VNDR-1 Vendor Registry

What is this control about?

It’s good compliance hygiene and a compliance requirement to track all your vendors and third-parties with whom you conduct business.  A vendor is not limited to a software company and can include business partners.

There are many ways to track this information; it could be done manually via spreadsheets or within a Vendor Management tool.

Luckily TrustCloud helps you automate this. For every system added in TrustOps, a vendor is added in the vendor registry.

Your job is to ensure that the vendor listing in TrustCloud is complete and includes all your vendors and business partners.

Available templates

TrustCloud has a curated list of templates internally or externally sourced to help you get started. Click on the link for a downloadable version:

  • Vendor Registrar template to track all vendors

Control implementation

Note: This control is 100% automated by TrustCloud. Connect your systems to enjoy the benefit of automation

For a manual implementation: 

At the very least and to meet compliance requirements, each organization must maintain a vendor listing or registrar and the registrar should include information such as:

  • Vendor description to describe the type of service provided
  • Contact information to have a method for contacting the vendor if and when an issue arises
  • Criticality rating based on the type of data being processed/accessed by the vendor
  • Agreement date to capture the contract date and terms agreed upon
  • Vendor status to capture the active or inactive status
  • Monitoring status to ensure that active monitoring is place on vendors with the highest criticality

What evidence do auditors look for?

Most auditors, at a minimum are looking for the below suggested action:

  • Provide the most up-to-date vendor listing

Evidence example

From the suggested action above, an example is provided below.

  1. Provide the most up-to-date vendor listing.

Automated registar in TrustCloud

Review the vendor page in TrustCloud to ensure that it is accurate and include all vendors.

VNDR 1screenshot1

