TPR-02Third Parties and Supply Chain
Due diligence proportionate to risk
Third parties are assessed before onboarding and periodically thereafter, at a depth proportionate to what they touch.
Why it exists
A questionnaire sent to everyone is a questionnaire nobody reads.
What usually proves it
Assessment records, tiering rationale, reassessment dates.
Smaller organizations
Two tiers, a short set of questions for the lower one.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC9.2
- Fully addressedISO/IEC 27001 Annex A · A.5.21
- Fully addressedNIST Cybersecurity Framework · GV.SC-07
- Fully addressedPCI DSS · 12.8.4
- Partially addressedHIPAA Security Rule · 164.308(b) — Satisfactory assurances through the agreement.
- Fully addressedGDPR · Art. 28(1)
- Partially addressedEU AI Act · Art. 25 — Contractual duties between value chain actors.
- Fully addressedNIST AI Risk Management Framework · GOVERN 6.1