Vendor Risk Management
Comprehensive third-party security assessment and monitoring program ensuring supply chain integrity and vendor compliance
Last Updated: September 2026
Policy Overview
POPS.GG (operated by CASH.BH LTD) maintains a comprehensive Vendor Risk Management (VRM) program to identify, assess, and mitigate risks associated with third-party vendors, service providers, and suppliers. This program ensures that vendors meet our security, privacy, and compliance standards and do not introduce unacceptable risks to our operations or customers.
Program Objectives
- Risk Identification: Systematically identify and assess risks from third-party relationships
- Due Diligence: Conduct thorough security assessments before vendor engagement
- Continuous Monitoring: Ongoing oversight of vendor security posture and performance
- Supply Chain Security: Protect against supply chain attacks and vulnerabilities
- Compliance Assurance: Ensure vendors meet regulatory and contractual obligations
- Incident Preparedness: Establish clear procedures for vendor-related security incidents
Scope & Applicability
This policy applies to all third-party relationships including:
- Service Providers: Cloud infrastructure, SaaS applications, professional services
- Technology Vendors: Software, hardware, security tools, development platforms
- Data Processors: Vendors processing customer or employee personal data
- Business Partners: Payment processors, advertising networks, integration partners
- Professional Services: Consultants, auditors, legal counsel with system access
- Suppliers: Physical goods suppliers with network connectivity or data access
Exclusions
This policy does not apply to: customers, end-users, employees (covered by HR policies), or vendors with no access to systems, data, or facilities.
Vendor Risk Classification
All vendors are classified by risk tier based on the nature and sensitivity of their access, data handling, and potential business impact. Risk tier determines the level of due diligence, assessment frequency, and contractual requirements.
Critical Risk (Tier 1)
Assessment Frequency: Annual review of published documentation and status pages
Due Diligence: For Tier 1 providers we rely on their published security/compliance documentation and status pages, reviewed annually
Examples:
- Cloud infrastructure providers (hosting production systems)
- Payment processors and financial service providers
- Database hosting services with customer data
- Identity and access management providers
- Vendors with production network access
- Data backup and disaster recovery providers
High Risk (Tier 2)
Assessment Frequency: Annual review + semi-annual monitoring
Due Diligence: Security questionnaire, documentation review, third-party certifications
Examples:
- SaaS applications processing personal data
- Email and communication service providers
- Security tool vendors (SIEM, EDR, vulnerability scanners)
- Development and staging environment providers
- Analytics and monitoring platforms
- Marketing automation with customer data access
Medium Risk (Tier 3)
Assessment Frequency: Biennial review
Due Diligence: Standard security questionnaire, basic documentation
Examples:
- Productivity and collaboration tools (limited data access)
- Non-sensitive SaaS applications
- Professional services with supervised access
- Training and development platforms
- Project management tools
Low Risk (Tier 4)
Assessment Frequency: Triennial review or as needed
Due Diligence: Basic vendor information and compliance verification
Examples:
- Office supplies and equipment (no system access)
- Public website services (non-authenticated)
- One-time consulting services (no data access)
- Marketing services (no PII access)
Pre-Engagement Due Diligence
Before engaging any new vendor, a comprehensive due diligence process must be completed. The depth of assessment is proportional to the vendor's risk tier.
