Vendor Access Approval Form

Purpose

Use this form before granting a vendor, MSP, contractor, consultant, or other external party access to company systems or data.

The objective is to ensure vendor access has a legitimate business purpose, appropriate approval, limited permissions, strong authentication, and a clear end or review date.

Vendor Information

Vendor: ____________________

Individual receiving access: ____________________

Internal vendor owner: ____________________

Service or project: ____________________

Request date: ____________________

Access Requested

System or service:


Access level:


Business reason:


Access type:

  • Standard user
  • Administrator
  • Remote support
  • VPN
  • Cloud access
  • Application access
  • API / integration
  • Database access
  • Backup access
  • Other: ____________________

Duration

Permanent while contract requires it

Temporary

Start date: ____________________

Expiry date: ____________________

Whenever practical, temporary or project-based access should expire automatically.

Data Access

Will this access allow the vendor to view or process:

  • Customer data: Yes / No

  • Employee data: Yes / No

  • Financial information: Yes / No

  • Credentials: Yes / No

  • Confidential company information: Yes / No

  • Other sensitive information: ____________________

Security Requirements

Confirm:

  • Named vendor account used where practical.
  • MFA enabled.
  • Shared credentials avoided.
  • Least privilege applied.
  • Access limited to required systems.
  • Remote access uses an approved method.
  • Administrative access separately approved.
  • Logging enabled where appropriate.
  • Vendor security expectations communicated.
  • Sensitive data access specifically approved.

High-Risk Access

Is privileged or otherwise high-risk access required?

  • Yes / No

If yes, explain:


Additional controls:


Approval

Internal vendor owner: ____________________

System owner: ____________________

Data owner where applicable: ____________________

IT/security approval: ____________________

Additional leadership approval required:

  • Yes / No

Approver: ____________________

Implementation

Account created by: ____________________

Access granted: ____________________

  • MFA confirmed: Yes / No / N/A

  • Expiry configured: Yes / No / N/A

  • Logging confirmed: Yes / No / N/A

Implementation date: ____________________

Evidence/ticket: ____________________

Review

Last review: ____________________

Next review: ____________________

  • Still required: Yes / No

  • Permissions still appropriate: Yes / No

Removal

Access removal date: ____________________

Removed by: ____________________

Evidence: ____________________

Practical Rule

Vendor access should be named, approved, limited, protected, reviewed, and removed when no longer required.