TPR-01Third Parties and Supply Chain

Third-party inventory

Third parties with access to data or systems are inventoried with an owner and a criticality judgement.

Why it exists

You cannot assess a vendor you have not listed.

What usually proves it

Vendor register with owner, data access and criticality.

Smaller organizations

One list, updated when someone signs a new tool.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC9.2
  • Fully addressedISO/IEC 27001 Annex A · A.5.19
  • Fully addressedNIST Cybersecurity Framework · GV.SC-04
  • Fully addressedPCI DSS · 12.8.1
  • Fully addressedHIPAA Security Rule · 164.308(b)(1)
  • Fully addressedGDPR · Art. 28
  • Partially addressedEU AI Act · Art. 25 — Responsibilities along the AI value chain.
  • Fully addressedNIST AI Risk Management Framework · GOVERN 6.1