What should you check before giving an IT supplier access to company systems?
Confirm the supplier’s task, required access, security controls, subcontractor involvement and exit process. Grant access appropriate to the work and keep an accountable internal owner. A contract alone does not control what an account can do.
Make access specific
List the systems, roles and duration required. Use named identities where appropriate and avoid granting broad administrative rights by default. Agree how temporary access is approved and removed after the task.
Review the information involved
Identify the data the supplier can view or export and where it may be processed. Confirm support tools and remote access arrangements. The assessment should reflect the actual service rather than a generic questionnaire alone.
Agree incident cooperation
Define how the supplier reports a suspected compromise, preserves relevant evidence and works with your response team. Check the escalation contacts and the responsibilities of any subcontractors.
Plan the end of the relationship
Specify documentation, data return or deletion, configuration handover and access revocation. Keep business ownership of critical accounts and subscriptions clear. The exit process should be workable even when the commercial relationship changes.
Review access periodically and after staff or scope changes. A supplier who needed extensive permissions during implementation may need much less access for ongoing support.
Put this guidance to work.
Explore the relevant emtech service, then discuss the scope that fits your business.