| KC-01 S1 | Classify the information the vendor will handle | ISO/IEC 27001:2022 Annex A 5.12 Classification of information | medium |
| KC-01 S2 | Set the supplier tier | ISO/IEC 27001:2022 Annex A 5.19 Information security in supplier relationships or SOC 2 CC9.2 Assessing and managing vendor and business partner risk or SSP-1 Supplier tiering | high |
| KC-01 S3 | Decide whether cloud service requirements apply | ISO/IEC 27001:2022 Annex A 5.23 Information security for use of cloud services | medium |
| KC-01 S4 | Find the contract clause gaps | ISO/IEC 27001:2022 Annex A 5.20 Addressing information security within supplier agreements or SOC 2 CC9.2 Assessing and managing vendor and business partner risk or SSP-3 Contract clauses for Tier 1 | high |
| KC-01 S5 | Assess the vendor's assurance report | ISO/IEC 27001:2022 Annex A 5.19 Information security in supplier relationships or ISO/IEC 27001:2022 Annex A 5.21 Managing information security in the ICT supply chain or ISO/IEC 27001:2022 Annex A 5.22 Monitoring, review and change management of supplier services or SOC 2 CC9.2 Assessing and managing vendor and business partner risk or SSP-4 Accepted assurance | medium |
| KC-01 S6 | Decide the vendor's access | ISO/IEC 27001:2022 Annex A 5.16 Identity management or ISO/IEC 27001:2022 Annex A 5.18 Access rights or ISO/IEC 27001:2022 Annex A 8.2 Privileged access rights or ISO/IEC 27001:2022 Annex A 8.5 Secure authentication or SOC 2 CC6.2 Registering and authorising users before issuing credentials or SOC 2 CC6.3 Role-based access, least privilege and segregation of duties or SSP-5 Supplier access | high |
| KC-01 S7 | Handle the bank detail change email | AP-4 Bank detail changes | high |
| KC-01 S8 | Decide the onboarding outcome | SSP-8 Approval authority or ISO/IEC 27001:2022 Annex A 5.19 Information security in supplier relationships or SOC 2 CC9.2 Assessing and managing vendor and business partner risk | high |
| KC-07 S1 | Is it a material arrangement? | APRA CPS 230 para 48 (register of material service providers) or APRA CPS 230 para 49 (services treated as material) | high |
| KC-07 S2 | Does the para 57 exemption apply? | APRA CPS 230 para 57 (Attachment category exemption) | medium |
| KC-07 S3 | Which clauses are missing? | APRA CPS 230 para 53 (formal agreement contents) or APRA CPS 230 para 54 (APRA access clauses) | high |
| KC-07 S4 | Offshoring: what does APRA need, and when? | APRA CPS 230 para 60 (notify APRA: critical operations and offshoring) | high |
| KC-07 S5 | Security capability before reliance | APRA CPS 234 para 16 (third-party security capability) or APRA CPS 234 para 22 (design of third-party controls) | medium |
| KC-07 S6 | Internal audit | APRA CPS 230 para 61 (internal audit review of proposed arrangements) | medium |
| KC-07 S7 | Approval | SPM-2 Approval of material arrangements or APRA CPS 230 para 52 (due diligence before a material arrangement) | high |