Processor Assessment Questionnaire
VENDOR / PROCESSOR DUE-DILIGENCE QUESTIONNAIRE
1. Security Controls
- Do you have an established Information Security Policy? [YES/NO]
- Is data encrypted at rest and in transit? [YES/NO]
2. Data Processing Agreements
- Will you sign a DPDP-aligned Data Processing Agreement (DPA)? [YES/NO]
- Do you engage sub-processors? [YES/NO]
3. Incident Response
- Do you have a documented incident response plan? [YES/NO]
- Will you notify us of a breach without undue delay? [YES/NO]
Note: This is a starting operational template. Customise based on vendor risk tier.