TPR-03Third Parties and Supply Chain
Contractual terms and offboarding
Contracts carry security, privacy and breach terms, and access and data are recovered when the relationship ends.
Why it exists
The end of a relationship is where data is most often left behind.
What usually proves it
Executed terms, offboarding checklist, deletion confirmations.
Smaller organizations
A short addendum and a close-out checklist.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC9.2
- Fully addressedISO/IEC 27001 Annex A · A.5.20
- Fully addressedNIST Cybersecurity Framework · GV.SC-05
- Fully addressedPCI DSS · 12.8.2
- Fully addressedHIPAA Security Rule · 164.314(a)
- Fully addressedGDPR · Art. 28(3)
- Partially addressedEU AI Act · Art. 25(4) — Written agreements along the value chain.
- Partially addressedNIST AI Risk Management Framework · GOVERN 6.2 — Contingency for third-party failure.