Vendor Management Policy Template

Use/reference this template as you build out your Vendor Management Policy

Written By Micah

The purpose of this policy is to establish security and privacy requirements for all Service Providers with respect to the protection of your company's assets, data, and personally identifiable information (β€œPII”). This policy applies to all contracts, purchase orders, statements of work, and agreements with Service Providers and Vendors who handle information deemed confidential and/or sensitive.

Commonly associated evidence:

  • Vendor Management Policy and Procedures

  • Vendor Risk Register

  • Vendor List

  • Vendor Due Diligence

  • Vendor Contract

Who needs a policy like this?

  • Most businesses

How to use the template:

  • Click on the link above to access the template

    • If you are a Google Workplace organization, make a copy by going to File > Make a copy

    • If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)

  • Review and then remove instructional text

  • Save in a centralized place

  • Attach to evidence either through Integrations, Automated Collection, or direct upload

If you need help using the template, please let us know.