Services

Vendor Compliance Review

Review how selected vendors handle personal data, their responsibilities and the evidence supporting their arrangements.

Reviewed 18 September 2026 · Prahari DPO

When this work helps

Useful before engaging a provider, renewing an arrangement, changing access or addressing gaps in an existing supplier relationship.

Scope and practical outputs

Review an agreed vendor set, covering data access, processing instructions, relevant contract provisions, incident handovers, retention and exit arrangements.

  • Vendor review findings and an evidence-gap register.
  • A responsibility and contract-issues checklist.
  • Prioritised follow-up actions for onboarding, renewal or exit.

What your team contributes

Procurement, the business owner, security and legal contacts provide context and make approval decisions. Obtain supplier answers through an authorised channel.

An example to discuss

For payroll support, examine the input file, permitted recipients, support access, incident handover and what happens to copies when the arrangement ends.

Agree the boundaries

A questionnaire response is a supplier claim until appropriately checked. The scope should state whether document review, interviews or further assurance is included; it does not automatically include a supplier audit.

Common questions

Can we approve every supplier using one checklist?

Use a common starting point, then adjust questions to the actual access, service and information involved.

Does signing the contract finish the work?

Keep track of unresolved actions, changes and exit arrangements. The operational handover matters as much as the document.

Discuss the work you need

Agree the service, deliverables, responsibilities and fees before committing to an engagement.

Related reading

This page explains topics to scope and discuss. It does not establish applicability, certify compliance or confirm a paid engagement.

← Services