Third-Party and SaaS Vendor Risk Program Setup
Third-Party and SaaS Vendor Risk Program Setup is a fixed-price, three-week engagement in which IT Partner builds a vendor risk management program your own team can run — sized for an organization of roughly 50 to 2,000 seats, not for a bank's GRC department. It starts with the inventory nobody has: every SaaS application and service provider your organization actually uses, merged from Microsoft Defender for Cloud Apps or Cloud App Discovery traffic, the enterprise applications and consent grants in Microsoft Entra ID, and twelve months of accounts-payable records. Each vendor is tiered by the data it holds, how critical it is and how deeply it is integrated; each tier gets a matching questionnaire, with HIPAA and CMMC variants where you need them; and a written evidence-review procedure tells your team how to read a SOC 2 report, an ISO 27001 certificate, a PCI Attestation of Compliance, a Business Associate Agreement or a Data Processing Addendum instead of filing it unread. A contract-clause checklist, renewal checkpoints and a risk-acceptance and exception log complete the program, and all of it lives in a vendor risk register we build as a SharePoint list in your tenant — or in Purview Compliance Manager custom assessments or the GRC tool you already own. During the engagement we assess your first wave of up to 10 tier-1 vendors alongside your team, so the procedure is learned by doing. $4,950 fixed; additional vendors are quoted at our published hourly rate. The result is the service-provider oversight evidence the FTC Safeguards Rule (16 CFR 314.4(f)), NYDFS Part 500 (§500.11), the HIPAA business-associate rules, PCI DSS Requirement 12.8, SOC 2 (CC9.2), CMMC and cyber-insurance questionnaires all ask for. We are Microsoft 365 engineers, not a law firm, a CPA firm or a certification body: we build the program and the evidence; we do not certify a vendor as secure, and neither should anyone else.
What this engagement is
Every framework a mid-market organization now answers to has a vendor-oversight clause, and they say nearly the same thing. The FTC Safeguards Rule requires a financial institution — which under the Gramm-Leach-Bliley definition includes auto dealers, mortgage brokers, tax preparers and many businesses that never thought of themselves that way — to select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess each provider based on the risk it presents (16 CFR 314.4(f)). NYDFS Part 500 requires written third-party service provider policies covering identification and risk assessment, minimum cybersecurity practices, due diligence and periodic reassessment (23 NYCRR 500.11). HIPAA requires a business associate agreement with every vendor that handles protected health information on your behalf. PCI DSS v4.0.1 Requirement 12.8 wants a list of every third-party service provider that touches account data, a written agreement with each, and a program that monitors their PCI DSS compliance status at least once every twelve months. SOC 2's CC9.2 asks how you assess and manage risks from vendors and business partners. The CMMC program rule treats external service providers that process controlled unclassified information as part of your assessment scope. And the cyber-insurance application asks, in one line, whether you have a vendor risk management program — a question that gets harder to answer with 'no' every year. The problem is rarely the policy; it is the list. In a 200-seat organization the finance system knows about forty vendors, IT knows about sixty, and the tenant's traffic shows a few hundred SaaS applications — many signed up for with a corporate email address and a credit card, often several holding customer data, and sometimes one with an OAuth consent grant that reads every user's mailbox. So the program starts with an inventory built from three sources that disagree with each other on purpose. Cloud-application traffic from Microsoft Defender for Cloud Apps or, on Entra ID P1 licensing, the Cloud App Discovery subset — Microsoft's catalog rates the risk of tens of thousands of cloud apps and shows who in your organization uses which. The enterprise applications registered in Microsoft Entra ID together with the user and admin consent grants behind them, which is where the integrations that can actually read your data are visible even when nobody remembers approving them. And twelve months of accounts-payable and expense records, which is where the vendors that never touch the tenant — the payroll bureau, the shredding company, the offsite backup — show up. Merged and de-duplicated, with a business owner attached to each entry, that becomes the vendor inventory. Most organizations are surprised by it. That surprise is the point. Then we make it manageable, because assessing three hundred vendors identically is how programs die in month two. A tiering model scores each vendor on the sensitivity of the data it holds — regulated data such as PHI, cardholder data, nonpublic personal information or CUI at the top — on how critical the service is to your operations, and on how deeply it is integrated with your identity and data. Tier 1 vendors get the full questionnaire and an evidence review; tier 2 a standard questionnaire; tier 3 a short self-attestation or none at all, with the reasoning written down. The