Joopler docs
Run your program

Vendors and TPRM

Track your vendors and subprocessors, tier them by risk, and keep agreements and reviews current.

Keep a register of the third parties that touch your data, tiered by risk, with the agreements and reviews an auditor asks for.

The vendor register

For each vendor or subprocessor, record what they are, the data they handle, and a risk tier based on data sensitivity and access. Higher-tier vendors get closer scrutiny and more frequent review.

Agreements and evidence

Track the paperwork that proves the relationship is governed:

  • SOC 2 (or equivalent) on file - whether you hold a current attestation for the vendor.
  • BAA for vendors that handle PHI, and a DPA for vendors that process personal data.
  • Subprocessor status, so your Trust Center subprocessor list stays accurate.

Reviews

Set a review cadence so higher-risk vendors are reassessed on schedule. A current register with reviews in place is what satisfies the vendor-management control across SOC 2, ISO 27001, HIPAA, and PCI.