Phase 1: Initial Assessment (All Vendors)
Business Requirements
- Detailed description of service/product requirements
- Business justification and expected benefits
- Budget allocation and cost-benefit analysis
- Alternative vendor comparison
Risk Tier Classification
- Data access requirements (type and sensitivity)
- System access requirements (production, internal, none)
- Criticality to business operations
- Regulatory compliance implications
- Geographic location and data residency
Vendor Information
- Company registration and legal status verification
- Reputation and service-history check
- Business reputation and references
- Previous security incidents or data breaches
- Insurance coverage verification
Phase 2: Security Assessment (Tier 1 & 2)
Security Questionnaire
Comprehensive security questionnaire covering:
- Information Security Program: Policies, governance, ISMS certification
- Access Control: Authentication, authorization, privileged access management
- Data Protection: Encryption, data handling, retention, disposal
- Network Security: Firewall, IDS/IPS, segmentation, monitoring
- Vulnerability Management: Scanning, patching, penetration testing
- Incident Response: Detection, response procedures, notification
- Business Continuity: Backup, disaster recovery, RTO/RPO
- Compliance: UK GDPR and any published certifications (e.g. ISO 27001)
- Physical Security: Data center security, access controls
- HR Security: Background checks, training, termination procedures
Documentation Review
- For Tier 1 providers we rely on their published security/compliance documentation and status pages, reviewed annually
- Published certifications (e.g. ISO 27001) if available
- Business continuity and disaster recovery plans
- Security policies and procedures
- Insurance certificates (cyber liability, E&O)
Technical Assessment (Tier 1 Only)
- Architecture review and security design assessment
- API security testing (if integration required)
- Data flow mapping and encryption verification
- Access control mechanism review
Phase 3: Risk Analysis & Approval
Risk Scoring
- Quantitative risk score based on assessment findings
- Gap analysis identifying security deficiencies
- Risk mitigation plan for identified gaps
- Compensating controls if vendor doesn't meet all requirements
Approval Workflow
- All tiers: Vendors are approved by the company director
Risk Acceptance
- Documented risk acceptance for vendors not meeting all requirements
- Compensating controls implemented before engagement
- Risk acceptance reviewed annually
- Executive sign-off required for high-risk acceptances
Contractual Requirements
Mandatory Contract Clauses
All vendor contracts must include the following security and compliance provisions:
Data Protection & Privacy
- Data Processing Agreement (DPA) compliant with GDPR Article 28
- Where we cannot negotiate terms, we rely on the provider’s standard DPA and transfer safeguards; data may be processed outside the UK/EU
- Prohibition on unauthorized data access, use, or disclosure
- Data retention and secure deletion requirements
- Subprocessor notification and approval rights
- Data subject rights facilitation (access, deletion, portability)
Security Requirements
- Minimum security controls (encryption, access control, monitoring)
- Security incident notification (within 24 hours)
- Review of the provider’s published security documentation (annual for Tier 1)
- Vulnerability disclosure and patching timelines
- Background checks for personnel with access
- Security awareness training requirements
Compliance & Certifications
- Maintenance of the certifications the provider publishes
- Annual provision of updated compliance reports
- Notification of certification changes or lapses
- Regulatory compliance obligations (GDPR, financial regulations)
Business Continuity
- Service Level Agreements (SLAs) with uptime guarantees
- Business continuity and disaster recovery capabilities
- Backup and restoration procedures
- Notification requirements for service disruptions
Termination & Exit
- Termination for cause (security breach, compliance failure)
- Data return or destruction upon termination
- Transition assistance and knowledge transfer
- Post-termination confidentiality obligations
Liability & Insurance
- Liability caps and indemnification for security breaches
- Insurance as provided under the provider’s standard terms
- Professional liability / Errors & Omissions coverage
- Annual certificate of insurance provision
Service Level Agreements (SLAs)
Minimum SLA requirements by vendor tier:
Tier 1 (Critical)
- Availability: 99.9% uptime
- Response: 1 hour for critical issues
- Resolution: 4 hours for critical issues
- Support: 24/7/365
Tier 2 (High)
- Availability: 99.5% uptime
- Response: 4 hours for critical issues
- Resolution: 24 hours for critical issues
- Support: Business hours + on-call
Ongoing Monitoring & Reviews
Continuous Monitoring
- Performance Monitoring: SLA compliance tracking, incident trends, service quality
- Security Monitoring: Security incident notifications, vulnerability disclosures, breach news
- Compliance Monitoring: Certification status, regulatory changes, audit findings
- Business Monitoring: Ownership changes and service-history developments
- Reputation Monitoring: News monitoring, social media, industry reports
Periodic Reassessments
Tier 1 (Annual Review)
- Annual comprehensive security reassessment
- For Tier 1 providers we rely on their published security/compliance documentation and status pages, reviewed annually
Tier 2 (Annual + Semi-Annual Check-ins)
- Annual security questionnaire update
- Review of updated compliance reports
- Semi-annual business review meetings
- Incident and change notification review
