VNDR-1 Inventory and Classification

Estimated reading: 2 minutes 1712 views

What is VNDR-1 Inventory and Classification Control?

Inventory and classification control talks about good compliance hygiene and a compliance requirement to track all your vendors and third parties with whom you conduct business. A vendor is not limited to a software organization and can include business partners.

There are many ways to track this information; it can be done manually via spreadsheets or within a vendor management tool. Luckily, TrustCloud helps you automate this. For every system added to TrustOps, a vendor is added to the vendor registry. You need to ensure that the vendor listing in TrustCloud is complete and includes all your vendors and business partners.

Available tools in the marketplace

no tool recommendation for this section.

Available templates

TrustCloud has a curated list of templates, internally or externally sourced, to help you get started. Click on the link for a downloadable version.

  1. Vendor Registrar template to track all vendors

Control implementation

NOTE: This control is 100% automated by TrustCloud. Connect your systems to enjoy the benefits of automation.

For a manual implementation: 

At the very least, to meet compliance requirements, each organization must maintain a vendor listing or registrar, and the registrar should include information such as:

  1. Vendor description to describe the type of service provided
  2. Contact information is needed to have a method for contacting the vendor if and when an issue arises.
  3. Criticality rating based on the type of data being processed or accessed by the vendor
  4. Agreement date to capture the contract date and terms agreed upon
  5. Vendor status to capture the active or inactive status
  6. Monitoring status to ensure that active monitoring is placed on vendors with the highest criticality

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below-suggested action:

  1. Provide the most up-to-date vendor listing

Evidence example

For the suggested action, an example is provided below:

  1. Provide the most up-to-date vendor listing.
    The following screenshot shows an automated registrar in TrustCloud.
    Review the vendor page in TrustCloud to ensure that it is accurate and includes all vendors.
    VNDR 1 Inventory and Classification

Join the conversation