questionnaires are ours, written to cover the domains the industry-standard questionnaires cover — governance, access control, encryption, vulnerability management, incident response, business continuity, subprocessors, data return and deletion, and a section on AI features — so you own them outright, with HIPAA and CMMC variants that add the business-associate and CUI-handling questions those frameworks need. Because well-run vendors answer with a SOC 2 report instead of a questionnaire, the evidence-review procedure tells your team exactly what to read: report type and period, the auditor's opinion, exceptions, the complementary user-entity controls you are expected to implement, carved-out subservice organizations; an ISO 27001 certificate's scope and expiry; a PCI Attestation of Compliance; a Business Associate Agreement; a Data Processing Addendum; and, for Microsoft itself, the audit reports and Data Protection Addendum Microsoft publishes on its Service Trust Portal. A contract-clause checklist — security obligations, breach-notification timing, subprocessor notice, audit rights, data return and deletion, insurance, and the BAA or DPA where required — gives procurement something to check before signature, and renewal checkpoints, a risk-acceptance and exception log and a RACI turn the program into a cycle rather than a project. All of it lives in a vendor risk register your organization owns. By default that is a SharePoint list, built with Microsoft Lists in your tenant: one row per vendor with owner, tier, data types, integration, evidence on file, contract dates, questionnaire status, findings, risk rating, decision and next review date, with views for the compliance officer, for procurement and for the auditor, and reminders for reviews and renewals. If you hold the Purview licensing for it, the same structure can be built as a custom assessment in Microsoft Purview Compliance Manager, a feature in preview at the time of writing; if you already run a GRC platform, we build the register there instead and do not sell you another one. We then assess your first wave of up to 10 tier-1 vendors with your team, so that by handover someone in your organization has sent a questionnaire, read a SOC 2 report, recorded a finding and made a risk decision with an engineer beside them. What we do not do is decide the law or certify a vendor. IT Partner is not a law firm, a CPA firm, a QSA, a C3PAO or a certification body: counsel decides whether a framework applies to you and what a contract must say, the auditor or examiner reaches their own conclusion, and no vendor is ever 'secure' — only assessed, on a date, against a standard you chose. We do sit on the vendor side of this process ourselves: we answer customer and carrier questionnaires every year, and the Microsoft 365 App Certification attestation for our own Teams app is published on Microsoft's site, so we know what a good answer looks like and what a weak one hides. Once the program exists, the Virtual CISO can own it and the Compliance Evidence and Audit Readiness Retainer can keep its evidence current; both are optional, and the register, the templates and the procedures are yours whoever runs them.
Success criteria
What you receive
How the work unfolds
We agree in writing which frameworks the program must evidence, which entities and tenants are in scope, the first-wave vendor count, the data-classification levels the tiering model will use (yours, or a simple three-level scheme we supply), and the access we need: read access to Defender for Cloud Apps or Cloud App Discovery and to Entra ID enterprise applications, plus an accounts-payable export. Access is least-privilege and time-bound under a GDAP relationship you approve.
Cloud-application traffic is collected from Defender for Cloud Apps — through its Defender for Endpoint integration where licensed, or from firewall and proxy logs — or from the Cloud App Discovery subset on Entra ID P1; the enterprise applications and consent grants in Entra ID are exported; the accounts-payable and expense records are matched against both. The three lists are merged, de-duplicated and attributed to business owners, and the deltas — the applications finance pays for that IT has never seen, and the ones IT sees that nobody pays for — are chased with your team.
The tiering model is drafted against your data classification and the frameworks in scope, then applied in a working session with compliance, IT and the business owners: every vendor gets a tier and a one-line reason. Tier 1 becomes the candidate list for the first wave, and you choose which vendors go first.
The tiered questionnaire set, the evidence-review procedure, the contract-clause checklist and the risk-acceptance and exception workflow are written for your organization and reviewed with you. The register is built — SharePoint list by default, Compliance Manager custom assessment or your GRC tool by agreement — and loaded with the inventory and the tiers.
Up to 10 tier-1 vendors go through the cycle with your team doing the work alongside us: questionnaires issued from your tenant, evidence requested and reviewed to the procedure, findings written, risk ratings assigned, decisions made by the risk owner and recorded. Vendors that do not respond inside the window are recorded as open with a follow-up date, not quietly dropped.
