Skip to content

Supplier Security Policy (Annex A.5.19 – A.5.23)

1. Overview

Third-party SaaS tools, cloud infrastructure providers, and subcontractors introduce significant supply-chain risks. This policy sets our mandatory vetting and management controls.

2. Vendor Onboarding Requirements

Before any cloud service or third-party vendor is engaged: 1. Security Due Diligence: The vendor must provide evidence of UKAS-accredited ISO 27001, SOC 2 Type II, or Cyber Essentials Plus. 2. Data Processing Agreement (DPA): Standard contractual clauses governing UK GDPR compliance, sub-processor notification, and data breach notification within 24 hours. 3. Asset Recording: The service is logged in the Master Supplier Register.

3. Annual Reviews

All critical tier-1 suppliers undergo an annual security and SLA review.