Tier 3 & 4 (Biennial/Triennial)
- Periodic reassessment per defined schedule
- Event-triggered reviews (security incidents, major changes)
Trigger Events for Additional Review
Immediate reassessment required for:
- Security Incidents: Any security breach or incident affecting vendor
- Material Changes: Ownership change, acquisition, major restructuring
- Service Changes: Major system changes, new data access requirements
- Compliance Changes: Loss of certification, regulatory violations
- Geographic Changes: Data location changes, new jurisdictions
- Financial Distress: Bankruptcy or publicly reported financial difficulties
- Negative News: Significant negative publicity or reputation damage
Performance Scorecards
Scorecard metrics reviewed annually for each vendor:
- Security Posture: Assessment scores, security incidents, vulnerability remediation
- Compliance Status: Certification maintenance, audit findings, regulatory compliance
- Service Performance: SLA compliance, incident response, service quality
- Business Relationship: Communication quality, responsiveness, innovation
- Overall Risk Score: Composite score determining vendor status (Green/Yellow/Red)
Supply Chain Security
Fourth-Party Risk Management
Vendors must manage their own supply chain security:
- Subprocessor Disclosure: Complete list of all subprocessors with access to our data
- Approval Rights: Prior approval required for new subprocessors
- Flow-Down Requirements: Vendors must impose equivalent security requirements on subprocessors
- Chain of Responsibility: Vendor remains liable for subprocessor security failures
- Subprocessor Lists: Review of the provider’s published subprocessor list for critical vendors
Software Supply Chain
- Software Composition Analysis: Scanning for vulnerable open-source dependencies
- Code Signing: Verification of software authenticity and integrity
- Update Validation: Testing vendor updates in non-production before deployment
- Version Control: Approved software versions tracked and controlled
- Patch Management: Vendor patch assessment and deployment process
Supply Chain Attack Prevention
- Third parties are not given server access
- Vendor integrations use scoped API keys, reviewed annually and revoked on offboarding
Vendor Security Incidents
Vendor Notification Requirements
Vendors must notify POPS.GG within specified timeframes:
- Critical Incidents: Within 4 hours (security breach, data loss, system compromise)
- High Severity: Within 24 hours (major outage, security vulnerability, compliance violation)
- Medium Severity: Within 72 hours (minor incidents, service degradation)
- Initial notification followed by detailed incident report within 7 days
POPS.GG Response Procedures
Immediate Actions (0-4 hours)
- Activate incident response team
- Assess impact to POPS.GG systems and data
- Implement containment measures (access revocation if needed)
- Notify affected stakeholders if customer data impacted
Investigation (4-24 hours)
- Detailed impact assessment
- Review vendor incident response actions
- Determine if regulatory notification required
- Coordinate with legal and compliance teams
Remediation & Review (1-7 days)
- Verify vendor remediation actions
- Conduct post-incident vendor review
- Update vendor risk assessment
- Consider alternative vendors if appropriate
- Document lessons learned
Vendor Termination Criteria
Immediate termination consideration for:
- Major security breach with customer data compromise
- Failure to notify security incidents per contract
- Loss of published certifications the provider relies on
- Repeated SLA violations or service failures
- Material misrepresentation of security capabilities
- Failure to remediate critical security findings
- Bankruptcy or financial insolvency
Vendor Offboarding
Structured offboarding process when vendor relationship ends:
Pre-Termination (30 days before)
- Identify alternative vendor or in-house solution
- Document data to be retrieved or deleted
- Plan transition timeline and responsibilities
- Notify vendor of upcoming termination per contract
Termination Actions (Day 1)
- Revoke all vendor access to systems and data
- Request data return in agreed format
- Initiate data deletion procedures per contract
- Retrieve company property (hardware, credentials)
Post-Termination (30 days after)
- Verify complete data deletion (certificate of destruction)
- Confirm no residual access or integrations
- Archive vendor documentation per retention policy
- Conduct lessons learned review
- Update vendor inventory and risk register
Program Governance
Roles & Responsibilities
Company Director
Vendors are approved by the company director, who also handles program management, vendor assessments, contract review, technical integration and monitoring
Vendor Review
- Reviewer: The company director
- Frequency: Annual review of Tier 1 providers
- Responsibilities: Review high-risk vendors, approve exceptions, policy updates
Metrics & Reporting
Metrics tracked and reviewed annually:
- Total vendors by risk tier
- Vendors pending assessment or overdue for reassessment
- High and critical risk findings open/closed
- Vendor security incidents
- SLA compliance rates
- Vendor risk score trends
- New vendor onboarding time
Program Review & Improvement
- Annual comprehensive program review
- Policy updates for regulatory changes
- Lessons learned from vendor incidents
- Benchmarking against industry standards
Contact Information
Vendor Risk Management
Company Director
Contact: compliance@pops.gg
For New Vendor Assessments:
Contact: compliance@pops.gg
Company Information
CASH.BH LTD
Company Number: 14298863
71–75 Shelton Street, Covent Garden
London, WC2H 9JQ, United Kingdom
General: compliance@pops.gg