The entity assesses and manages risks associated with vendors and business partners
The entity establishes specific requirements for a vendor and business partner engagement that includes (1) scope of services and product specifications, (2) roles and responsibilities, (3) compliance requirements, and (4) service levels
The entity assesses, on a periodic basis, the risks that vendors and business partners (and those entities’ vendors and business partners) represent to the achievement of the entity’s objectives
The entity assigns responsibility and accountability for the management of risks associated with vendors and business partners
The entity establishes communication and resolution protocols for service or product issues related to vendors and business partners
The entity establishes exception handling procedures for service or product issues related to vendors and business partners
The entity periodically assesses the performance of vendors and business partners
The entity implements procedures for addressing issues identified with vendor and business partner relationships
The entity implements procedures for terminating vendor and business partner relationships
The entity obtains confidentiality commitments that are consistent with the entity’s confidentiality commitments and requirements from vendors and business partners who have access to confidential information
On a periodic and as-needed basis, the entity assesses compliance by vendors and business partners with the entity’s confidentiality commitments and requirements
The entity obtains privacy commitments, consistent with the entity’s privacy commitments and requirements, from vendors and business partners who have access to personal information
On a periodic and as-needed basis, the entity assesses compliance by vendors and business partners with the entity’s privacy commitments and requirements and takes corrective action as necessary.