
- MeitY Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
- National Cyber Security Policy 2013, Ministry of Electronics and Information Technology
International Frameworks and Standards
- NIST SP 800-53 Rev 5, Security and Privacy Controls for Information Systems and Organizations
- NIST Cybersecurity Framework (CSF) 2.0, National Institute of Standards and Technology, 2024
- NIST SP 800-161 Rev 1, Cybersecurity Supply Chain Risk Management Practices
- CIS Controls v8, Center for Internet Security
- COBIT 2019, Control Objectives for Information and Related Technologies, ISACA
- PCI DSS v4.0, Payment Card Industry Data Security Standard
- Shared Assessments Standardized Information Gathering (SIG) Questionnaire, Shared Assessments Working Group
- AICPA SOC 2 Trust Services Criteria, TSP Section 100, 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
Third-Party Risk Management Resources
- Gartner Research: Magic Quadrant for IT Vendor Risk Management Solutions, Annual
- Forrester Research: The Forrester Wave™: Third-Party Risk Management Platforms, Quarterly
- BitSight Security Ratings Methodology, bitsight.com
- SecurityScorecard Ratings Methodology, securityscorecard.com
- UpGuard Vendor Risk Management Guide, upguard.com
Industry Reports and Statistics
- Verizon Data Breach Investigations Report (DBIR) 2024, Verizon Business
- IBM impact of a Data Breach Report 2024, IBM Security
- Ponemon Institute: Data Risk in the Third-Party Ecosystem, Annual
- CERT-In Annual Report 2023-2024, Indian Computer Emergency Response Team
- Reserve Bank of India Annual Report, RBI cyber security and payment system sections
Supply Chain Security
- NIST SP 800-161 Rev 1, Cybersecurity Supply Chain Risk Management Practices, National Institute of Standards and Technology
- CISA Supply Chain Risk Management, US Cybersecurity and Infrastructure Security Agency
- ENISA Supply Chain Security Guidance, European Union Agency for Cybersecurity