Vendor risk management glossary
The terms that come up when you vet vendors, assess processors and prepare for a SOC 2 or ISO 27001 audit, each defined in a paragraph, with a link to the guide that goes further.
BAA (business associate agreement)
The contract HIPAA requires between a covered entity (or a business associate) and a business associate that creates, receives, maintains or transmits protected health information on its behalf. Its required terms are set out in 45 CFR 164.504(e), with the Security Rule's requirements in 164.314(a): permitted uses of PHI, safeguards, breach reporting, flow-down to subcontractors, and return or destruction of PHI at termination.
Read more: HIPAA vendor risk assessment: vetting business associates under the Security Rule
Bridge letter
Also: Gap letter
A letter from a service organisation's management covering the time between the end of its most recent SOC report period and a more recent date, stating whether there have been material changes to the controls the report described. It is written by management, not the auditor, so it carries less weight than the report itself; customers accept it to cover a gap of a few months until the next report is issued.
Read more: SOC 2 vendor management: what auditors expect from your third-party programme
CAIQ (Consensus Assessments Initiative Questionnaire)
A free security questionnaire for cloud providers published by the Cloud Security Alliance and mapped to its Cloud Controls Matrix (CCM). Providers often publish a completed CAIQ in the CSA STAR registry, which lets a customer review their answers without sending a questionnaire of its own.
Read more: Vendor risk assessment questionnaire: what to ask, and how to score the answers
Concentration risk
The risk that comes from depending heavily on a single party: one vendor supporting many critical processes, or many of your vendors relying on the same fourth party, such as one cloud provider or region. Each vendor may look acceptable on its own while together they create a single point of failure that no individual assessment shows.
Read more: ISO 27001 Annex A 5.21: Managing information security in the ICT supply chain · Third-party risk management for small businesses: a programme without a GRC team
DPA (data processing agreement)
Also: Data processing addendum
The contract between a controller and a processor that GDPR Article 28(3) requires: it describes the processing and binds the processor to act on documented instructions, keep the data confidential and secure, control sub-processors, assist the controller, delete or return data at the end, and allow audits. In European usage DPA can also mean a data protection authority, the regulator; context usually makes clear which.
Read more: GDPR Article 28 processor due diligence: vetting vendors that handle personal data
Inherent vs residual risk
Inherent risk is the risk a vendor relationship carries before any controls are considered, driven by what data the vendor sees and how critical the service is. Residual risk is what remains after the vendor's controls and your own mitigations are taken into account. Inherent risk decides how closely to look; residual risk is what you accept, or not, when you approve the vendor.
Read more: Vendor risk tiering: how to classify third parties and set a review cadence · Vendor due diligence: a practical guide for small and mid-sized businesses
Nth-party risk
Risk from any party further down the supply chain than your direct vendors: fourth parties, their suppliers, and so on. Few organisations can assess these parties directly; Nth-party risk management usually means mapping who they are from vendors' sub-processor lists and assurance reports, and watching for concentration where many vendors depend on the same one.
Read more: ISO 27001 Annex A 5.21: Managing information security in the ICT supply chain
OFAC SDN list
The Specially Designated Nationals and Blocked Persons List published by the US Treasury's Office of Foreign Assets Control. US persons are generally prohibited from dealing with people and entities on it, and their property in US jurisdiction is blocked. Entities owned 50 percent or more by blocked persons are treated as blocked even if not named. Screening vendors and their owners against it is a basic onboarding check for US businesses.
Read more: US vendor onboarding: W-9, SAM.gov, OFAC, insurance and bank verification
Risk tiering
Sorting vendors into a small number of risk levels, commonly critical, high, medium and low, based on the sensitivity of the data they access, how critical their service is and how hard they would be to replace. The tier sets how deep due diligence goes, which contract terms apply and how often the vendor is reassessed, so effort follows risk.
Read more: Vendor risk tiering: how to classify third parties and set a review cadence
SAM.gov exclusion
A record in the US System for Award Management, run by the General Services Administration, showing that a person or company is excluded, for example suspended or debarred, from receiving federal contracts and certain federal financial assistance. Federal contractors and grant recipients must check it; for commercial buyers it is a quick, strong red-flag check.
