CyberCode.ph · Philippines

Vendor and SaaS Security Checklist Philippines: What Businesses Should Review

Last updated September 4, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 3, 2026

Direct Answer

Before a Philippine business gives a vendor access to systems, customer data, employee data or critical workflows, it should review the vendor’s security controls and the access being granted. A practical vendor-security review should cover identity, MFA, encryption, logging, backups, vulnerability management, subprocessors, incident response, business continuity, data handling and how access or data will be removed when the relationship ends.

Key Takeaways

  • Review the actual service and data flow, not only the vendor’s marketing page.
  • Require MFA and least-privilege access where available.
  • Know what data the vendor can access and which subcontractors are involved.
  • Document incident-notification and support routes.
  • Plan data export, deletion and account termination before purchase.

1. Identity and access

Ask whether the service supports MFA, SSO, role-based permissions, administrator separation and audit logs. Determine whether vendor support personnel can access your environment and how such access is authorized.

2. Data protection

Identify the data categories involved, encryption in transit and at rest where relevant, retention, backup, export and deletion. If personal data is processed, coordinate the security review with privacy due diligence.

3. Security operations

Review patching, vulnerability management, penetration testing or independent assessments where available. Ask how security issues are reported and remediated.

4. Incident response

Contracts or service terms should provide a practical incident contact and explain notification. Your own incident plan should identify who contacts the vendor and how logs, evidence or emergency access restrictions can be requested.

5. Business continuity and backups

Understand service resilience, backup practices, recovery objectives and what happens during extended outages. Critical workflows may require an alternative manual process or export.

6. Subprocessors and fourth parties

Know whether the vendor relies on other providers that receive data or operate important service components. Changes in subprocessors can change risk.

7. Contract and exit terms

Check data ownership, export formats, termination assistance, deletion, retention after termination and whether fees apply to retrieving your own data.

8. Ongoing review

Risk changes after purchase. Review material security notices, new integrations, administrator access, contract renewals and whether the service remains necessary.

Practical checklist

  • MFA/SSO available
  • Role-based access
  • Audit logging
  • Encryption and data protection
  • Backup/recovery information
  • Incident contact
  • Subprocessor information
  • Data export and deletion process
  • Offboarding plan
  • Periodic review owner

FAQs

Is an ISO certificate enough vendor due diligence?

No. Certifications can be useful evidence, but the business still needs to understand the actual service, data, access and contractual arrangement.

Should small vendors be rejected automatically?

No. Risk should be assessed against the service’s importance and the data involved, not company size alone.

Who should own vendor security reviews?

Security, IT, privacy, legal, procurement and the business owner may all have roles depending on the vendor and risk.

Related Cybercode Guides

Official Sources