GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

VND-006 Vendor Monitoring and Performance Review

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Vendor performance, security posture, and compliance with contractual security obligations are reviewed at defined intervals (at least annually) and upon significant changes. Reviews include assessment of incident history, audit reports, certifications, and service delivery against SLAs. Findings are documented and escalated where material deficiencies are identified.

Rationale

Vendor risk is not static. A supplier that passed initial due diligence may deteriorate over time. Ongoing monitoring ensures the organisation detects changes before they become material risks.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredrole duty

VND-006 stays the review of the suppliers the organisation itself buys from. The inversion RTS 2024/1773 Art. 9(2), point (a) asks for, the provider producing periodic, incident, service delivery, ICT security and business continuity testing reports for the customer, is VND-014 since S8 wave B (EX-97 folded there).

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (24)

STA-12Supply Chain Agreement Reviewfull
STA-13Supply Chain Compliance Assessmentfull
STA-14Supply Chain Service Agreement Compliancepartial
STA-15Supply Chain Governance Reviewpartial
STA-12Supply Chain Agreement Reviewfull
STA-13Supply Chain Compliance Assessmentfull
STA-14Supply Chain Service Agreement Compliancepartial
STA-15Supply Chain Governance Reviewpartial
DORA-Art.28.6Exercise of access, inspection and audit rightsinformative
DORA-RTS-2024/1773-Art.9.1Monitoring measures and key indicators in the contractinformative
5.22Monitoring, review and change management of supplier servicesfull
NIS2-Art.21.2.dSupply Chain Securityinformative
NIS2-Art.21.3Supplier-Specific Risk Factors in Supply Chain Measuresinformative
NIS2-CIR-5.1Supply Chain Security Policyinformative
CA-2(3)Control Assessments | Leveraging Results from External Organizationspartial
SA-9External System Servicesinformative
SR-6Supplier Assessments and Reviewsfull
GV-6.1-003Third-Party AI Risk Policies | GV-6.1-003informative
GV-6.1-009Third-Party AI Risk Policies | GV-6.1-009informative
GV-6.2-002Third-Party Failure Contingency Processes | GV-6.2-002informative
GV-6.2-004Third-Party Failure Contingency Processes | GV-6.2-004informative
MP-5.2-002External Impact Feedback Practices | MP-5.2-002full
MANAGE 3.1Third-Party AI Risk Monitoring and Controlspartial
CC9.2Vendor and Business Partner Risk Managementinformative

Evidence (2)

recorddocumentmanual

Completed vendor review records documenting periodic reassessment of vendor security posture, compliance, and contractual adherence.

Example: Annual vendor review records (vendor management system / Jira) for top-tier vendors from the last 12 months, each showing: review date, reviewer, security posture re-assessment (updated SOC 2 / SIG questionnaire), SLA performance review, incident history check, and any escalated findings with resolution status

Test: Request vendor review records for 5 critical vendors over the last 12 months. Verify: (1) a formal review was conducted for each vendor within the last 12 months, (2) each review includes a security posture assessment (updated certificate or questionnaire response), (3) any identified deficiencies are tracked to resolution, (4) review was signed off by a named owner (procurement, security, or risk team).

reportdocumentmanual

Vendor risk register or monitoring report showing current risk ratings for all active vendors with trend information.

Example: Vendor Risk Register (SecurityScorecard / Vanta / spreadsheet), showing all active vendors with current risk tier, last assessment date, open findings, and score trend (improved / stable / deteriorated) over the last 12 months

Test: Request the vendor risk register. Verify: (1) all active vendors with access to organisational data are present, (2) each vendor has a current risk rating with a review date within 12 months, (3) any vendors rated High or Critical risk have documented remediation plans or exit justifications, (4) register is maintained by a named owner.

Questions (3)

boolean

Are vendor security posture and contractual performance reviewed at defined intervals of at least annually?

Reviews should include: updated security certifications or questionnaire responses, incident history check, SLA performance, and any open findings from the previous review. Material deficiencies should be escalated and tracked to resolution.

multi

What triggers a vendor security review outside of the regular annual cycle?

Vendor security incident or disclosed breachSignificant change to vendor service scope, ownership, or infrastructureCustomer complaint or audit finding relating to a vendorVendor certification lapses or is downgradedMaterial change to the volume or sensitivity of data processed by the vendorNone of the above

Event-triggered reviews are critical because vendor risk does not change on a fixed annual schedule. Vendor breaches and significant service changes should always trigger an unscheduled reassessment.

multi

Which of the following does each vendor review record?

The vendor's current certifications or questionnaire responsesIncident history since the last reviewService delivery against the agreed levelsThe status of findings raised at the previous reviewEscalation of any material deficiency, with the escalation recordedNone of the above

Options run from the most commonly recorded to the least. A review that reads the current certificate and nothing else repeats the pre-engagement assessment rather than testing the relationship since.