Security InBuilt working template

Vendor Security Review

A proportional supplier review centred on data, access, dependency, evidence and exit planning.

Organisation
________________________________
Owner
________________________________
Version / date
________________________________
01

Service dependency

Business process, service owner, criticality and credible failure impact.

Notes / evidence
02

Data and access

Data classes, hosting regions, privileged access, subprocessors and retention.

Notes / evidence
03

Control evidence

Independent reports, testing scope, remediation, logging and incident notice.

Notes / evidence
04

Resilience

Backups, recovery objectives, dependency concentration and tested continuity.

Notes / evidence
05

Exit plan

Export format, deletion evidence, access removal and replacement dependency.

Notes / evidence