## Purpose

Use this form before granting a vendor, MSP, contractor, consultant, or other external party access to company systems or data.

The objective is to ensure vendor access has a legitimate business purpose, appropriate approval, limited permissions, strong authentication, and a clear end or review date.

## Vendor Information

Vendor: ____________________

Individual receiving access: ____________________

Internal vendor owner: ____________________

Service or project: ____________________

Request date: ____________________

## Access Requested

System or service:

---

Access level:

---

Business reason:

---

**Access type:**

- Standard user
- Administrator
- Remote support
- VPN
- Cloud access
- Application access
- API / integration
- Database access
- Backup access
- Other: ____________________

## Duration

Permanent while contract requires it

Temporary

Start date: ____________________

Expiry date: ____________________

Whenever practical, temporary or project-based access should expire automatically.

## Data Access

**Will this access allow the vendor to view or process:**

- Customer data: Yes / No

- Employee data: Yes / No

- Financial information: Yes / No

- Credentials: Yes / No

- Confidential company information: Yes / No

- Other sensitive information: ____________________

## Security Requirements

**Confirm:**

- [ ]  Named vendor account used where practical.
- [ ]  MFA enabled.
- [ ]  Shared credentials avoided.
- [ ]  Least privilege applied.
- [ ]  Access limited to required systems.
- [ ]  Remote access uses an approved method.
- [ ]  Administrative access separately approved.
- [ ]  Logging enabled where appropriate.
- [ ]  Vendor security expectations communicated.
- [ ]  Sensitive data access specifically approved.

## High-Risk Access

Is privileged or otherwise high-risk access required?

- Yes / No

If yes, explain:

---

Additional controls:

---

## Approval

Internal vendor owner: ____________________

System owner: ____________________

Data owner where applicable: ____________________

IT/security approval: ____________________

Additional leadership approval required:

- Yes / No

Approver: ____________________

## Implementation

Account created by: ____________________

Access granted: ____________________

- MFA confirmed: Yes / No / N/A

- Expiry configured: Yes / No / N/A

- Logging confirmed: Yes / No / N/A

Implementation date: ____________________

Evidence/ticket: ____________________

## Review

Last review: ____________________

Next review: ____________________

- Still required: Yes / No

- Permissions still appropriate: Yes / No

## Removal

Access removal date: ____________________

Removed by: ____________________

Evidence: ____________________

## Practical Rule

Vendor access should be named, approved, limited, protected, reviewed, and removed when no longer required.
