Third-Party Risk Review - New Contract or Renewal

Service

Request a review of an outside IT vendor before a new contract or a renewal. Covers software, cloud services, online platforms, hardware, and other technology products or services used by the District. Supports compliance with Administrative Procedure 3910.1.

Use this to: Screen an IT vendor for security, privacy, and contract fit before the District signs or renews an agreement.

Do not use this for

  • Non-IT vendors or purchases with no technology, data, or system-access component. Route through the standard purchasing process instead.
  • A planned change to an existing IT service. Use the Technology change request service instead.

Before you request

Have the following ready. If you are unsure of an answer, provide what you have and Technology Services and Support will follow up.

  • Vendor name, product or service, and a short description of the business use.
  • Whether the vendor will handle sensitive student or employee information or connect to District systems.
  • If sensitive data or system access is involved, ask the vendor (you do not prepare these yourself) for a SOC 2 Type 2 report or a completed HECVAT. Attaching one significantly reduces follow-up.

Protect your information: Never include passwords, multifactor authentication verification codes, recovery codes, or other secrets in a service request.