Vendor & Third-Party Register Template
Record every vendor with its criticality tier, data accessed, due diligence status, and review date — aligned with ISO 27001 controls A.5.19–A.5.22.
In short
A vendor register lists every supplier and third party holding organisational data or holding access to its systems, together with risk tier, security agreements, and reassessment schedule. ISO 27001 controls A.5.19 to A.5.22 require supplier risk management, and this register is its foundation.
- Format
- XLSX
- Size
- 17 KB
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
Most organisations know which vendors they pay. Far fewer know which vendors hold their customers' data. Those two lists are rarely the same, and it is the second one that carries the risk.
This register orders vendors not by contract value but by what they hold and can reach. A small vendor with administrative access to production carries more risk than a large one supplying hardware — and an assessment ordered by contract value inverts that priority.
Most Useful For
- Organisations dependent on many SaaS services and third parties
- Procurement and security teams needing a uniform vendor onboarding process
- Companies asked by enterprise clients to evidence third-party risk management
What's Inside
Vendor profile
Name, service provided, internal relationship owner, and contract status.
Data & access
Types of data held, level of system access, and whether personal data is processed.
Risk tier
The vendor risk classification that sets assessment depth and frequency.
Contractual security clauses
Flags for security, confidentiality, incident notification, and right-to-audit clauses.
Assessment & certification
Last assessment date and outcome, plus vendor certifications such as ISO 27001 or SOC 2.
Exit plan
Data return and destruction procedures at end of relationship — the part almost always skipped.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Controls A.5.19 & A.5.20 | Information security in supplier relationships and within supplier agreements. |
| ISO/IEC 27001:2022 | Controls A.5.21 & A.5.22 | ICT supply chain security management, and monitoring and review of supplier services. |
| Law 27/2022 (PDP Law) | Personal data processors | The duty to govern relationships with processors handling personal data on the controller's behalf. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Must every vendor be assessed to the same depth?
No, and forcing it is what stalls the programme. High-risk vendors — those holding personal data or holding privileged access — get deep, recurring assessment. Low-risk vendors need only a brief check at onboarding. What matters is that the distinguishing criteria are written down.
Is a vendor's ISO 27001 certificate enough?
It helps but does not replace assessment. Certificates have a scope, and that scope may not cover the service you are buying. What needs checking is the scope statement, not merely the certificate's existence.
How often should reassessment happen?
High-risk vendors typically annually; medium risk every two years; low risk at contract renewal. Reassessment is also event-driven: an incident at the vendor, a change in service, or a change in the data entrusted to them.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
Risk Register Template
Manage information security risk identification, assessment, and mitigation in one structured worksheet.
Free DownloadStatement of Applicability (SoA) Template — ISO 27001:2022
Document the applicability of all 93 ISO 27001:2022 Annex A controls along with their justifications.
Free DownloadInformation Security Policy Template
An organization-level information security policy framework ready to tailor to your business context.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.