Vendor Risk Management

Comprehensive third-party security assessment and monitoring program ensuring supply chain integrity and vendor compliance

Last Updated: September 2026

Policy Overview

POPS.GG (operated by CASH.BH LTD) maintains a comprehensive Vendor Risk Management (VRM) program to identify, assess, and mitigate risks associated with third-party vendors, service providers, and suppliers. This program ensures that vendors meet our security, privacy, and compliance standards and do not introduce unacceptable risks to our operations or customers.

Program Objectives

  • Risk Identification: Systematically identify and assess risks from third-party relationships
  • Due Diligence: Conduct thorough security assessments before vendor engagement
  • Continuous Monitoring: Ongoing oversight of vendor security posture and performance
  • Supply Chain Security: Protect against supply chain attacks and vulnerabilities
  • Compliance Assurance: Ensure vendors meet regulatory and contractual obligations
  • Incident Preparedness: Establish clear procedures for vendor-related security incidents

Scope & Applicability

This policy applies to all third-party relationships including:

  • Service Providers: Cloud infrastructure, SaaS applications, professional services
  • Technology Vendors: Software, hardware, security tools, development platforms
  • Data Processors: Vendors processing customer or employee personal data
  • Business Partners: Payment processors, advertising networks, integration partners
  • Professional Services: Consultants, auditors, legal counsel with system access
  • Suppliers: Physical goods suppliers with network connectivity or data access

Exclusions

This policy does not apply to: customers, end-users, employees (covered by HR policies), or vendors with no access to systems, data, or facilities.

Vendor Risk Classification

All vendors are classified by risk tier based on the nature and sensitivity of their access, data handling, and potential business impact. Risk tier determines the level of due diligence, assessment frequency, and contractual requirements.

Critical Risk (Tier 1)

Assessment Frequency: Annual review of published documentation and status pages
Due Diligence: For Tier 1 providers we rely on their published security/compliance documentation and status pages, reviewed annually

Examples:

  • Cloud infrastructure providers (hosting production systems)
  • Payment processors and financial service providers
  • Database hosting services with customer data
  • Identity and access management providers
  • Vendors with production network access
  • Data backup and disaster recovery providers

High Risk (Tier 2)

Assessment Frequency: Annual review + semi-annual monitoring
Due Diligence: Security questionnaire, documentation review, third-party certifications

Examples:

  • SaaS applications processing personal data
  • Email and communication service providers
  • Security tool vendors (SIEM, EDR, vulnerability scanners)
  • Development and staging environment providers
  • Analytics and monitoring platforms
  • Marketing automation with customer data access

Medium Risk (Tier 3)

Assessment Frequency: Biennial review
Due Diligence: Standard security questionnaire, basic documentation

Examples:

  • Productivity and collaboration tools (limited data access)
  • Non-sensitive SaaS applications
  • Professional services with supervised access
  • Training and development platforms
  • Project management tools

Low Risk (Tier 4)

Assessment Frequency: Triennial review or as needed
Due Diligence: Basic vendor information and compliance verification

Examples:

  • Office supplies and equipment (no system access)
  • Public website services (non-authenticated)
  • One-time consulting services (no data access)
  • Marketing services (no PII access)

Pre-Engagement Due Diligence

Before engaging any new vendor, a comprehensive due diligence process must be completed. The depth of assessment is proportional to the vendor's risk tier.

Phase 1: Initial Assessment (All Vendors)

Business Requirements

  • Detailed description of service/product requirements
  • Business justification and expected benefits
  • Budget allocation and cost-benefit analysis
  • Alternative vendor comparison

Risk Tier Classification

  • Data access requirements (type and sensitivity)
  • System access requirements (production, internal, none)
  • Criticality to business operations
  • Regulatory compliance implications
  • Geographic location and data residency

Vendor Information

  • Company registration and legal status verification
  • Reputation and service-history check
  • Business reputation and references
  • Previous security incidents or data breaches
  • Insurance coverage verification

Phase 2: Security Assessment (Tier 1 & 2)

Security Questionnaire

Comprehensive security questionnaire covering:

  • Information Security Program: Policies, governance, ISMS certification
  • Access Control: Authentication, authorization, privileged access management
  • Data Protection: Encryption, data handling, retention, disposal
  • Network Security: Firewall, IDS/IPS, segmentation, monitoring
  • Vulnerability Management: Scanning, patching, penetration testing
  • Incident Response: Detection, response procedures, notification
  • Business Continuity: Backup, disaster recovery, RTO/RPO
  • Compliance: UK GDPR and any published certifications (e.g. ISO 27001)
  • Physical Security: Data center security, access controls
  • HR Security: Background checks, training, termination procedures