Read more: US vendor onboarding: W-9, SAM.gov, OFAC, insurance and bank verification
SCCs (Standard Contractual Clauses)
Model contract clauses adopted by the European Commission that provide a lawful basis under GDPR Article 46 for transferring personal data to countries without an adequacy decision. The current set, adopted in June 2021 by Implementing Decision (EU) 2021/914, has four modules for different controller and processor combinations. The UK uses its own International Data Transfer Agreement or the UK Addendum to the EU clauses.
Read more: GDPR Article 28 processor due diligence: vetting vendors that handle personal data
SIG (Standardized Information Gathering questionnaire)
A third-party risk questionnaire published by Shared Assessments, available in a shorter and a fuller version and updated annually, covering security, privacy, resilience and other risk domains. It is licensed rather than free, and widely used by larger organisations to assess their vendors.
Read more: Vendor risk assessment questionnaire: what to ask, and how to score the answers
SOC 2 Type I vs Type II
Both are attestation reports by an independent CPA firm on a service organisation's controls against the AICPA Trust Services Criteria (security, and optionally availability, processing integrity, confidentiality and privacy). A Type I report assesses whether controls are suitably designed at a single point in time. A Type II report also tests whether they operated effectively over a period, typically 3 to 12 months, and is the stronger evidence for vendor due diligence.
Read more: SOC 2 vendor management: what auditors expect from your third-party programme
Sub-processor
Under the GDPR, a processor engaged by your processor to carry out processing of personal data on your behalf, such as the hosting provider behind a SaaS tool. Article 28(2) and (4) require your prior specific or general written authorisation, notice of changes with a chance to object, and the same data protection obligations passed down by contract, with your processor remaining liable for the sub-processor's performance.
Read more: GDPR Article 28 processor due diligence: vetting vendors that handle personal data
Third party vs fourth party
A third party is an organisation you have a direct relationship with: your vendor, supplier or contractor. A fourth party is your vendor's vendor, such as the cloud host, email service or subcontractor your vendor relies on to serve you. You have no contract with a fourth party, so you manage its risk through your vendor: by asking who it is, requiring obligations to flow down, and being told when it changes.
Read more: ISO 27001 Annex A 5.21: Managing information security in the ICT supply chain · AI vendor due diligence: a checklist for vendors that use AI on your data
TIA (transfer impact assessment)
An assessment of whether the law and practice of the country personal data is transferred to could stop the chosen transfer tool, usually SCCs, from giving the data essentially equivalent protection, and what supplementary measures are needed if so. It has been expected since the Court of Justice's Schrems II judgment in July 2020 and is described in the European Data Protection Board's Recommendations 01/2020.
Read more: GDPR Article 28 processor due diligence: vetting vendors that handle personal data
TPRM (third-party risk management)
The ongoing process of identifying, assessing, mitigating and monitoring the risks that come from vendors, suppliers, contractors and other third parties across the relationship: before signing, during it and at exit. In a small business it usually comes down to a vendor inventory, risk tiering, proportionate due diligence, contract terms and a reassessment schedule.
Read more: Third-party risk management for small businesses: a programme without a GRC team · Vendor due diligence: a practical guide for small and mid-sized businesses
Vendor vetting
Checking a prospective vendor before approving it: verifying the legal entity, screening it and its owners for sanctions and adverse media, and assessing financial stability, security, privacy and contract terms in proportion to its risk, then recording a decision. It is the first stage of vendor due diligence, which continues with reassessment for as long as the vendor is used.
Read more: How to vet a vendor: a ten-step vendor vetting checklist · Vendor onboarding checklist: the checks to finish before the contract is signed
W-8BEN-E
IRS Form W-8BEN-E, Certificate of Status of Beneficial Owner for United States Tax Withholding and Reporting (Entities). A foreign entity gives it to a US payer to document that it is not a US person, its FATCA status and any tax treaty benefits it claims, which determine how much US tax, if any, the payer must withhold. Foreign vendors provide it instead of a W-9.
Read more: US vendor onboarding: W-9, SAM.gov, OFAC, insurance and bank verification
W-9
IRS Form W-9, Request for Taxpayer Identification Number and Certification. A US vendor gives it to the business paying it, supplying its legal name, tax classification and taxpayer identification number (usually an EIN), and certifying whether it is subject to backup withholding. The payer uses it for 1099 information reporting.
Read more: US vendor onboarding: W-9, SAM.gov, OFAC, insurance and bank verification
Put the vocabulary to work
VendorVett keeps your vendor inventory, risk tiers, questionnaires, evidence and decisions in one audit-ready record. Free to start.