HLD Group
Vendor & third-party risk policy
Assessment and ongoing management of suppliers and subprocessors.
Last updated: 24 July 2026
Version 1.4 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy defines how HLD Group assesses, onboards, monitors, and offboards third-party vendors and service providers to manage the security, privacy, continuity, and compliance risks they introduce. Much of our risk sits in our supply chain, and third parties who handle our data or systems are governed as an extension of our own controls.
2. Scope
This policy applies to all third parties that process HLD Group or customer data, connect to our systems, or provide services material to our operations, including cloud providers, software vendors, subprocessors, contractors, and subcontractors.
3. Definitions
- Vendor — a third party providing goods or services to HLD Group
- Subprocessor — a vendor that processes personal data on our behalf when we act as processor
- Critical vendor — a vendor whose failure would materially affect our operations or obligations
- Fourth party — a vendor’s own suppliers, whose risk can flow through to us
- Due diligence — the assessment of a vendor’s risk before and during engagement
4. Risk-based due diligence
Vendors are assessed proportionate to the risk they present, considering the sensitivity of data involved, the level of system access, and the criticality of the service. Higher-risk vendors receive deeper assessment, including review of certifications, security questionnaires, and, where warranted, evidence and audit reports.
- Security posture, including certifications such as SOC 2, ISO/IEC 27001, and relevant attestations
- Privacy and data protection practices, and location of data processing
- Business continuity and resilience of critical vendors
- Financial and reputational stability for critical dependencies
- Sanctions, export control, and modern slavery screening where relevant
5. Contractual safeguards
- Security and confidentiality obligations appropriate to the data and access
- Data processing terms and subprocessor controls where personal data is involved
- Breach and incident notification obligations with defined timeframes
- Right to audit or to receive assurance evidence for higher-risk vendors
- Service levels and continuity commitments for critical services
- Return or deletion of data and orderly exit at the end of the engagement
6. Ongoing monitoring and reassessment
Vendor risk is monitored throughout the relationship, not only at onboarding. Critical and high-risk vendors are reassessed periodically and on material change, and their assurance evidence is refreshed. Fourth-party concentration and dependency risks are considered for critical services.
7. Access and offboarding
Vendor access follows the Access Control Policy — time-bound, least-privilege, and individually attributable — and is removed promptly when no longer required. On termination, access is revoked, and data is returned or securely deleted with confirmation obtained.
8. Framework alignment
- ISO/IEC 27001:2022 Annex A controls 5.19 to 5.22 (supplier relationships) and 5.23 (cloud services)
- NIST SP 800-161 Rev. 1 (cybersecurity supply chain risk management)
- NIST SP 800-53 Rev. 5 control family SR (Supply Chain Risk Management)
- SOC 2 Trust Services Criteria CC9.2
9. Roles, exceptions, and review
Procurement and the requesting business own vendor relationships, with security and privacy assurance under the CISO and privacy officer. Exceptions require documented approval with compensating controls and an expiry date. This policy is reviewed at least annually.
Related frameworks
For contractual attestations or audit packs, contact [email protected].