VA Works

Vendor Management and Third-Party Provider Policy

Last Revised: September 18, 2025

1. Purpose and Relationship to Governing Documents

This Vendor Management and Third-Party Provider Policy ("Policy") is published by VA WORKS, LLC ("Consultant") and forms part of the Governing Policies referenced in the Master Service Agreement (MSA), the MSA Terms and Conditions (https://vaworks.com/MasterServiceAgreement), and any applicable Scope of Work Terms and Conditions (https://vaworks.com/SOWSelection). In the event of conflict, priority shall be determined in accordance with the MSA.

The purpose of this Policy is to establish standards for the evaluation, selection, oversight, and offboarding of third-party vendors and service providers engaged by Consultant in support of its internal business operations.

2. Scope

This Policy applies to all third-party service providers engaged by Consultant, including contractors, consultants, SaaS platforms, and technology providers.

Important Note: Third-party vendors engaged by Consultant do not have access to client systems, client credentials, or Non-Public Personal Information (NPI). All access to such environments is managed exclusively by the client.

3. Vendor Classification

Vendors engaged by Consultant are classified according to function:

  • Tier 1 – Administrative Support: Internal vendors supporting HR, payroll, or communications.
  • Tier 2 – Operational Tools: Platforms for scheduling, training, or internal management.
  • Tier 3 – Low-Risk Services: Office suppliers, couriers, or logistics providers.

4. Due Diligence and Onboarding

Prior to engagement, vendors are evaluated for:

  • Business legitimacy and reputation;
  • Adequate internal security posture (if applicable);
  • Contractual commitment to confidentiality.

All vendors must execute written agreements addressing scope of services, confidentiality of Consultant's internal operations, and termination/audit clauses.

5. Ongoing Monitoring

  • Vendor relationships are reviewed annually for necessity and performance.
  • Contracts are updated or renewed as appropriate.
  • No vendor is permitted access to client systems or regulated client data under any circumstance.

6. Termination and Offboarding

When a vendor relationship ends:

  • Any shared access to Consultant's internal tools is revoked within 24 hours;
  • Final invoicing and closure documentation are completed and retained.

7. Confidentiality and Safeguards

Even without access to client data, vendors are required to:

  • Sign confidentiality agreements;
  • Follow basic data-handling protocols where applicable.

8. Documentation and Audit

All vendor agreements are securely stored and subject to internal audit. Clients may request confirmation at any time that no third-party vendors access their systems or NPI.

9. Client Systems Disclaimer

Consultant's use of third-party vendors is limited strictly to Consultant's internal business operations. Vendors do not interact with or manage Company-owned systems, platforms, or data. In accordance with the Data Security and Breach Disclaimer, Company remains solely responsible for its own environments, including any virtual desktops, licensed platforms, or third-party applications it provides. Consultant assumes no liability for Company's internal systems or security obligations.

10. Policy Review

This Policy is reviewed annually, or sooner in response to regulatory or business changes, by Consultant's leadership.

Start Here

0/10 steps explored