Documentation Review

  • For Tier 1 providers we rely on their published security/compliance documentation and status pages, reviewed annually
  • Published certifications (e.g. ISO 27001) if available
  • Business continuity and disaster recovery plans
  • Security policies and procedures
  • Insurance certificates (cyber liability, E&O)

Technical Assessment (Tier 1 Only)

  • Architecture review and security design assessment
  • API security testing (if integration required)
  • Data flow mapping and encryption verification
  • Access control mechanism review

Phase 3: Risk Analysis & Approval

Risk Scoring

  • Quantitative risk score based on assessment findings
  • Gap analysis identifying security deficiencies
  • Risk mitigation plan for identified gaps
  • Compensating controls if vendor doesn't meet all requirements

Approval Workflow

  • All tiers: Vendors are approved by the company director

Risk Acceptance

  • Documented risk acceptance for vendors not meeting all requirements
  • Compensating controls implemented before engagement
  • Risk acceptance reviewed annually
  • Executive sign-off required for high-risk acceptances

Contractual Requirements

Mandatory Contract Clauses

All vendor contracts must include the following security and compliance provisions:

Data Protection & Privacy

  • Data Processing Agreement (DPA) compliant with GDPR Article 28
  • Where we cannot negotiate terms, we rely on the provider’s standard DPA and transfer safeguards; data may be processed outside the UK/EU
  • Prohibition on unauthorized data access, use, or disclosure
  • Data retention and secure deletion requirements
  • Subprocessor notification and approval rights
  • Data subject rights facilitation (access, deletion, portability)

Security Requirements

  • Minimum security controls (encryption, access control, monitoring)
  • Security incident notification (within 24 hours)
  • Review of the provider’s published security documentation (annual for Tier 1)
  • Vulnerability disclosure and patching timelines
  • Background checks for personnel with access
  • Security awareness training requirements

Compliance & Certifications

  • Maintenance of the certifications the provider publishes
  • Annual provision of updated compliance reports
  • Notification of certification changes or lapses
  • Regulatory compliance obligations (GDPR, financial regulations)

Business Continuity

  • Service Level Agreements (SLAs) with uptime guarantees
  • Business continuity and disaster recovery capabilities
  • Backup and restoration procedures
  • Notification requirements for service disruptions

Termination & Exit

  • Termination for cause (security breach, compliance failure)
  • Data return or destruction upon termination
  • Transition assistance and knowledge transfer
  • Post-termination confidentiality obligations

Liability & Insurance

  • Liability caps and indemnification for security breaches
  • Insurance as provided under the provider’s standard terms
  • Professional liability / Errors & Omissions coverage
  • Annual certificate of insurance provision

Service Level Agreements (SLAs)

Minimum SLA requirements by vendor tier:

Tier 1 (Critical)

  • Availability: 99.9% uptime
  • Response: 1 hour for critical issues
  • Resolution: 4 hours for critical issues
  • Support: 24/7/365

Tier 2 (High)

  • Availability: 99.5% uptime
  • Response: 4 hours for critical issues
  • Resolution: 24 hours for critical issues
  • Support: Business hours + on-call

Ongoing Monitoring & Reviews

Continuous Monitoring

  • Performance Monitoring: SLA compliance tracking, incident trends, service quality
  • Security Monitoring: Security incident notifications, vulnerability disclosures, breach news
  • Compliance Monitoring: Certification status, regulatory changes, audit findings
  • Business Monitoring: Ownership changes and service-history developments
  • Reputation Monitoring: News monitoring, social media, industry reports

Periodic Reassessments

Tier 1 (Annual Review)

  • Annual comprehensive security reassessment
  • For Tier 1 providers we rely on their published security/compliance documentation and status pages, reviewed annually

Tier 2 (Annual + Semi-Annual Check-ins)

  • Annual security questionnaire update
  • Review of updated compliance reports
  • Semi-annual business review meetings
  • Incident and change notification review

Tier 3 & 4 (Biennial/Triennial)

  • Periodic reassessment per defined schedule
  • Event-triggered reviews (security incidents, major changes)

Trigger Events for Additional Review

Immediate reassessment required for:

  • Security Incidents: Any security breach or incident affecting vendor
  • Material Changes: Ownership change, acquisition, major restructuring
  • Service Changes: Major system changes, new data access requirements
  • Compliance Changes: Loss of certification, regulatory violations
  • Geographic Changes: Data location changes, new jurisdictions
  • Financial Distress: Bankruptcy or publicly reported financial difficulties
  • Negative News: Significant negative publicity or reputation damage

