Anchor's own TPRM service line, condensed: tiering, the pre-signature checklist, and the questions that actually separate a real security program from a filled-out questionnaire.
| □ | Criticality tier assigned before the security review starts — this decides how deep to go, not the vendor's sales rep |
| □ | Security questionnaire completed (SIG Lite for moderate, full SIG or CAIQ for critical/cloud vendors) |
| □ | BAA executed before any regulated data (PHI) is shared — not after, not "in progress" |
| □ | DPA executed if the vendor processes personal data subject to GDPR/CCPA |
| □ | Subprocessor list reviewed — a vendor's own subprocessors inherit the same tier logic |
| □ | Breach notification clause with a specific time window, not "promptly" left undefined |
| □ | Right-to-audit or right to request a SOC 2 / ISO 27001 certificate, for critical-tier vendors |
| □ | Data deletion/return terms on contract termination — decided now, not negotiated during an offboarding dispute |