Supplier Security Assessment Questionnaire Template for New Zealand
Generate a bespoke document
What is a Supplier Security Assessment Questionnaire?
The Supplier Security Assessment Questionnaire is a critical risk management tool used by organizations in New Zealand to evaluate the security posture of their potential and existing suppliers. This document is designed to ensure compliance with New Zealand's Privacy Act 2020, the Contract and Commercial Law Act 2017, and other relevant regulations. It helps organizations gather comprehensive information about suppliers' security controls, data protection practices, incident response procedures, and compliance status. The questionnaire is particularly important in the context of increasing cyber threats and regulatory requirements for supply chain security. It typically forms part of the vendor due diligence process and may be used both during initial supplier selection and for ongoing supplier monitoring.
About the Supplier Security Assessment Questionnaire
When engaging with suppliers in New Zealand's complex regulatory environment, you need a systematic approach to assess their security capabilities and compliance status. A Supplier Security Assessment Questionnaire provides the structured framework necessary to evaluate potential risks and ensure your organization meets its due diligence obligations under New Zealand law.
When do you need this document?
You should implement a supplier security assessment process whenever you're considering new vendor relationships, particularly those involving access to sensitive data or critical business systems. This is essential when onboarding cloud service providers, software vendors, data processors, or any third-party that will handle customer information or integrate with your IT infrastructure. The assessment becomes critical if you're in regulated industries like banking, healthcare, or government contracting where supplier security directly impacts your compliance obligations. Regular reassessment of existing suppliers is equally important, typically conducted annually or when there are significant changes to their services or your risk profile.
Key legal considerations
Your supplier assessment must address data protection requirements comprehensively, as you remain liable for Privacy Act 2020 compliance even when personal information is processed by third parties. The questionnaire should evaluate the supplier's information security governance, including their policies for data collection, use, storage, and disclosure. Pay particular attention to their incident response procedures and breach notification protocols, as these directly impact your ability to meet the Act's mandatory breach reporting requirements. Consider the supplier's business continuity planning and disaster recovery capabilities, as service disruptions could affect your ability to fulfill contractual obligations under the Contract and Commercial Law Act 2017. If dealing with public sector suppliers, ensure they understand Public Records Act 2005 requirements for information management and retention.
Legal requirements in New Zealand
New Zealand law requires organizations to implement appropriate safeguards when engaging suppliers who will access personal information. Under the Privacy Act 2020, you must ensure suppliers have adequate security measures and only use personal information for authorized purposes. The Contract and Commercial Law Act 2017 governs electronic transactions and requires suppliers to maintain systems that support secure electronic commerce. For suppliers handling public sector information, the Public Records Act 2005 mandates specific record-keeping standards and retention schedules. Your assessment should verify the supplier's understanding of computer crime provisions under the Crimes Act 1961, particularly regarding unauthorized access and data tampering. Additionally, ensure suppliers provide accurate information about their security capabilities, as misleading representations could violate the Fair Trading Act 1986. Document all assessment findings and supplier responses, as these records may be required for regulatory compliance or audit purposes.
GOVERNING LAW
Applicable law
This Supplier Security Assessment Questionnaire is drafted to comply with New Zealand law. Key legislation includes:
Contract and Commercial Law Act 2017: Governs electronic transactions and commercial relationships, relevant for digital security measures and electronic business operations.
Public Records Act 2005: Important for suppliers dealing with public sector organizations, setting requirements for record-keeping and information management.
Crimes Act 1961 (particularly sections relating to computer crimes): Relevant for cybersecurity requirements and legal obligations regarding computer systems and data protection.
Fair Trading Act 1986: Ensures suppliers provide accurate information about their security practices and capabilities.
NZISM (New Zealand Information Security Manual): Though not legislation, it's the NZ government's manual of information assurance and information systems security, providing security standards and guidelines.
Telecommunications (Interception Capability and Security) Act 2013: Relevant for suppliers providing telecommunications services or network security solutions.
Financial Markets Conduct Act 2013: Important for suppliers handling financial data or providing services to financial institutions.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it