Vendor onboarding security that survives the audit — and the incident
A repeatable path from first contract to reassessment date: tier the vendor, verify the evidence, grant least privilege, record the residual risk and schedule the next review. Built for UK, Australian and US requirements in one control set.
Six steps to secure vendor onboarding
Tier before you assess
Verify the evidence, not the claim
Provision least privilege
Land the risk in the register
Schedule the next look
Meet the regime you operate under
What changes by region
| Region | Primary expectations | Usual evidence request |
|---|---|---|
| United Kingdom | ISO 27001 Annex A 5.19–5.22, UK GDPR Art. 28, IDTA for transfers, FCA/PRA operational resilience for regulated firms | ISO 27001 certificate + SoA, DPA, Cyber Essentials Plus |
| Australia | Privacy Act APPs (incl. APP 8), APRA CPS 234 and CPS 230 for regulated entities | ISO 27001 or SOC 2, Essential Eight maturity statement, data-location detail |
| United States | SOC 2 Trust Services Criteria, HIPAA BAAs, GLBA, CCPA/CPRA service-provider terms, FedRAMP for federal | SOC 2 Type II report, SIG or CAIQ, pen test summary |
One control set answers all three. Map once, reuse the evidence — see the supplier due diligence checklist for the stage-by-stage version.
Onboarding checklist at a glance
- Tier assigned and rationale recorded
- Business owner named
- Certificate scope checked against the service
- SOC 2 report period and exceptions reviewed
- DPA signed, sub-processors listed
- Transfer mechanism documented
- SSO/MFA enforced, least-privilege roles
- Incident notification timescales agreed
- Residual risk logged with treatment owner
- Reassessment and certificate expiry dates set
Answers buyers, procurement and auditors want
What is vendor onboarding security?+
Vendor onboarding security is the set of checks and controls applied when a new supplier is brought into your environment: assessing their security posture, verifying certification evidence, agreeing contractual security obligations, provisioning least-privilege access and recording residual risk. It is the point at which most third-party exposure is either contained or quietly accepted.
UK: what do UK regulators and ISO 27001 expect for vendor onboarding?+
In the UK, ISO 27001:2022 Annex A 5.19–5.22 set the baseline: security in supplier relationships, security within agreements, ICT supply-chain risk management, and monitoring and review. Where personal data is involved, UK GDPR Article 28 requires a written processor contract and due diligence that the processor offers sufficient guarantees; international transfers need the UK IDTA or the UK Addendum to the EU SCCs. Regulated firms should also read the FCA and PRA operational resilience expectations for material outsourcing, which require identifying important business services and their third-party dependencies.
Australia: what applies to vendor onboarding in Australia?+
Australian Privacy Principles under the Privacy Act 1988 make you accountable for personal information disclosed to a supplier, including overseas recipients under APP 8. APRA-regulated entities must follow CPS 234 for information security — which explicitly requires assurance over third parties handling their information assets — and CPS 230 for operational risk and material service provider management. Many Australian buyers additionally reference the ACSC Essential Eight as a practical maturity baseline in vendor questionnaires.
US: what do US buyers ask for during vendor onboarding?+
US enterprise buyers usually lead with a SOC 2 Type II report and check the report period, scope and any exceptions, often alongside a completed SIG or CAIQ questionnaire. Sector rules add layers: HIPAA requires a Business Associate Agreement for protected health information, GLBA safeguards apply in financial services, and federal work brings FedRAMP and NIST SP 800-161 supply-chain requirements. State privacy laws such as the CCPA/CPRA impose specific service-provider contract terms.
How long should vendor onboarding take?+
For a low-tier supplier with no data access, minutes — a register entry and a signed contract. For a critical supplier, expect one to three weeks, most of it waiting on their evidence. The way to compress it is to ask for the right artefacts once, in a single request, rather than discovering gaps across three rounds of email.
What should we do if a vendor has no certification?+
Do not treat absence of a certificate as an automatic rejection — treat it as a control gap to be managed. Substitute evidence (penetration test, documented policies, architecture review), tighten the contract, reduce the data or access granted, and record the residual risk with a review date and, where appropriate, a certification milestone in the contract.
How does ISO-STANDARD.app handle vendor onboarding security?+
Vendors are records inside the same workspace as your risks, controls, assets and evidence. Each carries a tier, an owner, stored certificates with expiry reminders, questionnaire responses, linked risks and a reassessment date — and the resulting supplier register is exactly what an ISO 27001 auditor asks to see.
Make vendor onboarding evidence, not email
Tier, assess, log the risk and set the review date in one workspace — and publish your own trust profile so buyers stop sending you questionnaires.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.