1. Purpose and Relationship to Governing Documents
This Vendor Management and Third-Party Provider Policy ("Policy") is published by VA WORKS, LLC ("Consultant") and forms part of the Governing Policies referenced in the Master Service Agreement (MSA), the MSA Terms and Conditions (https://vaworks.com/MasterServiceAgreement), and any applicable Scope of Work Terms and Conditions (https://vaworks.com/SOWSelection). In the event of conflict, priority shall be determined in accordance with the MSA.
The purpose of this Policy is to establish standards for the evaluation, selection, oversight, and offboarding of third-party vendors and service providers engaged by Consultant in support of its internal business operations.
2. Scope
This Policy applies to all third-party service providers engaged by Consultant, including contractors, consultants, SaaS platforms, and technology providers.
Important Note: Third-party vendors engaged by Consultant do not have access to client systems, client credentials, or Non-Public Personal Information (NPI). All access to such environments is managed exclusively by the client.
3. Vendor Classification
Vendors engaged by Consultant are classified according to function:
- Tier 1 – Administrative Support: Internal vendors supporting HR, payroll, or communications.
- Tier 2 – Operational Tools: Platforms for scheduling, training, or internal management.
- Tier 3 – Low-Risk Services: Office suppliers, couriers, or logistics providers.
4. Due Diligence and Onboarding
Prior to engagement, vendors are evaluated for:
- Business legitimacy and reputation;
- Adequate internal security posture (if applicable);
- Contractual commitment to confidentiality.
All vendors must execute written agreements addressing scope of services, confidentiality of Consultant's internal operations, and termination/audit clauses.
5. Ongoing Monitoring
- Vendor relationships are reviewed annually for necessity and performance.
- Contracts are updated or renewed as appropriate.
- No vendor is permitted access to client systems or regulated client data under any circumstance.
6. Termination and Offboarding
When a vendor relationship ends:
- Any shared access to Consultant's internal tools is revoked within 24 hours;
- Final invoicing and closure documentation are completed and retained.
7. Confidentiality and Safeguards
Even without access to client data, vendors are required to:
- Sign confidentiality agreements;
- Follow basic data-handling protocols where applicable.
8. Documentation and Audit
All vendor agreements are securely stored and subject to internal audit. Clients may request confirmation at any time that no third-party vendors access their systems or NPI.
9. Client Systems Disclaimer
Consultant's use of third-party vendors is limited strictly to Consultant's internal business operations. Vendors do not interact with or manage Company-owned systems, platforms, or data. In accordance with the Data Security and Breach Disclaimer, Company remains solely responsible for its own environments, including any virtual desktops, licensed platforms, or third-party applications it provides. Consultant assumes no liability for Company's internal systems or security obligations.
10. Policy Review
This Policy is reviewed annually, or sooner in response to regulatory or business changes, by Consultant's leadership.
