Vendor Management
Skill packages tagged with “Vendor Management”
ICT Third-Party Risk Policy (DORA)
Draft the ICT third-party risk management policy required by DORA Art. 28 and RTS 2024/1773, covering strategy, due diligence, contractual provisions (Art. 30), monitoring, exit planning, concentration risk, and sub-outsourcing governance.
ISO 20000 Supplier Management
Establish supplier management for ISO/IEC 20000-1:2011 Clause 7.2 -- supplier identification, criticality classification, contract requirements, performance monitoring, and governance of outsourced processes.
SOC 2 Vendor Management
Establish third-party and subservice organization oversight for SOC 2 audit readiness. Risk-tiered assessment framework with vendor register, SOC report review validation, CSOCs validation, and tiered security requirements per CC9.2. Covers vendor risk scoring, SOC report currency checks, and bridge letter tracking.