Vendor Assessment Policy

Last update: 7 September 2026

----------

## 1. Overview

Integrated Retail Pte Ltd does not deliver its solutions alone. Software and hardware vendors supply the products we resell and support. Cloud and hosting providers run the platforms. Service partners perform installation and support work in each market. Business systems hold our own commercial and customer data.

Our customers hold us accountable for the service, regardless of which of those parties is involved. A weakness in any of them becomes our problem and our customers' problem. This policy sets out how the Company assesses those third parties before engaging them, and how it keeps that assessment current.

## 2. Purpose

To ensure that every third party the Company depends on:

-   is assessed for security, data protection and reliability proportionate to the risk it carries;
    
-   is bound by written obligations covering confidentiality, data protection and incident notification;
    
-   is recorded, so the Company can tell a customer at any time who is involved in delivering their service;
    
-   is monitored, not assessed once and forgotten.
    

## 3. Scope

This policy applies to any third party that supplies a product or service on which the Company or its customers depend, including:

-   **product vendors** — the software and hardware providers whose products we resell, implement and support;
    
-   **cloud and hosting providers** — infrastructure running Company-hosted or Company-developed solutions;
    
-   **subprocessors** — any third party that processes personal data on our behalf;
    
-   **in-country service partners** — appointed contractors performing installation, maintenance or support;
    
-   **business system providers** — ticketing, CRM, finance, email, file storage and similar;
    
-   **professional advisers** where they receive Confidential or Restricted information.
    

Outside the scope of this policy: suppliers with no access to Company or customer data, systems or premises — office consumables, utilities, general facilities.

Accountability for this policy sits with IT Management, supported by the Data Protection Officer where personal data is involved.

  

## 4. Two Different Kinds of Vendor

The Company assesses vendors for two quite different reasons, and it is worth being explicit about which applies, because the assessment has different consequences.

  
| |Product vendors|Service providers and subprocessors
|--|--|--|
|Examples|The software and hardware platforms in our portfolio|Cloud hosting, business systems, in-country service partners
|Why we assess|To understand and document their controls, so we can answer customer questions accurately and pass through the right commitments|To decide whether to engage them at all, and on what terms
|What a poor result means|We disclose the limitation to customers, apply compensating controls, and reflect it in what we commit to|We do not engage them, or we require remediation first
|Who decides|Managing Director, as a commercial and strategic decision informed by the assessment|IT Management, on the assessment

The distinction matters. A product vendor relationship is a commercial decision that an assessment informs but does not determine. A subprocessor engagement is a decision the assessment can and should block.

**What the Company does not do is skip the assessment because the relationship is already in place**. For existing product vendors, the assessment produces the documentation we rely on when a customer asks how their data is protected.

  

## 5. Policy

### 5.1 Risk Tiering

Every vendor is assigned a tier. The tier determines how deeply it is assessed and how often it is reviewed.

|Tier|Applies where the vendor|Assessment|Review
|--|--|--|--|
|**Tier 1 — High**|Processes personal data, hosts customer data, or is critical to delivering a contracted service|Full assessment (section 5.2), documented evidence, written data protection terms|Annually
|**Tier 2 — Medium**|Has access to Confidential information or systems, but not to personal data, and is not service-critical|Short assessment and contractual terms|Every 2 years
|**Tier 3 — Low**|Has no access to Company or customer data or systems|Basic due diligence and standard contract terms|On renewal

Where a vendor's role changes — it starts handling personal data, or becomes critical to a service — it is re-tiered and reassessed.

### 5.2 What We Assess

For Tier 1 vendors, we seek to establish:

-   **Security controls** — access control, encryption, logging, patching, endpoint and network security.
    
-   **Certifications and audit reports** — ISO/IEC 27001, SOC 2 or equivalent, where held.
    
-   **Data protection** — lawful basis and role (controller or processor), written data protection terms, and compliance with the laws of our markets.
    
-   **Data location** — where data is stored and from where it is accessed, so we can meet cross-border transfer obligations.
    
-   **Their own subprocessors** — who they in turn rely on, and whether they notify us of changes.
    
-   **Incident notification** — whether they will notify us of a breach, and within what timeframe.
    
-   **Backup and recovery** — their commitments, and whether they meet what we have promised our customers.
    
-   **Retention and deletion** — what happens to data at the end of the relationship.
    
-   **Business viability and continuity** — whether they can be expected to still be operating, and what happens to our customers if they are not.
    
-   **Support model** — escalation route, response commitments, and end-of-life policy for the products we resell.
    

For Tier 2, we cover security controls, data protection terms, incident notification and support. For Tier 3, we confirm identity, standing and standard contract terms.

Publicly available documentation — a vendor's security page, certifications, service level agreement and privacy documentation — is acceptable evidence where it answers the question. We do not require a questionnaire where the answer is already published.

