Back to blog
Checklists

Vendor onboarding security checklist: from request to go-live

A step-by-step checklist for onboarding a supplier securely - triage, tiering, due diligence, contract terms, technical setup and the offboarding plan you should write before go-live.
GRC Copilot Team
Vendor onboarding security checklist: from request to go-live

Most third-party risk problems are created at onboarding, when speed matters and nobody wants to be the blocker. A checklist that runs in parallel with procurement - rather than after it - is the difference between managing supplier risk and inheriting it.

Step 1 - Intake triage

Five questions, answered before any assessment work:

  • What data will they access, and at what classification?
  • Will they connect to our systems or hold credentials?
  • What breaks if they are unavailable?
  • Are they processing personal data on our behalf?
  • Is there an existing vendor who already does this?

That last question prevents a surprising amount of work - and a surprising amount of duplicate spend.

Step 2 - Tier the vendor

  • Tier 1 - Critical: sensitive data at volume, privileged access, or business-critical availability. Full assessment, evidence review, contractual security terms, annual reassessment.
  • Tier 2 - Important: moderate data or operational dependency. Standard questionnaire and certification review.
  • Tier 3 - Low: no sensitive data, easily replaced. Lightweight screening.
Tiering is what makes the programme survivable. Sending every supplier a 200-question assessment guarantees the process gets bypassed for anything urgent.

Step 3 - Due diligence (Tier 1 and 2)

  • Certifications - ISO 27001 (check the scope statement covers the service you are buying, and the expiry date), SOC 2 Type II, PCI attestation where relevant.
  • Read the SOC 2 exceptions section and the complementary user entity controls - the things you must do.
  • Penetration test recency and evidence that high findings were fixed.
  • Data locations - storage, processing, backups, and support access jurisdictions.
  • Subprocessor list, and whether you get notice of changes.
  • Incident notification commitments and timelines.
  • Business continuity - RTO, RPO and when they last tested.
  • Cyber liability insurance.
  • AI usage - whether AI processes your data, and whether it trains on it.

Onboard vendors without the spreadsheet marathon

GRC Copilot tiers suppliers, generates the right assessment per tier, reads the evidence they return, and tracks reassessment dates automatically.

Step 4 - Contract terms

  • Security requirements appropriate to the tier.
  • Breach notification window - specify hours, not "promptly".
  • Data processing agreement where personal data is involved.
  • Subprocessor approval or notification rights.
  • Audit or evidence rights proportionate to risk.
  • Data location commitments.
  • Secure return and deletion of data at termination, with confirmation in writing.
  • Right to terminate on material security failure.

Step 5 - Technical onboarding

  • Provision least-privilege access; no shared accounts.
  • MFA enforced for any vendor access.
  • Time-bound access where the engagement is finite.
  • Log vendor activity distinguishably from staff activity.
  • Add to the asset and vendor inventory with a named internal owner.
  • Record the data flows - what goes to them, and what comes back.

Step 6 - Write the exit plan now

Before go-live, record how you would leave: how data is returned or destroyed, how long migration would take, whether an alternative exists, and who owns the relationship. Exit plans written under pressure are always worse, and regulators increasingly ask to see them for critical providers.

Step 7 - Ongoing

  • Reassess on the tier cadence - annually for critical.
  • Reassess on trigger events: their breach, ownership change, new subprocessor, or a change in the service.
  • Review access quarterly, including vendor accounts.
  • Offboard properly - revoke access, confirm deletion in writing, close the record.

Frequently asked questions

What if procurement has already signed?

Assess anyway and document residual risk with an accountable owner. Then fix the process so security triage happens at intake - retroactive assessment is how the same problem recurs.

Is a SOC 2 report enough on its own?

It is strong evidence, but read the period covered, the criteria in scope, the exceptions, and the complementary user entity controls you are responsible for.

How do we handle vendors who refuse assessment?

Treat refusal as a finding, escalate to the business owner, and require documented risk acceptance from someone with authority.

Do low-tier vendors need anything?

Basic screening and contract terms. The point of tiering is to spend scrutiny where the risk actually is.

Key takeaways

  • Triage at intake, in parallel with procurement - not after signature.
  • Tier first; uniform assessment guarantees the process is bypassed.
  • Check certificate scope and SOC 2 exceptions, not just their existence.
  • Write the exit plan before go-live.
#vendor-onboarding #checklist #due-diligence #contracts #offboarding