TemplatesFree

Vendor & Third-Party Register Template

Record every vendor with its criticality tier, data accessed, due diligence status, and review date — aligned with ISO 27001 controls A.5.19–A.5.22.

In short

A vendor register lists every supplier and third party holding organisational data or holding access to its systems, together with risk tier, security agreements, and reassessment schedule. ISO 27001 controls A.5.19 to A.5.22 require supplier risk management, and this register is its foundation.

Format
XLSX
Size
17 KB
Price
Free

Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.

What This Document Is For

Most organisations know which vendors they pay. Far fewer know which vendors hold their customers' data. Those two lists are rarely the same, and it is the second one that carries the risk.

This register orders vendors not by contract value but by what they hold and can reach. A small vendor with administrative access to production carries more risk than a large one supplying hardware — and an assessment ordered by contract value inverts that priority.

Most Useful For

  • Organisations dependent on many SaaS services and third parties
  • Procurement and security teams needing a uniform vendor onboarding process
  • Companies asked by enterprise clients to evidence third-party risk management

What's Inside

01

Vendor profile

Name, service provided, internal relationship owner, and contract status.

02

Data & access

Types of data held, level of system access, and whether personal data is processed.

03

Risk tier

The vendor risk classification that sets assessment depth and frequency.

04

Contractual security clauses

Flags for security, confidentiality, incident notification, and right-to-audit clauses.

05

Assessment & certification

Last assessment date and outcome, plus vendor certifications such as ISO 27001 or SOC 2.

06

Exit plan

Data return and destruction procedures at end of relationship — the part almost always skipped.

Standards & Regulations It Helps Satisfy

Standard / RegulationClause / ArticleWhat this document covers
ISO/IEC 27001:2022Controls A.5.19 & A.5.20Information security in supplier relationships and within supplier agreements.
ISO/IEC 27001:2022Controls A.5.21 & A.5.22ICT supply chain security management, and monitoring and review of supplier services.
Law 27/2022 (PDP Law)Personal data processorsThe duty to govern relationships with processors handling personal data on the controller's behalf.

This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.

Questions About This Document

Must every vendor be assessed to the same depth?

No, and forcing it is what stalls the programme. High-risk vendors — those holding personal data or holding privileged access — get deep, recurring assessment. Low-risk vendors need only a brief check at onboarding. What matters is that the distinguishing criteria are written down.

Is a vendor's ISO 27001 certificate enough?

It helps but does not replace assessment. Certificates have a scope, and that scope may not cover the service you are buying. What needs checking is the scope statement, not merely the certificate's existence.

How often should reassessment happen?

High-risk vendors typically annually; medium risk every two years; low risk at contract renewal. Reassessment is also event-driven: an incident at the vendor, a change in service, or a change in the data entrusted to them.

Related Reading

Background that helps you fill this document in correctly, rather than merely filling it in.

Need guidance, not just a template?

A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.