The procedure document, RACI, renewal checkpoints and framework-mapping pack are finalized from what the first wave taught us. The handover session walks the people who will run the program through the register, the questionnaires and the procedure; the recording and every working file are yours.
Prerequisites
Who does what
IT Partner
- Collect and merge the three inventory sources, de-duplicate, attribute owners with your help, and document the deltas.
- Design the tiering model, run the tiering session, and record every tier with its rationale.
- Write the tiered questionnaires, the evidence-review procedure, the contract-clause checklist and the risk-acceptance workflow for your organization, not from a generic pack.
- Build and load the register in your tenant or GRC tool, with views and reminders working before handover.
- Assess up to 10 tier-1 vendors with your team in the first wave, reading the evidence to the procedure and writing findings you can defend to an auditor.
- Produce the procedure document, RACI, renewal checkpoints and the framework-mapping pack, naming plainly what still needs counsel or the auditor.
- Deliver the handover session, remove our access cleanly at the end, and treat everything discovered as confidential.
Your team
- Name the program owner, the vendor business owners and the procurement or legal contact, and make them available for the working sessions.
- Provide the accounts-payable export, existing contracts, BAAs and DPAs, your data classification and the frameworks in scope.
- Approve the GDAP relationship and supply the discovery traffic source.
- Choose the first-wave vendors from the tier-1 list and chase vendor contacts who do not respond.
- Make and sign the risk decisions — accept, remediate, exception, replace — and own them; we recommend and record.
- Adopt the procedures into your written policy with counsel's review, and run the reassessment cycle after handover — alone, or with the retainer or the vCISO.
What's not included
Limitations & technical notes
Frequently asked questions
What is a vendor risk management program, and why are we suddenly being asked for one?
A vendor risk management program — third-party risk management, or TPRM, in larger-company vocabulary — is the documented, repeatable way an organization decides which service providers may hold its data or connect to its systems, checks that they protect it, and rechecks them over time. You are being asked for one because the frameworks converged: the FTC Safeguards Rule, NYDFS Part 500, HIPAA, PCI DSS, SOC 2 and CMMC all contain a service-provider oversight requirement, and cyber-insurance carriers now ask about it on the application. An auditor or examiner who once accepted 'we have contracts' now expects a list, a tiering rationale, evidence on file and a reassessment date. This engagement builds exactly that, sized so a compliance officer with a day job can keep it running.
Which regulations actually require vendor oversight, and what do they say?
In short: the FTC Safeguards Rule (16 CFR 314.4(f)) requires you to select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them based on the risk they present. NYDFS Part 500 (§500.11) requires written third-party service provider policies covering identification and risk assessment, minimum cybersecurity practices, due diligence and periodic reassessment, with due-diligence guidance that reaches access controls, encryption and breach notice. HIPAA requires a business associate agreement with any vendor that creates, receives, maintains or transmits PHI for you. PCI DSS v4.0.1 Requirement 12.8 requires a list of the third-party service providers that touch account data, written agreements, due diligence before engagement, a program that monitors each provider's PCI DSS compliance status at least once every twelve months, and a record of which requirements each party manages. SOC 2's CC9.2 asks how you assess and manage vendor and business-partner risk. The CMMC program rule brings external service providers that handle CUI or security protection data into your assessment scope, with cloud providers that store CUI expected to meet FedRAMP Moderate or an equivalent. Those are our readings at the time of writing; counsel decides what applies to you, and the framework-mapping pack says which artifact answers which clause.
How do you find the vendors we do not know about?
From three sources that never agree. First, cloud-application traffic: Microsoft Defender for Cloud Apps — fed by Defender for Endpoint on your managed devices where licensed, or by firewall and proxy logs — or the Cloud App Discovery subset included with Entra ID P1, matched against Microsoft's catalog of cloud apps with risk scores, showing which apps are used, by whom and how much. Second, Microsoft Entra ID: the enterprise applications registered in your tenant and the user and admin consent grants behind them, which is where an integration that can read mail or files is visible even when nobody remembers approving it. Third, twelve months of accounts-payable and expense records, which catch the vendors that never touch the tenant at all. We merge the three, remove duplicates, attach an owner to each entry and hand you the deltas. The list is always longer than anyone expected, and it is the single most useful artifact of the engagement.
