The short answer
Create one register covering purchased software, free tools, browser extensions, mobile apps, AI services, integrations, OAuth consent, remote support, service accounts, file transfers, websites, and providers. For each, record the business owner, information involved, access method, privileges, location, subcontractors, authentication, retention, incident notice, export, deletion, continuity, and offboarding.
Key takeaways
- A vendor inventory names the relationship; an access map explains what the relationship can do.
- Include free apps, trials, browser extensions, embedded AI, integrations, and employee-created accounts—not only approved contracts.
- Review both stored data and ongoing access to email, files, calendars, directories, devices, databases, and administration.
- Prioritize vendors by access, criticality, information sensitivity, and replacement difficulty.
- Offboarding is complete only when access, tokens, accounts, forwarding, remote tools, retained data, and dependencies are addressed.
The Canadian Centre for Cyber Security states that the first step in securing a supply chain is knowing which vendors have access to data and support critical business functions. It recommends an inventory of third parties and categorization based on operational criticality.
Small organizations rarely acquire technology through one controlled procurement process. A staff member may add a browser extension, an owner may approve a cloud app to remove a bottleneck, a bookkeeper may connect accounting data, a website plugin may send customer information elsewhere, and a support provider may retain remote access long after the original task.
Most of these decisions are understandable. The control failure occurs when nobody records the relationship, checks the permissions, or owns the exit.
The 12 questions every vendor and app record should answer
01 What is the tool or provider, and why is it used?
Record the legal vendor, product, plan, account, business purpose, internal owner, users, contract, renewal, and whether it is approved, experimental, embedded, or unsanctioned.
02 What information does it receive or create?
Identify personal, client, employee, financial, operational, proprietary, authentication, and metadata. Include prompts, recordings, transcripts, logs, generated content, exports, and support data.
03 How does information reach it?
Record uploads, email forwarding, API connections, OAuth consent, agents, browser extensions, mobile permissions, file synchronization, remote access, website forms, scripts, plugins, and manual entry.
04 What can it read, change, delete, send, or administer?
Review delegated and application permissions, roles, group access, mailbox and file access, offline access, device control, directory access, and administrator privileges. A broad permission may exceed the feature staff actually use.
05 Who controls the organizational account?
Record billing, administrators, MFA, recovery, ownership, domain verification, provider contacts, and the organization’s ability to replace an administrator or reseller.
06 Where is information processed and stored?
Record known hosting and processing locations, backup and support locations, remote support, cross-border considerations, and whether the vendor can change locations under its terms. Obtain legal or privacy advice where location matters.
07 Which subcontractors and connected services are involved?
Identify material subprocessors, hosting providers, AI model providers, payment processors, support partners, and integrations. Focus first on those that receive sensitive information or support a critical function.
08 How is access authenticated and monitored?
Review individual identities, MFA, SSO, privileged access, service accounts, API keys, tokens, logging, alerting, session controls, and who reviews suspicious activity.
09 What happens after an incident or vulnerability?
Record notification commitments, timing, contacts, cooperation, evidence, containment expectations, support availability, and the organization’s own escalation path.
10 How long is information retained, and how is it deleted?
Review active data, logs, backups, deleted accounts, model or service improvement, legal holds, exports, account closure, and proof or limits of deletion. Do not promise deletion that the contract or service cannot deliver.
11 Can the business export its data and continue elsewhere?
Record export formats, frequency, administrative requirements, cost, dependency on vendor cooperation, migration support, configuration information, and practical replacement time.
12 How does the relationship end?
Define notice, data export, transfer of ownership, access removal, token revocation, remote-tool removal, service-account handling, forwarding, retained information, final invoices, and evidence of completion.
Four practical vendor tiers
| Tier | Use |
|---|---|
| Critical operator | Failure or loss of access stops a core service, payment, production, professional workflow, or essential communication. |
| Sensitive-data processor | Receives or can reach material personal, client, employee, financial, health, privileged, or proprietary information. |
| Privileged technical provider | Has administrative, remote, security, backup, domain, network, device, or recovery access. |
| Standard/low-impact tool | Limited information and replaceable function, but still recorded and subject to basic approval and offboarding. |
Discovery sources that reveal hidden relationships
- Accounts payable, credit cards, invoices, renewals, and procurement records
- Microsoft 365 or Google Workspace enterprise applications and consent grants
- SSO application lists, password-manager collections, browser extensions, and mobile apps
- Email forwarding, shared mailboxes, transport rules, website plugins, forms, and marketing tags
- Remote-support agents, device-management tools, backup consoles, security products, and service accounts
- Interviews with staff who perform finance, client service, marketing, operations, HR, IT, and management work
The AI-vendor extension
For AI tools, also record model or service provider, account tier, training or improvement settings, prompt and output retention, connected sources, agents, tool use, human review, prohibited information, and whether the tool can take actions. Use the AI Readiness & Governance process for higher-risk uses.
Frequently asked questions
Is a list of software subscriptions enough?
No. It misses free tools, integrations, browser extensions, remote access, service accounts, website components, and the specific permissions or data paths behind each relationship.
Should every vendor receive a full security assessment?
No. Use a risk-based approach. Critical, privileged, sensitive-data, hard-to-replace, and high-consequence vendors justify deeper review than low-impact tools.
Can CyberTECT certify that a vendor is secure?
No. CyberTECT can help document the relationship, review available evidence, identify concerns, and support a risk decision. No external review can guarantee a vendor will not fail or experience an incident.
Who should own the vendor register?
Leadership should assign an accountable business owner. Finance, privacy, security, IT, procurement, and operational staff may contribute, but the organization needs one maintained record and review process.
How often should vendors be reviewed?
Use a risk-based schedule and trigger reviews after incidents, major product or ownership changes, new integrations, material contract changes, data expansion, renewal, or service degradation.
Know the access path before depending on the vendor
Small businesses do not need an enterprise procurement department to improve vendor control. They need one current record that shows which relationships matter, what access exists, who owns the decision, and how the organization exits safely.
CyberTECT can establish the vendor baseline through a Digital Operations Checkup or examine it as part of the complete AI & Digital Operations Review.
Start with the level of review you need
Take the 90-second Digital Operations Control Check for an immediate directional result. For an evidence-based review of accounts, files, Microsoft 365 backups, vendors, AI use, and continuity, discuss the Digital Operations Checkup or the complete AI & Digital Operations Review. Scope and fees are confirmed before work begins.
General information only. This article does not provide legal, privacy, professional-conduct, or regulatory advice. Organizations should obtain appropriate advice for their sector, jurisdiction, information, and intended AI use.
Related CyberTECT services and checks
Authoritative sources and further guidance
- Canadian Centre for Cyber Security — Supply chain security for small and medium organizations
- Canadian Centre for Cyber Security — Consumers of managed services
- NIST CSF 2.0 Supply Chain Risk Management Quick-Start Guide
- NIST Cybersecurity Framework 2.0
CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.