What to check on a vendor before you sign
A questionnaire sent once is not due diligence. Here is how to tier vendors, write the contract and review the files that actually matter.
When a vendor hosts your personal information or connects to your systems, their incident becomes yours. Law 25 leaves the enterprise accountable to the people concerned. ISO 27001:2022, in controls A.5.19 to A.5.23, asks for a written agreement and follow-up over time. Most teams have the vendor fill in a form at onboarding, then file it.
Three tiers, not one questionnaire
Sending 80 questions to the coffee supplier wastes time on both sides. The tier follows what the vendor actually touches.
Standard
No personal information, no access to your systems. A light check at onboarding is enough, as long as the service does not change.
Important
They process some of your personal information, or they have an account in an application that is not critical. Ask where the data sits, who their subcontractors are, and how they notify you of an incident.
Critical
They hold sensitive personal information, an administration access, or a service you cannot operate without. Add a right to verify, an exit plan, and a review at least once a year.
What the written contract has to say
To entrust personal information to a service provider, Law 25 expects a written contract. Someone who is not a lawyer should be able to read it.
The measures the vendor takes to protect confidentiality.
Use limited to performing the mandate. No resale, and no training of a model on your data, unless a clause says so.
Retention ends with the mandate, with return or destruction.
Notice without delay of any breach or attempted breach of the confidentiality obligations.
The list of subcontractors, and a duty to tell you before adding one that touches the same information.
Review the file, do not only create it
An ISO or SOC 2 certificate from three years ago says nothing about the service you use today. Tie the review to the risk.
Critical
At least once a year, after an incident, and when the vendor changes a subcontractor or a hosting region.
Important
At contract renewal, and if the nature of the service changes.
Standard
At onboarding only, unless the vendor starts touching personal information or a system.
Exit is part of due diligence
When the contract ends, take the information back or have it destroyed, revoke accounts and remote access, and require the same from subcontractors. A dated, signed destruction certificate is worth more than an email that says it is done.
A vendor register that actually gets reviewed
CapTRISK tracks the inventory, questionnaires, score and review dates, instead of a file forgotten in a mailbox.