Do we need Defender for Cloud Apps or Microsoft 365 E5 for this?
No. The inventory works on Microsoft 365 Business Premium or E3, because Cloud App Discovery — the discovery subset of Defender for Cloud Apps — is included with Microsoft Entra ID P1 and accepts firewall and proxy log uploads for ongoing reporting against Microsoft's cloud-app catalog. The full Defender for Cloud Apps license, in Microsoft 365 E5, the Defender Suite or as a standalone add-on, adds the native Defender for Endpoint feed, which removes the need for log exports, plus OAuth app governance and the controls that turn discovery into policy. We verify what your tenant surfaces at kickoff and tell you plainly what a license would add; if you want the fuller product deployed properly, that is the separate Defender for Cloud Apps implementation. Any Microsoft license is billed by Microsoft or your CSP at Microsoft's published price; it is never part of this fee.
How does the tiering work, and who decides?
The model scores three things: the sensitivity of the data the vendor holds or can reach, with regulated data — PHI, cardholder data, nonpublic personal information, CUI — at the top; how critical the service is to operations, measured by what stops if it fails; and how deeply it is integrated with your identity and data, from single sign-on and API or OAuth access down to a vendor that only ever receives a purchase order. The scores set the tier, the tier sets the questionnaire depth and the reassessment frequency, and the reasoning is written next to every assignment so an auditor can follow it. You decide the thresholds and the tiers in a working session with us; the model is a proposal until you approve it, and it is written so you can re-tier a vendor yourself when its role changes.
Do you use the SIG questionnaire or the CAIQ?
We write your questionnaire set to cover the same domains those questionnaires cover, so you own it outright and can issue it from your own tenant. The Standard Information Gathering questionnaire (SIG) from Shared Assessments is a licensed product — an organization sending it needs a Shared Assessments license, although a vendor answering one does not — and the Cloud Security Alliance's CAIQ is free but written for cloud providers to self-assess against the Cloud Controls Matrix. If you already hold a SIG license, or a customer or regulator expects SIG Lite specifically, we build the program around it. Either way, a vendor that answers with a completed SIG or CAIQ instead of your questionnaire is a good sign, and the evidence-review procedure tells your team how to accept one.
What happens when a vendor sends a SOC 2 report instead of answering questions?
That is the outcome you want, and the procedure is built for it. Your team checks the report type — a Type I describes controls at a point in time, a Type II tests them over a period — and the period covered, reads the auditor's opinion, lists every exception and what the vendor said about it, extracts the complementary user-entity controls the report expects you to implement (they are your obligations, and they surface in the register), notes the subservice organizations carved out of the report, and confirms the report's scope actually covers the service you buy. The same checklist approach applies to an ISO/IEC 27001 certificate (scope statement, certification body, expiry), a PCI Attestation of Compliance (which services, which date, which assessor), a HIPAA Business Associate Agreement and a Data Processing Addendum. A report is filed as evidence with its review date and its gaps, never as a substitute for thinking.
Where does the register live, and why not just a spreadsheet?
By default in your own tenant, as a SharePoint list built with Microsoft Lists: one row per vendor, columns for owner, tier, data types, integration, evidence on file, contract and renewal dates, questionnaire status, findings, risk rating, decision and next review date, with views for the compliance officer, procurement and the auditor, version history on every change and reminders for reviews and renewals. A spreadsheet has no owner, no history and no reminders, which is how last year's program becomes this year's audit finding. If you hold the Purview licensing, the same structure can be a custom assessment in Microsoft Purview Compliance Manager — in preview at the time of writing — with its improvement actions and evidence uploads; if you already run a GRC platform, we build the register there and do not sell you another one. In every case the register is yours, in a system you own, whoever runs the program later.
How many vendors are assessed during the engagement?
Up to 10 tier-1 vendors in the first wave — the number is set so that your team can genuinely do the work alongside us rather than watch. Every vendor in the inventory is tiered; the first wave is where the questionnaire, the evidence review and the risk decision are exercised end to end on your real vendors. After handover, further vendors are assessed by your team using the procedure, or by us in batches quoted at our published hourly rate or as a fixed batch price agreed in writing before we start.
Is Microsoft itself a vendor in this program?
