How Osano Can Help
How Osano Can Help You Mature Your Privacy Program Building, running,...
Read NowGet an overview of the simple, all-in-one data privacy platform
Manage consent for data privacy laws in 50+ countries
Streamline and automate the DSAR workflow
Efficiently manage assessment workflows using custom or pre-built templates
Streamline consent, utilize non-cookie data, and enhance customer trust
Automate and visualize data store discovery and classification
Ensure your customers’ data is in good hands
Key Features & Integrations
Discover how Osano supports CPRA compliance
Learn about the CCPA and how Osano can help
Achieve compliance with one of the world’s most comprehensive data privacy laws
Key resources on all things data privacy
Expert insights on all things privacy
Key resources to further your data privacy education
Meet some of the 5,000+ leaders using Osano to transform their privacy programs
A guide to data privacy in the U.S.
What's the latest from Osano?
Data privacy is complex but you're not alone
Join our weekly newsletter with over 35,000 subscribers
Global experts share insights and compelling personal stories about the critical importance of data privacy
Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start a privacy program
Upcoming webinars and in-person events designed for privacy professionals
The Osano story
Become an Osanian and help us build the future of privacy!
We’re eager to hear from you
Benchmark and Grow Your Organization’s Privacy Program
Related to contract management, vendor risk management provides a method for managing privacy risks that would otherwise be outside of your control. Once your customers’ data passes to a third party, there’s little you can do to continue to protect it unless you engage in robust vendor risk management processes. There is a significant overlap between vendor risk management and contract management. However, aspects of vendor risk management are not related to contracts; similarly, not all contract-related privacy issues involve vendors. Hence, the two are represented by separate elements in this model.
The concept of vendor risk may not be present in an organization with immature vendor risk management practices. Not only will the regulatory requirements around mitigating vendor risk be poorly understood, but there may be no actual activities taking place to mitigate vendor risk. If regulatory requirements are understood, they may be met according to the letter of the law but not its spirit.
Contractual language may be put into place, but there will be little or inconsistent auditing for compliance. Likewise, there will be inconsistent or absent reviews of privacy risk in vendors prior to onboarding. When a privacy breach or privacy incident occurs relating to vendors, there may be little to no remediation.
Mature vendor risk management involves an established and continuously improved process for assessing vendors for privacy risk. That starts before vendor selection occurs by using candidate vendors’ privacy practices to establish a short list of acceptable candidates and continues on through onboarding, ongoing review, the establishment of risk mitigation strategies, implementation of risk mitigation plans should vendor practices change, and regular communication with vendors to ensure compliance with privacy and security requirements.
Privacy professionals interested in improving their vendor risk management process should:
With Osano, building, managing, and scaling your privacy program becomes simple. Schedule a demo or try a free 30-day trial today.