Third Parties
Keep one register of every supplier and vendor so you always know who touches your data and when each contract is due for review.
The Third Parties module is your central register of the suppliers and vendors your organisation relies on. For each one you capture contact details, the services they provide, a risk tier, and the data-protection facts you need for ISO 27001 and UK GDPR. Keeping this up to date means nothing lapses quietly in the background.
Add a vendor
Create the record
Add the vendor's name, contact details, and a short description of the services they provide to you.
Set a risk tier
Choose Low, Medium, High, or Critical based on how much they could affect your security and operations.
Record data-protection info
Note whether the vendor processes personal data and whether a Data Processing Agreement (DPA) is in place, with its signed date.
Track key dates
Set the contract expiry and next review dates so renewals and reassessments never catch you out.
Risk tiers
The risk tier gives you a quick read on how closely a vendor needs to be managed.
| Tier | Typical vendor |
|---|---|
| Low | No access to your data or systems; easily replaced. |
| Medium | Limited access or non-sensitive data; moderate reliance. |
| High | Processes personal or sensitive data; important to operations. |
| Critical | Deep access to critical data or systems; hard to replace. |
Evidence and questionnaires
Attach supporting evidence to any vendor — contracts, certifications, and security assessments — so proof lives alongside the record. You can also link security questionnaires to a vendor to gather their own answers about how they protect your data.
Works with
- Questionnaires — send security assessments to your vendors. See Questionnaires.
- Evidence — attach contracts and certifications. See Evidence.
- Risks — feed vendor risk tiers into your wider assessment. See Risk Register.