Yes, and usually the largest one. Microsoft is tiered like any other provider — for most customers it is tier 1 by data sensitivity alone — and the evidence-review procedure shows your team where Microsoft publishes its evidence: the SOC and ISO audit reports on the Service Trust Portal, and the Data Protection Addendum and Product Terms that carry the HIPAA business associate terms for in-scope services. The register records that evidence with its dates like any other vendor's. What the program does not do is assess how your own tenant is configured; that is the readiness assessment for your framework, and the two are designed to sit side by side in the auditor's binder.
Will this make us compliant with the FTC Safeguards Rule, NYDFS Part 500 or PCI DSS?
No single engagement makes an organization compliant with anything, and we will not tell you otherwise to close a sale. Each of those frameworks has many elements; this program builds and evidences the service-provider oversight element — the inventory, the risk-based assessment, the contractual-safeguards checklist and the periodic reassessment — and the framework-mapping pack shows an examiner or auditor exactly where each artifact answers each clause. Your own controls, your written information security program, your incident response plan and the legal determinations are separate work, some of it ours and some of it counsel's. The conclusion about compliance belongs to the regulator, the auditor, the QSA or the carrier; the evidence is what we make complete and honest.
We are an auto dealer and the manufacturer requires us to use certain vendors. Are those in scope?
Yes. The FTC's June 2025 Safeguards Rule FAQs for auto dealers addressed this directly: a vendor does not stop being a service provider because a manufacturer mandated it, so a manufacturer-required DMS, CRM or digital-retailing platform that handles customer information still needs the contractual safeguards and the periodic assessment the rule requires — while the manufacturer itself is generally not your service provider merely because it receives customer data from you, unless it provides you a financial service. That is our reading of the FTC's guidance at the time of writing, and your counsel's reading governs. In practice, mandated vendors are tiered and assessed like any other, and where a vendor will not engage with a questionnaire the register records the evidence you could obtain — often a SOC 2 report or a security overview the vendor publishes — and the risk decision you made on it.
Who runs the program after you leave?
Your organization, by design. The procedure document and RACI name who onboards a new vendor, who issues the questionnaire, who reviews evidence, who signs risk acceptances and who runs the reassessment calendar; the register's reminders do the nagging. The first wave exists so that the people named in the RACI have done each step once with an engineer beside them. If you would rather not staff it, the Compliance Evidence and Audit Readiness Retainer can keep the evidence refreshed and the reassessments on schedule for a flat monthly fee, and the Virtual CISO can own the program's decisions; both are optional, month to month, and everything stays in your tenant if you stop.
How is this different from the Shadow IT Assessment Workshop or the Defender for Cloud Apps implementation?
They answer different questions. The Shadow IT Assessment Workshop and its remote edition use Defender for Cloud Apps to discover unmanaged cloud use and give IT a visibility-and-control roadmap — a discovery engagement for the IT team. The Defender for Cloud Apps implementation configures the product itself: app policies, session controls, Conditional Access App Control, DLP across SaaS. This engagement builds the governance program that a compliance officer, procurement and the business run: tiering, questionnaires, evidence review, contracts, risk decisions and a register an auditor can read. It uses discovery as an input; it does not replace either of those, and a workshop's findings drop straight into its inventory.
What about AI tools — Copilot-style assistants and the AI features our vendors keep adding?
They go in the same inventory and the same tiers, with a few extra questions. An AI vendor, or an existing vendor that has added an AI feature, is assessed on what data it receives, whether your data is used to train models shared with other customers, where processing happens, how prompts and outputs are retained, and whether the feature can be switched off contractually — questions the tier-1 questionnaire carries in its AI section. Discovery from Defender for Cloud Apps sees the generative-AI apps your users reach, which is why they appear in the inventory whether or not anyone signed a contract. We wrote about the Microsoft-side controls in Shadow AI is already in your Microsoft 365 tenant — control it with Purview; the vendor-side governance is this program.
Why is the price fixed at $4,950, and what if we are bigger than the scope?
Because the scope is fixed: one organization, one Microsoft 365 tenant, the three-source inventory, the tiering model, the questionnaire set, the procedures, the register and a first wave of up to 10 tier-1 vendors, in three weeks. The price is quoted in writing before work begins and you pay after you approve delivery. If you have several legal entities or tenants, a larger first wave or a GRC platform that needs configuration work, we say so on the scoping call and quote the difference before anything starts — not after. And there is no lock-in in either direction: the register, the templates and the procedures are yours whether or not you ever engage us again.