← Governance & GRC
Guide EMTECH KNOWLEDGE HUB

What should you check before giving an IT supplier access to company systems?

THE SHORT ANSWER

Confirm the supplier’s task, required access, security controls, subcontractor involvement and exit process. Grant access appropriate to the work and keep an accountable internal owner. A contract alone does not control what an account can do.

Make access specific

List the systems, roles and duration required. Use named identities where appropriate and avoid granting broad administrative rights by default. Agree how temporary access is approved and removed after the task.

Review the information involved

Identify the data the supplier can view or export and where it may be processed. Confirm support tools and remote access arrangements. The assessment should reflect the actual service rather than a generic questionnaire alone.

Agree incident cooperation

Define how the supplier reports a suspected compromise, preserves relevant evidence and works with your response team. Check the escalation contacts and the responsibilities of any subcontractors.

Plan the end of the relationship

Specify documentation, data return or deletion, configuration handover and access revocation. Keep business ownership of critical accounts and subscriptions clear. The exit process should be workable even when the commercial relationship changes.

Review access periodically and after staff or scope changes. A supplier who needed extensive permissions during implementation may need much less access for ongoing support.

FROM PLANNING TO IMPLEMENTATION

Put this guidance to work.

Explore the relevant emtech service, then discuss the scope that fits your business.

Keep exploring

Related emtech resources

YOUR NEXT STEP

Turn a question into a clear plan.

Tell us what your business needs. We’ll help identify the right conversation, service or project scope.

Already an emtech customer?

Use the support contacts in your service agreement for active incidents.

Open customer support

Discuss your requirements

Please do not include passwords or confidential files.