### 5.3 When We Assess

-   **Before engagement**, for any new Tier 1 or Tier 2 vendor.
    
-   **Before adding a product to the portfolio**, as part of the commercial evaluation.
    
-   **On the review cycle** in section 5.1.
    
-   **On material change** — a change of ownership, a move of hosting location, a new subprocessor, a significant security incident, or a change in the data they handle.
    
-   **When a customer asks**, if our documentation is not current enough to answer.
    

### 5.4 Contractual Requirements

Tier 1 and Tier 2 vendors must be bound in writing to, at minimum:

-   confidentiality;
    
-   processing personal data only on our instructions or the customer's, and only for the agreed purpose;
    
-   appropriate technical and organisational security measures;
    
-   notifying us of a personal data breach or security incident without undue delay;
    
-   disclosing their own subprocessors and notifying us of changes;
    
-   returning or deleting data at the end of the relationship;
    
-   providing the documentation we need to answer our customers' due diligence questions.
    

Where a vendor's standard terms — common with large cloud and software providers — cannot be negotiated, we assess those standard terms against these requirements and record any gap as a risk under section 5.6.

### 5.5 In-Country Service Partners

Partners performing work in Singapore, Malaysia, Thailand or Indonesia are assessed as Tier 1 where they access customer systems or premises, and are additionally required to:

-   work only within the access granted for their appointed role, under the Company's Security Policy and Password Policy;
    
-   ensure their personnel are subject to equivalent confidentiality obligations;
    
-   not subcontract without our written approval;
    
-   report any incident immediately to the Technical Services Manager.
    

Partner appointments are reviewed annually, and access is revoked within 24 hours of an appointment ending.

### 5.6 Findings, Gaps and Risk Acceptance

-   Findings are recorded against the vendor in the vendor register.
    
-   Where a gap can be closed, we require remediation before engagement, or within an agreed period for an existing vendor.
    
-   Where a gap cannot be closed — typically with a large vendor whose terms are fixed — the residual risk is scored under section 5 of the Security Policy, and accepted only by IT Management, or by the Managing Director where the risk is High.
    
-   **Accepted risks that affect what we can commit to a customer are disclosed to that customer**, rather than absorbed silently.
    
-   Risk acceptances are recorded with a justification and reviewed at least annually.
    

### 5.7 Ongoing Monitoring

Assessment is not a one-off exercise. On an ongoing basis we:

-   monitor vendor security advisories, breach disclosures and end-of-life notices;
    
-   track service performance against the vendor's commitments, and whether that supports what we have promised customers;
    
-   record incidents involving a vendor, and treat a pattern as a reason to reassess ahead of schedule;
    
-   note changes to a vendor's subprocessors, hosting locations or ownership.
    

### 5.8 Vendor Register and Customer Disclosure

The Company maintains a register recording, for each vendor: what it provides, its tier, whether it processes personal data, where that data is held, its assessment date and outcome, its contractual terms, and its review date.

From this register the Company maintains a **subprocessor list** identifying every third party that processes personal data on behalf of customers, with the service provided and the data location. **This list is available to customers on request**, as committed in the Company's Privacy Policy and compliance statements.

### 5.9 Exit and Replacement

For every Tier 1 vendor, the Company records what would happen if the relationship ended — whether data can be exported, in what format, whether an alternative exists, and what the customer impact would be. This is assessed at onboarding, not at the point of crisis.

At the end of a vendor relationship, we confirm data has been returned or deleted, access has been revoked, and the register has been updated.

  

## 6. Customer Requests

Customers may request the subprocessor list, our assessment position on a specific vendor, or the vendor's own security and privacy documentation. We provide what we hold, subject to any confidentiality obligation owed to the vendor. Where we cannot share a vendor's document directly, we say so and provide a summary or direct the customer to the vendor.

  

## 7. Policy Compliance

### 7.1 Compliance Measurement

IT Management verifies compliance through review of the vendor register against actual engagements, completeness of assessments against the review cycle, and internal and external audits.

### 7.2 Exceptions

Engaging a Tier 1 or Tier 2 vendor without a completed assessment requires advance approval from IT Management, with a justification, a compensating control and a date by which the assessment will be completed.

### 7.3 Non-Compliance

An employee found to have engaged a vendor outside this policy, or to have granted a third party access to Company or customer systems without assessment and approval, may be subject to disciplinary action, up to and including termination of employment.

  

## 8. Review

This policy is reviewed and updated at least annually, and also on any material change to the portfolio, to the Company's hosting arrangements, or to applicable law.

  

## 9. Contact

Questions about this policy, or requests for vendor and subprocessor information, may be directed to:

**Integrated Retail Pte Ltd** Email: connect@integratedretail.com