Skip to main content

third partyVersion 1SOC2ISO27001NIST800-171

Third-Party Risk Assessment Policy

Tiering, scoring, and contractual requirements for every vendor relationship.

Download PDFSHA-256 cd515001dd564bf8…

Third-Party Risk Assessment Policy

Companion to 017-vendor-subprocessor-management-policy.md; this document defines how Rex Black scores third-party risk and enforces tiered requirements.

1. Tiering

Tier Criteria Examples
T1 Processes Restricted or critical to operations. AWS, Stripe
T2 Processes Confidential data or single-function critical path. Google Workspace, GitHub
T3 Internal-only data or low operational impact. Marketing SaaS

2. Minimum requirements by tier

Requirement T1 T2 T3
SOC 2 Type II (or ISO 27001) ✓ ✓ ,
DPA with SCCs where applicable ✓ ✓ Optional
Annual security review ✓ ✓ Optional
Shared-responsibility model documented ✓ ✓ ,
Incident notification SLA ≤ 72 hours ✓ ✓ Optional
Quarterly attestation refresh check ✓ ( )
Named internal owner ✓ ✓ ✓
Entry in subprocessor register ✓ ✓ ✓

3. Assessment inputs

  1. Vendor questionnaire (SIG Lite or Rex Black's short form for smaller vendors).
  2. SOC 2 / ISO reports.
  3. Penetration test summary if available.
  4. Public incident record (status page, news, CVE history).
  5. Financial health (for T1, where the vendor is single-sourced).
  6. Data flow diagram showing what leaves Rex Black.

4. Scoring

Each vendor gets a score (Low / Medium / High / Critical) driven by:

  • Data classification processed.
  • Criticality to operations.
  • Maturity of the vendor's attestations and controls.
  • Observed incident history.

The score feeds the Risk Register as an inherent risk. Treatment (monitoring level, contractual requirements) is calibrated to the score.

5. Contract terms

For T1 / T2, Rex Black's base contract language includes:

  1. Security requirements referencing the vendor's SOC 2 scope.
  2. Notification of security incidents affecting Rex Black data within 72 hours of discovery.
  3. Right to audit (via third party or questionnaire) and right to receive renewed attestations annually.
  4. Data return and certified deletion within 30 days of termination.
  5. Sub-subprocessor notice obligation.

6. Ongoing monitoring

  • Renewal triggers a review of the vendor's latest attestation.
  • Material incidents at a vendor trigger an immediate re-assessment.
  • An out-of-date T1/T2 attestation (> 13 months) is a Risk Register entry.

7. Offboarding

Offboarding is executed per the Vendor Management Policy; the subprocessor register is updated with the offboarding date and the risk is closed.

8. Roles & responsibilities

Role Responsibility
Security Officer Tiers, scoring, monitoring cadence.
Privacy Officer DPA review; data flow approval.
Legal counsel Contract negotiation and renewals.
Owner Relationship management; performance review.

9. References

  • 017-vendor-subprocessor-management-policy.md
  • 020-risk-management-policy.md
  • registers/subprocessors.md

10. Revision history

Version Date Author Approver Change
1.0 2026-04-17 S.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center