Vendor Access Approval Form
Purpose
Use this form before granting a vendor, MSP, contractor, consultant, or other external party access to company systems or data.
The objective is to ensure vendor access has a legitimate business purpose, appropriate approval, limited permissions, strong authentication, and a clear end or review date.
Vendor Information
Vendor: ____________________
Individual receiving access: ____________________
Internal vendor owner: ____________________
Service or project: ____________________
Request date: ____________________
Access Requested
System or service:
Access level:
Business reason:
Access type:
- Standard user
- Administrator
- Remote support
- VPN
- Cloud access
- Application access
- API / integration
- Database access
- Backup access
- Other: ____________________
Duration
Permanent while contract requires it
Temporary
Start date: ____________________
Expiry date: ____________________
Whenever practical, temporary or project-based access should expire automatically.
Data Access
Will this access allow the vendor to view or process:
-
Customer data: Yes / No
-
Employee data: Yes / No
-
Financial information: Yes / No
-
Credentials: Yes / No
-
Confidential company information: Yes / No
-
Other sensitive information: ____________________
Security Requirements
Confirm:
- Named vendor account used where practical.
- MFA enabled.
- Shared credentials avoided.
- Least privilege applied.
- Access limited to required systems.
- Remote access uses an approved method.
- Administrative access separately approved.
- Logging enabled where appropriate.
- Vendor security expectations communicated.
- Sensitive data access specifically approved.
High-Risk Access
Is privileged or otherwise high-risk access required?
- Yes / No
If yes, explain:
Additional controls:
Approval
Internal vendor owner: ____________________
System owner: ____________________
Data owner where applicable: ____________________
IT/security approval: ____________________
Additional leadership approval required:
- Yes / No
Approver: ____________________
Implementation
Account created by: ____________________
Access granted: ____________________
-
MFA confirmed: Yes / No / N/A
-
Expiry configured: Yes / No / N/A
-
Logging confirmed: Yes / No / N/A
Implementation date: ____________________
Evidence/ticket: ____________________
Review
Last review: ____________________
Next review: ____________________
-
Still required: Yes / No
-
Permissions still appropriate: Yes / No
Removal
Access removal date: ____________________
Removed by: ____________________
Evidence: ____________________
Practical Rule
Vendor access should be named, approved, limited, protected, reviewed, and removed when no longer required.