サンプル一覧

Third-Party Risk Management Policy(third-party risk policy)

vendor lifecycleのtiering、due diligence、contract control、monitoring、incident、exit planを定める架空policyです。

対象法域: England and Wales - completed fictional worked example

サンプルをダウンロード

編集可能なMicrosoft Word版はインタラクティブページからダウンロードできます。

重要: この文例は一般的な情報提供のみを目的とし、法律上の助言ではありません。使用前に該当する法令、指定様式および署名・押印要件を確認してください。

# THIRD-PARTY RISK MANAGEMENT POLICY(THIRD-PARTY RISK POLICY)

日付: 26 August 2030

当事者: Northmoor Analytics Limitedおよびits procurementおよびbusiness teams

## 1. 目的と当事者

本policyはcloud hosting、payroll、cleaning、professional advice、marketingを含むNorthmoorの74 supplierに適用します。engagement前、contract中、exitをcoverしますが、supplierをpartnerにせず、management accountabilityをProcurementへtransferしません。

## 2. 事実、範囲および条件

Tier 1 critical supplierはcore serviceをstopし、sensitive dataへaccessし、single point of failureを作り得ます。Tier 2はimportantだがsubstitutable、Tier 3はroutineです。Procurementはbusiness criticality、data、concentration、financial dependency、geography、substitutabilityをscoreし、onboarding前に理由をrecordします。

## 3. processと責任

Tier 1 due diligenceはownership、sanction・adverse-media screening、3年のaccountまたはequivalent financial evidence、insurance、2 reference、relevantならCyber Essentials・ISO 27001、resilience test、data-protection assessmentを含みます。Tier 2はproportionate questionnaire、Tier 3はidentity・insurance・conflict checkです。

## 4. evidence、recordおよびsafeguard

contractにはservice、SLA・RTO、confidentiality、UK GDPR controller・processor role、subprocessor approval、security control、24時間以内incident notice、audit evidence、insurance、IP ownership、termination assistance、data return・deletionを記します。Tier 1のsignature前にLegal、Information Security、business ownerがapproveします。

## 5. review、escalationおよびoutcome

Tier 1はmonthly SLA metric、quarterly review、annual reassessment、practicableなら4時間以内のmaterial incident noticeを出します。Tier 2はannual reviewです。Northmoorはmissed service、financial deterioration、cyber event、concentrationをtrackします。audit不可能を要求せず、certificationがsafetyをproveするともpromiseしません。

## 6. 留保と実務上のprotection

各Tier 1にはalternative source、data export、credential、people dependency、RTO・RPO、transition owner、tested workaroundを記すexit planがあります。supplierはorderly terminationにcooperateし、緊急substitutionはGold・Silver decisionとdocumented risk acceptance後にactivateできます。

## 7. England and Walesのlawとcompletion

Head of Procurementがpolicyをownし、CTOがtechnical risk、boardが£250,000超exposureのresidual riskをacceptします。staffはconcernをimmediately reportし、retaliationは禁止です。毎年reviewし、England and Wales lawを適用します。version 2.1は2030年8月26日にapproveします。

ご自身の状況に合った文書を作成

カスタマイズした文書を作成