TorontoBiztech
Search

Glossary

Vendor Access

Vendor access is the standing permission a third party holds into your systems and data, and it is usually the least governed risk a business carries.

By Biztech Editors Reviewed TorontoGlossaryCybersecurityVendor Risk

Vendor access is the standing permission a third party holds into your systems, data, or premises. It is granted during an implementation, used occasionally afterward, and reviewed almost never.

Who Holds It

More parties than most businesses can list from memory:

  • The firm that implemented your accounting or ERP system, often still holding administrator credentials
  • Your managed IT provider, usually with domain administrator rights
  • Software vendors with remote support tooling on staff machines
  • Your bookkeeper or external accountant, inside the financial system
  • Payroll and benefits providers, holding employee data
  • Marketing agencies inside your website, analytics, and advertising accounts
  • A developer who built something four years ago and was never offboarded

Why It Matters More Than It Looks

It survives the relationship. Access granted for a project frequently outlives the project, the contract, and sometimes the vendor.

It is usually over-scoped. Administrator rights are faster to grant than a properly scoped role, so administrator is what gets granted.

It bypasses your controls. Your own staff have onboarding, offboarding, and access reviews. Vendor accounts frequently sit outside all three.

Their breach becomes your incident. If a vendor with access is compromised, the exposure is your data and your notification obligation.

What Governing It Actually Requires

Four things, none of them technically difficult:

  1. A list. Every third party with access, what they can reach, and why. The absence of this list is the usual finding.
  2. Scope. Access limited to what the role needs, and time-limited where the work is time-limited.
  3. Review. A recurring check that each account is still needed and still correctly scoped.
  4. Offboarding. A defined step when a relationship ends, executed instead of assumed.

A Toronto Note

Federally regulated financial institutions operate under formal third-party risk expectations from their regulator, so businesses supplying that sector are increasingly asked to evidence their own vendor access controls as a condition of the contract. That pushes the requirement down the supply chain to companies that never faced it before.

Where This Applies