Performance Scorecards

Scorecard metrics reviewed annually for each vendor:

  • Security Posture: Assessment scores, security incidents, vulnerability remediation
  • Compliance Status: Certification maintenance, audit findings, regulatory compliance
  • Service Performance: SLA compliance, incident response, service quality
  • Business Relationship: Communication quality, responsiveness, innovation
  • Overall Risk Score: Composite score determining vendor status (Green/Yellow/Red)

Supply Chain Security

Fourth-Party Risk Management

Vendors must manage their own supply chain security:

  • Subprocessor Disclosure: Complete list of all subprocessors with access to our data
  • Approval Rights: Prior approval required for new subprocessors
  • Flow-Down Requirements: Vendors must impose equivalent security requirements on subprocessors
  • Chain of Responsibility: Vendor remains liable for subprocessor security failures
  • Subprocessor Lists: Review of the provider’s published subprocessor list for critical vendors

Software Supply Chain

  • Software Composition Analysis: Scanning for vulnerable open-source dependencies
  • Code Signing: Verification of software authenticity and integrity
  • Update Validation: Testing vendor updates in non-production before deployment
  • Version Control: Approved software versions tracked and controlled
  • Patch Management: Vendor patch assessment and deployment process

Supply Chain Attack Prevention

  • Third parties are not given server access
  • Vendor integrations use scoped API keys, reviewed annually and revoked on offboarding

Vendor Security Incidents

Vendor Notification Requirements

Vendors must notify POPS.GG within specified timeframes:

  • Critical Incidents: Within 4 hours (security breach, data loss, system compromise)
  • High Severity: Within 24 hours (major outage, security vulnerability, compliance violation)
  • Medium Severity: Within 72 hours (minor incidents, service degradation)
  • Initial notification followed by detailed incident report within 7 days

POPS.GG Response Procedures

Immediate Actions (0-4 hours)

  • Activate incident response team
  • Assess impact to POPS.GG systems and data
  • Implement containment measures (access revocation if needed)
  • Notify affected stakeholders if customer data impacted

Investigation (4-24 hours)

  • Detailed impact assessment
  • Review vendor incident response actions
  • Determine if regulatory notification required
  • Coordinate with legal and compliance teams

Remediation & Review (1-7 days)

  • Verify vendor remediation actions
  • Conduct post-incident vendor review
  • Update vendor risk assessment
  • Consider alternative vendors if appropriate
  • Document lessons learned

Vendor Termination Criteria

Immediate termination consideration for:

  • Major security breach with customer data compromise
  • Failure to notify security incidents per contract
  • Loss of published certifications the provider relies on
  • Repeated SLA violations or service failures
  • Material misrepresentation of security capabilities
  • Failure to remediate critical security findings
  • Bankruptcy or financial insolvency

Vendor Offboarding

Structured offboarding process when vendor relationship ends:

Pre-Termination (30 days before)

  • Identify alternative vendor or in-house solution
  • Document data to be retrieved or deleted
  • Plan transition timeline and responsibilities
  • Notify vendor of upcoming termination per contract

Termination Actions (Day 1)

  • Revoke all vendor access to systems and data
  • Request data return in agreed format
  • Initiate data deletion procedures per contract
  • Retrieve company property (hardware, credentials)

Post-Termination (30 days after)

  • Verify complete data deletion (certificate of destruction)
  • Confirm no residual access or integrations
  • Archive vendor documentation per retention policy
  • Conduct lessons learned review
  • Update vendor inventory and risk register

Program Governance

Roles & Responsibilities

Company Director

Vendors are approved by the company director, who also handles program management, vendor assessments, contract review, technical integration and monitoring

Vendor Review

  • Reviewer: The company director
  • Frequency: Annual review of Tier 1 providers
  • Responsibilities: Review high-risk vendors, approve exceptions, policy updates

Metrics & Reporting

Metrics tracked and reviewed annually:

  • Total vendors by risk tier
  • Vendors pending assessment or overdue for reassessment
  • High and critical risk findings open/closed
  • Vendor security incidents
  • SLA compliance rates
  • Vendor risk score trends
  • New vendor onboarding time

Program Review & Improvement

  • Annual comprehensive program review
  • Policy updates for regulatory changes
  • Lessons learned from vendor incidents
  • Benchmarking against industry standards

Contact Information

Vendor Risk Management

Company Director

Contact: compliance@pops.gg

For New Vendor Assessments:

Contact: compliance@pops.gg

Company Information

CASH.BH LTD

Company Number: 14298863

71–75 Shelton Street, Covent Garden
London, WC2H 9JQ, United Kingdom

General: compliance@pops.gg