# Supplier security policy

Source: https://aestech.com.au/policy-templates/#supplier-security-policy
Markdown URL: https://aestech.com.au/policy-templates/supplier-security-policy.md

Use for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, cloud services, and AI supplier reviews.

Frameworks: ISO 27001, SOC 2, ISO 42001

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how suppliers are assessed, approved, monitored and offboarded when they can affect company information, customer data or critical services.

2. Supplier risk tiers
- Critical: stores or processes confidential data, affects production, security, availability or regulated obligations.
- Standard: supports business processes but has limited data or system access.
- Low: no access to confidential data or critical systems.

3. Due diligence
Before approval, critical suppliers must be reviewed for security posture, privacy, data location, subcontractors, incident notification, continuity, certifications and contractual terms.

4. Ongoing review
Critical suppliers are reviewed at least annually and after major scope, product, location, subprocessor or incident changes.

5. Evidence
Keep supplier register, risk tier, review records, security reports, contracts, data processing terms, offboarding records and exception approvals.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md