Run your program
Vendors and TPRM
Track your vendors and subprocessors, tier them by risk, and keep agreements and reviews current.
Keep a register of the third parties that touch your data, tiered by risk, with the agreements and reviews an auditor asks for.
The vendor register
For each vendor or subprocessor, record what they are, the data they handle, and a risk tier based on data sensitivity and access. Higher-tier vendors get closer scrutiny and more frequent review.
Agreements and evidence
Track the paperwork that proves the relationship is governed:
- SOC 2 (or equivalent) on file - whether you hold a current attestation for the vendor.
- BAA for vendors that handle PHI, and a DPA for vendors that process personal data.
- Subprocessor status, so your Trust Center subprocessor list stays accurate.
Reviews
Set a review cadence so higher-risk vendors are reassessed on schedule. A current register with reviews in place is what satisfies the vendor-management control across SOC 2, ISO 27001, HIPAA, and PCI.