# THIRD-PARTY RISK MANAGEMENT POLICY
Date: 26 August 2030
Parties: Northmoor Analytics Limited and its procurement and business teams
## 1. Purpose and parties
This policy applies to Northmoor's 74 suppliers, including cloud hosting, payroll, cleaning, professional advice and marketing. It covers risk before engagement, during the contract and at exit; it does not make a supplier a partner or transfer management accountability to Procurement.
## 2. Facts, scope and terms
Tier 1 critical suppliers can stop a core service, access sensitive data or create a single point of failure; Tier 2 suppliers are important but substitutable; Tier 3 suppliers are routine. Procurement scores business criticality, data, concentration, financial dependency, geography and substitutability and records the rationale before onboarding.
## 3. Process and responsibilities
Tier 1 due diligence includes ownership, sanctions and adverse-media screening, three years' accounts or equivalent financial evidence, insurance, two references, Cyber Essentials or ISO 27001 evidence where relevant, resilience testing and a data-protection assessment. Tier 2 uses a proportionate questionnaire; Tier 3 receives a basic identity, insurance and conflict check.
## 4. Evidence, records and safeguards
A contract must state services, SLA and RTO, confidentiality, UK GDPR controller/processor roles, subprocessor approval, security controls, incident notice within 24 hours, audit evidence, insurance, intellectual-property ownership, termination assistance and data return/deletion. Legal, Information Security and the business owner approve Tier 1 terms before signature.
## 5. Review, escalation and outcome
Tier 1 suppliers provide monthly SLA metrics, quarterly reviews, annual reassessment and material-incident notice within four hours where practicable; Tier 2 is reviewed annually. Northmoor tracks missed service, financial deterioration, cyber events and concentration. The policy does not demand an impossible audit or promise that certification proves safety.
## 6. Reservations and practical protections
Every Tier 1 supplier has an exit plan: alternative source, data export, access credentials, people dependency, RTO/RPO, transition owner and tested workaround. A supplier must cooperate with orderly termination; emergency substitution may be activated after a Gold/Silver decision and documented risk acceptance.
## 7. England and Wales law and completion
The Head of Procurement owns the policy, the CTO owns technical risk and the board accepts residual risk above £250,000 exposure. Staff report concerns immediately; retaliation is prohibited. The policy is reviewed annually. England and Wales law applies and version 2.1 is approved on 26 August 2030.