Back to blog
Templates

Supplier security schedule template: the clauses worth negotiating

Every security requirement is negotiable before signature and almost none afterwards. The clauses that get used in anger, the ones vendors concede easily, and how to handle a refusal.
GRC Copilot Team
Supplier security schedule template: the clauses worth negotiating

A security schedule is only worth the clauses you would actually invoke. Most run to pages of boilerplate and omit the two provisions organisations reach for when something goes wrong. Write for the incident, not for the file.

The clauses used in anger

  1. Breach notification with a hard deadline. Specify hours, not "promptly", and define what starts the clock - typically the supplier becoming aware. Your own regulatory clocks depend on this, so a 72-hour supplier clause can leave you with no time at all.
  2. Incident cooperation. An obligation to support your investigation, including providing logs and making staff available. Without it you may be unable to establish what happened in your own incident.
If you can only win two points in a negotiation, win these. Everything below matters less in practice.

The rest of the schedule

  • Security standards maintained for the term - a named certification held throughout, not merely at signature.
  • Sub-processors - disclosure, notice before new ones, and flow-down of equivalent obligations.
  • Data location, with notice before change, covering backups and support access from other regions.
  • Audit or assurance - most suppliers offer a report rather than an on-site audit. Accept that for most tiers; hold the audit right for critical suppliers.
  • Personnel screening for anyone handling your data.
  • Vulnerability and patching commitments with timeframes by severity.
  • Return and deletion on exit, in a usable format, with certification.
  • Liability not capped far below the realistic cost of a breach of your data.

What vendors concede easily

Notification timelines, sub-processor disclosure, deletion certification and evidence of certification are usually straightforward. Liability caps and audit rights are where negotiations stall - so spend your capital accordingly rather than fighting every clause equally.

Track supplier obligations against real evidence

GRC Copilot runs structured vendor assessments, tracks assurance evidence and expiry, and connects supplier risk to the controls that depend on them.

Tier the schedule

Applying the full schedule to every purchase is how security becomes the department that blocks a stationery order. Maintain three versions - critical, important and low - and publish the tiering criteria so procurement can apply them without asking.

When a supplier refuses

Large providers will not amend standard terms for a mid-sized customer, and pretending otherwise wastes weeks. The workable response:

  • Accept published commitments where they are adequate - a solid trust centre and assurance report may cover more than a negotiated clause would.
  • Where a term cannot be obtained, record the gap as an accepted risk with the reason, a compensating control and a named business owner. That is defensible; silence is not.
  • Keep a list of what you failed to get, and raise it at renewal - the one recurring moment leverage returns.

After signature

Clauses only work if someone checks them. Track certificate expiry, re-read assurance reports rather than filing them, watch for sub-processor changes, and confirm deletion actually happened at exit. Departed suppliers with live access are the vendor-side equivalent of an unrevoked leaver.

Frequently asked questions

Should we demand audit rights from everyone?

No. Accept assurance reports for most tiers and reserve audit rights for critical suppliers, where you might actually exercise them.

What notification window should we ask for?

24 to 48 hours of the supplier becoming aware, and define awareness. Anything longer erodes your own reporting margin.

What if the supplier is critical and refuses?

Escalate as a business risk decision with the exposure stated plainly. That acceptance belongs to the business owner, not to security.

Do we need a separate schedule per supplier?

Three tiered templates cover almost everything. Bespoke drafting per supplier does not scale.

Key takeaways

  • Breach notification and incident cooperation are the clauses used in anger.
  • Define what starts the notification clock, in hours.
  • Tier the schedule or procurement will bypass it.
  • Record refused terms as accepted risk with an owner.
#supplier #contract #security-schedule #template #breach-notification #audit-rights