All sample legal documents

Third-Party Risk Management Policy

A completed vendor lifecycle policy covering tiering, due diligence, contract controls, monitoring and exit planning.

Jurisdiction: England and Wales - completed fictional worked example

Download Sample

An editable Microsoft Word version is available from the interactive page.

Important: This sample provides general legal information only and is not legal advice. Check the law, prescribed forms and signing requirements that apply to your exact jurisdiction and circumstances before use.

# THIRD-PARTY RISK MANAGEMENT POLICY

Date: 26 August 2030

Parties: Northmoor Analytics Limited and its procurement and business teams

## 1. Purpose and parties

This policy applies to Northmoor's 74 suppliers, including cloud hosting, payroll, cleaning, professional advice and marketing. It covers risk before engagement, during the contract and at exit; it does not make a supplier a partner or transfer management accountability to Procurement.

## 2. Facts, scope and terms

Tier 1 critical suppliers can stop a core service, access sensitive data or create a single point of failure; Tier 2 suppliers are important but substitutable; Tier 3 suppliers are routine. Procurement scores business criticality, data, concentration, financial dependency, geography and substitutability and records the rationale before onboarding.

## 3. Process and responsibilities

Tier 1 due diligence includes ownership, sanctions and adverse-media screening, three years' accounts or equivalent financial evidence, insurance, two references, Cyber Essentials or ISO 27001 evidence where relevant, resilience testing and a data-protection assessment. Tier 2 uses a proportionate questionnaire; Tier 3 receives a basic identity, insurance and conflict check.

## 4. Evidence, records and safeguards

A contract must state services, SLA and RTO, confidentiality, UK GDPR controller/processor roles, subprocessor approval, security controls, incident notice within 24 hours, audit evidence, insurance, intellectual-property ownership, termination assistance and data return/deletion. Legal, Information Security and the business owner approve Tier 1 terms before signature.

## 5. Review, escalation and outcome

Tier 1 suppliers provide monthly SLA metrics, quarterly reviews, annual reassessment and material-incident notice within four hours where practicable; Tier 2 is reviewed annually. Northmoor tracks missed service, financial deterioration, cyber events and concentration. The policy does not demand an impossible audit or promise that certification proves safety.

## 6. Reservations and practical protections

Every Tier 1 supplier has an exit plan: alternative source, data export, access credentials, people dependency, RTO/RPO, transition owner and tested workaround. A supplier must cooperate with orderly termination; emergency substitution may be activated after a Gold/Silver decision and documented risk acceptance.

## 7. England and Wales law and completion

The Head of Procurement owns the policy, the CTO owns technical risk and the board accepts residual risk above £250,000 exposure. Staff report concerns immediately; retaliation is prohibited. The policy is reviewed annually. England and Wales law applies and version 2.1 is approved on 26 August 2030.

Create a version for your situation

Create a tailored Third-Party Risk