Skip to main content

ER-31 Pre-Kickoff - Supplier/Vendor Risk Management Policy

C
Written by Claudio Morsella
Updated over a year ago

What to Provide

Vendor Risk Management Policy

The evidence should demonstrate:

  • Vendor risk assessment process

  • Vendor risk rating process

  • Critical vendor management process

  • Requirement for critical vendors to be reviewed annually

  • Security requirements for vendors

  • Date of last review and document version numbering

Evidence Format
Exported word processing document in a common file type such as .docx or .pdf.

Associated Unified Control ID

Associated Framework Control

CTRL-1094

LCL-27

Did this answer your question?