Back to all articles
Supplier Technology Due Diligence: Vetting the Vendors
Audit and Compliance
6 August 20267 min read

Supplier Technology Due Diligence: Vetting the Vendors

aS

asitplan Strategy Team

Author

RL

Rob Lloyd

Technical Reviewer

06 August 2026

Last Reviewed

School business leaders, DPOs, and IT managers

Target Audience

The Context

Schools outsource a massive amount of functionality: MIS providers, catering systems, parent communication apps, and IT support. This means sensitive school data is stored on networks the school does not control. If a supplier is breached, the school's data is breached, yet many schools procure these services based solely on cost and features, ignoring security.

Who This Guide is For

School business leaders, Data Protection Officers (DPOs), and IT managers.

Why This Matters

Supply chain attacks are increasingly common. An attacker compromises a small, weakly defended software vendor to gain access to the hundreds of schools that use that software. The school remains legally responsible as the Data Controller, even if the Data Processor (the vendor) was the one who was breached.

What Good Looks Like

A formalized vendor risk assessment process that occurs before any contract is signed. The school requires vendors to provide objective evidence of their security posture (e.g., penetration test summaries, ISO 27001 certificates, or Cyber Essentials Plus) and actively rejects vendors who refuse to comply.

Approach and Methodology

  1. Categorize the Vendors: Not all vendors pose the same risk. A catering system holding pupil allergy data and parent financial details requires strict vetting. A vendor supplying unmanaged library books requires none.
  2. The Security Questionnaire: Develop a standard set of questions for high-risk vendors. Do they encrypt data at rest? Do they mandate MFA for their own staff? Where is the data physically hosted?
  3. Demand Evidence, Not Promises: If a vendor claims their platform is "bank-level secure," ask for the executive summary of their latest independent penetration test. If they refuse, assume the platform is insecure.
  4. Data Processing Agreements (DPAs): Ensure a robust DPA is signed, legally obligating the vendor to notify the school within a specific timeframe (e.g., 24 hours) if they suffer a breach.
  5. Review Access: Audit what access the vendor has to your network. Do they have a permanent VPN connection? If so, restrict it to 'Just-in-Time' access.
  6. Annual Re-assessment: A vendor's security posture can degrade. Re-assess high-risk vendors annually to ensure they still meet your baseline standards.

Evidence to Retain

  • Completed Vendor Risk Assessments for all high-risk suppliers.
  • Signed Data Processing Agreements (DPAs) stored centrally.
  • A register of all third-party access to the school network.

Questions Leadership Should Ask

  • "If our parent communication app was hacked tonight, are they legally obligated to tell us immediately?"
  • "Do we have a list of every third-party vendor that currently holds our staff or student data?"

Common Pitfalls

  • Procurement Silos: The Head of Department buys an app because it looks great for teaching, completely bypassing the IT and DPO vetting process.
  • Accepting Generic Answers: Accepting a vendor's marketing brochure as proof of their cybersecurity posture.
  • The "Too Big to Fail" Assumption: Assuming that because a vendor is a large, well-known educational company, they must be secure. Large companies suffer breaches regularly.

How asitplan Can Help

asitplan allows you to track your software and service vendors alongside your hardware assets. You can log compliance documentation (like DPAs and vendor security certificates) directly against the vendor record, ensuring your supply chain due diligence is always auditable and up to date.

Ready to simplify your school's IT compliance?

asitplan provides the unified dashboard and automated reporting you need to stay ahead of DfE standards and KCSIE updates.