### VENDOR / PROCESSOR DUE-DILIGENCE QUESTIONNAIRE #### 1. Security Controls - Do you have an established Information Security Policy? [YES/NO] - Is data encrypted at rest and in transit? [YES/NO] #### 2. Data Processing Agreements - Will you sign a DPDP-aligned Data Processing Agreement (DPA)? [YES/NO] - Do you engage sub-processors? [YES/NO] #### 3. Incident Response - Do you have a documented incident response plan? [YES/NO] - Will you notify us of a breach without undue delay? [YES/NO] Note: This is a starting operational template. Customise based on vendor risk tier.