Back to Corporate Standards
CS-09 · Corporate Standards

Vendor Due Diligence & Risk Management

Proposed lifecycle controls for selecting and overseeing suppliers.

Public draft · Pending management and legal approval. Not yet effective. This proposed standard is not a certification or a statement of legal compliance.

DOCUMENT

CS-09

OWNER

Escalation Holding LLC

EFFECTIVE

Pending approval

REVIEWED

Not specified

Class · PUBLIC·Review cycle · Pending approval

Draft status and purpose

This public draft is pending management and legal approval; it is not currently adopted and provides no certification or compliance guarantee.

The proposed Standard describes a repeatable, risk-based approach for deciding whether to engage a vendor, what safeguards to require, how to monitor the relationship, and how to end access or services. It should be applied with the Code of Ethics, CS-06 Sanctions Policy, CS-08 Conflicts of Interest & Gifts Standard, and applicable contracts; it does not duplicate their reporting or screening requirements.

Scope and risk principles

Upon adoption, the Standard would cover suppliers, contractors, consultants, cloud and technology providers, professional advisers, subcontractors, and other third parties that provide goods or services, connect to company systems, handle company or customer information, or could affect service delivery.

Management should use a proportionate risk assessment rather than a one-size-fits-all checklist. Relevant factors include information handled, system or facility access, criticality and substitutability of the service, geographic and legal exposure, subcontracting, concentration risk, resilience, financial condition, and the effect of a failure or misconduct.

A business owner should not treat a completed questionnaire as approval by itself. The proposed review should consider evidence, open issues, contract protections, residual risk, and whether the relationship remains justified.

Proposed intake and due diligence

Before commitment, the proposed business owner should submit a vendor intake describing the service, data and access requested, business need, expected term, dependencies, and responsible contacts. Management should designate reviewers for procurement, security, privacy, legal, finance, or other expertise as the risk requires.

Due diligence should verify the vendor's identity, ownership and control, relevant experience, capacity, legal and regulatory posture, use of subcontractors, information-security practices, privacy terms, incident history, continuity arrangements, and ability to meet the proposed service requirements. The depth of review should match the assessed risk and available evidence.

The reviewer should document unresolved findings and either require remediation or safeguards, accept the residual risk through a recorded decision, select another vendor, or decline the engagement. Counterparty screening should follow CS-06 Sanctions Policy rather than being recreated in this Standard.

Contracting, onboarding, and access controls

A written agreement should describe the service, responsibilities, confidentiality, ownership and permitted use of information, privacy and security obligations, incident communication, subcontracting, audit or evidence rights, business continuity, insurance where appropriate, and return or deletion of information at exit. Legal review should be obtained when terms create material risk or cannot meet the proposed baseline.

Onboarding should confirm that required due diligence, approvals, conflict disclosures, and contract protections are complete before service access or sensitive information is provided. Access should be limited to the minimum systems, data, duration, and functions necessary for the service, with an identified owner and a documented removal process.

Vendor accounts, integrations, data transfers, and privileged activities should be inventoried and reviewed. The company should avoid shared access, use secure transfer methods, log material activity where feasible, and require the vendor to notify the designated contact of a suspected security or privacy incident without waiting for routine review.

Ongoing monitoring and exit

The proposed business owner should reassess a vendor at a frequency appropriate to its risk and whenever there is a material change, such as a new service, expanded access, ownership change, significant incident, subcontractor change, financial distress, or relevant legal development. Monitoring can include service performance, control evidence, incident and issue logs, continuity testing, access reviews, and remediation status.

Findings should have a named accountable contact, a target for resolution set according to the risk, evidence of closure, and an escalation path for overdue or disputed items. Management should be able to suspend, limit, or replace a vendor when risk is unacceptable or required safeguards are not maintained.

Exit planning should address transition, access removal, return or deletion of information, termination of integrations, preservation of records and evidence, continuity of critical services, and confirmation of completion. The plan should be tested or updated when the service is material to operations.

Proposed responsibilities and official reference

Upon adoption, management should designate a proposed owner for the vendor program, business owners for individual relationships, and independent reviewers for higher-risk decisions. Procurement or an equivalent process should maintain the inventory; security, privacy, legal, finance, and service owners should contribute within their designated responsibilities.

Vendor intake, assessments, approvals, contracts, evidence, issues, access reviews, incidents, and exit records should be retained by category under CS-10 Records Retention & Legal Holds. A legal hold overrides ordinary disposal and should be handled through the designated hold process.

NIST SP 1305, The Cybersecurity Framework 2.0, is available at https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1305.pdf. It is voluntary risk guidance, not a certification, legal requirement, or guarantee that any vendor or program is compliant.

This draft does not promise that due diligence will identify every risk. Management and legal should approve the final scope, evidence expectations, contract language, review cadence, and exceptions before the Standard is adopted.

/PUBLIC_DRAFT

This is a public draft of CS-09 — Vendor Due Diligence & Risk Management, provided for review. It is not an adopted company policy. Questions about this document should be directed to compliance@alexasecurity.net.

VERSION

2026.1

REVIEWED

Not specified

NEXT REVIEW

Pending approval