Vendor Management Policy

Explore Roboto Studio's Vendor Management Policy. Find out how we strategically select and manage vendors for optimal collaboration and efficiency.

1.0 Purpose

The purpose of this policy is to set forth the guidelines that should be followed to maintain the security of the organization’s information systems and data when Roboto Studio enters into any arrangement with a third-party supplier or vendor or Cloud Service Provider (CSP), as well as to identify elements of managing vendors, due diligence, risk assessments, and contract management.

2.0 Scope

The scope of this policy covers Roboto Studio’s relationship with business partners, suppliers or third-party vendors, including CSPs (collectively referred to as “vendors” or “third parties”), including any third-party access to information, IT assets, IT infrastructure, and facilities of Roboto Studio and/or its client information. The policy also covers all third-party related activities associated with providing security for cloud services (i.e., SaaS, PaaS, IaaS) and Artificial Intelligence (i.e., generative AI and Large Language Models).

3.0 Policy

3.1 Managing Outsourcing Risks

Roboto Studio shall develop an organization-wide strategy for managing risks associated with supply-chain management. Risks involved must be identified, documented, and vetted by Roboto Studio’s management before outsourcing any processes or services to a third party/vendor or allowing third-party access to the organization’s information or systems.

3.2 Contracts

Contracts that include the exchange of confidential data must require confidentiality agreements to be executed by the vendor and shall identify applicable security and privacy policies and procedures to which the vendor is subject. Contracts must clearly identify the roles and responsibilities of the vendor and the security and privacy reporting requirements.

3.3 Oversight and Monitoring

Management shall designate staff responsible for monitoring the performance and compliance of each outsourced program/vendor/cloud service. The duties should include regular review of the third party’s performance to determine compliance with expectations and contracts. All third-party vendors shall be evaluated for security risks to the organization periodically through a formal risk assessment process.

3.4 Termination of Service

Upon termination of vendor services, contracts must require the return or destruction of all Roboto Studio’s data. Roboto Studio’s management shall immediately ensure the termination of the vendor’s access to Roboto Studio systems. Exit strategies must be developed for the use of any vendor services and exit reviews shall be performed on vendors to ensure compliance with termination clauses.

Version History

A list of all the versions including their version, author, date and comments.

0.1Joe Pindar (Fresh Security)2022-05-16First Draft
1.0Joe Pindar (Fresh Security)2022-06-01Sign Off
1.1Joe Pindar (Fresh Security)2023-10-01Add patching timeliness requirements. Add policy review schedule. Review for best practice alignment.



Like what you see ?

Sign up for a 30 min chat and see if we can help

© 2024 Roboto Studio Ltd - 11126043

Roboto Studio Ltd,

86-90 Paul Street,

London, EC2A 4NE

Registered in England & Wales | VAT Number 426637679