TPR-02Third Parties and Supply Chain

Due diligence proportionate to risk

Third parties are assessed before onboarding and periodically thereafter, at a depth proportionate to what they touch.

Why it exists

A questionnaire sent to everyone is a questionnaire nobody reads.

What usually proves it

Assessment records, tiering rationale, reassessment dates.

Smaller organizations

Two tiers, a short set of questions for the lower one.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC9.2
  • Fully addressedISO/IEC 27001 Annex A · A.5.21
  • Fully addressedNIST Cybersecurity Framework · GV.SC-07
  • Fully addressedPCI DSS · 12.8.4
  • Partially addressedHIPAA Security Rule · 164.308(b) — Satisfactory assurances through the agreement.
  • Fully addressedGDPR · Art. 28(1)
  • Partially addressedEU AI Act · Art. 25 — Contractual duties between value chain actors.
  • Fully addressedNIST AI Risk Management Framework · GOVERN 6.1