third partyVersion 1SOC2ISO27001NIST800-171
Third-Party Risk Assessment Policy
Tiering, scoring, and contractual requirements for every vendor relationship.
Third-Party Risk Assessment Policy
Companion to 017-vendor-subprocessor-management-policy.md; this
document defines how Rex Black scores third-party risk and
enforces tiered requirements.
1. Tiering
| Tier | Criteria | Examples |
|---|---|---|
| T1 | Processes Restricted or critical to operations. | AWS, Stripe |
| T2 | Processes Confidential data or single-function critical path. | Google Workspace, GitHub |
| T3 | Internal-only data or low operational impact. | Marketing SaaS |
2. Minimum requirements by tier
| Requirement | T1 | T2 | T3 |
|---|---|---|---|
| SOC 2 Type II (or ISO 27001) | ✓ | ✓ | , |
| DPA with SCCs where applicable | ✓ | ✓ | Optional |
| Annual security review | ✓ | ✓ | Optional |
| Shared-responsibility model documented | ✓ | ✓ | , |
| Incident notification SLA ≤ 72 hours | ✓ | ✓ | Optional |
| Quarterly attestation refresh check | ✓ | ( | ) |
| Named internal owner | ✓ | ✓ | ✓ |
| Entry in subprocessor register | ✓ | ✓ | ✓ |
3. Assessment inputs
- Vendor questionnaire (SIG Lite or Rex Black's short form for smaller vendors).
- SOC 2 / ISO reports.
- Penetration test summary if available.
- Public incident record (status page, news, CVE history).
- Financial health (for T1, where the vendor is single-sourced).
- Data flow diagram showing what leaves Rex Black.
4. Scoring
Each vendor gets a score (Low / Medium / High / Critical) driven by:
- Data classification processed.
- Criticality to operations.
- Maturity of the vendor's attestations and controls.
- Observed incident history.
The score feeds the Risk Register as an inherent risk. Treatment (monitoring level, contractual requirements) is calibrated to the score.
5. Contract terms
For T1 / T2, Rex Black's base contract language includes:
- Security requirements referencing the vendor's SOC 2 scope.
- Notification of security incidents affecting Rex Black data within 72 hours of discovery.
- Right to audit (via third party or questionnaire) and right to receive renewed attestations annually.
- Data return and certified deletion within 30 days of termination.
- Sub-subprocessor notice obligation.
6. Ongoing monitoring
- Renewal triggers a review of the vendor's latest attestation.
- Material incidents at a vendor trigger an immediate re-assessment.
- An out-of-date T1/T2 attestation (> 13 months) is a Risk Register entry.
7. Offboarding
Offboarding is executed per the Vendor Management Policy; the subprocessor register is updated with the offboarding date and the risk is closed.
8. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Security Officer | Tiers, scoring, monitoring cadence. |
| Privacy Officer | DPA review; data flow approval. |
| Legal counsel | Contract negotiation and renewals. |
| Owner | Relationship management; performance review. |
9. References
017-vendor-subprocessor-management-policy.md020-risk-management-policy.mdregisters/subprocessors.md
10. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.