TPR-03Third Parties and Supply Chain

Contractual terms and offboarding

Contracts carry security, privacy and breach terms, and access and data are recovered when the relationship ends.

Why it exists

The end of a relationship is where data is most often left behind.

What usually proves it

Executed terms, offboarding checklist, deletion confirmations.

Smaller organizations

A short addendum and a close-out checklist.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC9.2
  • Fully addressedISO/IEC 27001 Annex A · A.5.20
  • Fully addressedNIST Cybersecurity Framework · GV.SC-05
  • Fully addressedPCI DSS · 12.8.2
  • Fully addressedHIPAA Security Rule · 164.314(a)
  • Fully addressedGDPR · Art. 28(3)
  • Partially addressedEU AI Act · Art. 25(4) — Written agreements along the value chain.
  • Partially addressedNIST AI Risk Management Framework · GOVERN 6.2 — Contingency for third-party failure.