Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Vendor security reviews · Public sector & education

Vendor Security Review & Questionnaire Support for Public Agencies & Crown Corporations

Privacy Horizon reviews the SaaS platforms, managed file transfer services and subcontractors a public body relies on, then turns the findings into contract terms and a due-diligence file your audit committee or a ministry reviewer can actually read. Agencies bring us in before a new MFT or citizen-portal vendor is onboarded, after a peer body's vendor becomes the incident everyone is asking about, or when a procurement rule expects proof the vendor was assessed rather than assumed safe.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What a vendor review has to cover in an agency's supply chain

Public bodies buy differently than private companies: procurement rules, central providers and subcontractor chains all sit between your program data and the vendor that ultimately touches it, so a review has to trace further than a single contract.

Managed file transfer platforms

MFT tools move claims, licensing and benefit records between your body, ministries and other vendors, and the Nova Scotia experience showed one compromised platform can expose a jurisdiction's holdings at once.

SaaS behind citizen and case-management portals

Claims systems, licensing platforms and citizen self-service tools are frequently built on a commercial SaaS layer, and its hosting, access model and export terms deserve the same scrutiny as the program itself.

Subcontractors behind the named vendor

The prime contract rarely lists everyone who touches your data; a review traces the subcontractor chain the way regulators now do after the PowerSchool investigation, and asks who the vendor has quietly delegated access to.

Central and shared-service providers

SSC or a provincial data centre may sit beneath your systems without your having selected them, so the exercise shifts from a go/no-go decision to inventorying which service-level and security commitments already exist on paper and where the record falls silent.

Vendors with a path into operational technology

Utilities and transit operators bring in equipment suppliers and remote-maintenance contractors whose access reaches SCADA and control environments, a class of vendor a private-sector review rarely needs to consider.

Regulatory map

Why agencies can't treat vendor vetting as optional

Vendor risk sits inside statutes and central directives that bind a public body directly, so an unreviewed vendor is not just an operational gap, it is a documented compliance question waiting for an auditor or commissioner to ask it.

GO-ITS 25.0 and the OPS Procurement Directive

Ontario agencies work under a directive expecting compliance with the OPS Procurement Directive and alignment with GO-ITS 25.0, whose threat and risk assessment and pre-production testing expectations extend naturally to vendor-delivered systems.

Primary source →

FIPPA's safeguards duty follows the data

Ontario's designated agencies have owed personal information a statutory safeguards duty wherever it sits since mid-2025, which puts a vendor's security posture squarely inside your own compliance obligation rather than a separate question.

Primary source →

FOIPPA's reasonable-security standard

BC's FOIPPA holds Schedule 2 Crowns to a reasonable-security test under s. 30, and the OIPC increasingly wants to know how that test was applied to the vendors a body selected and continues to rely on, not only to systems it runs itself.

Primary source →

Alberta's privacy management program

Required from June 11, 2026, POPA's program presumes documented oversight of the service providers a public body relies on, alongside its own policies, training and breach process.

Primary source →

The CCSPA horizon for designated operators

Parliament passed Bill C-8 into law in mid-2026, and a designated operator under the coming Critical Cyber Systems Protection Act will eventually owe documented assurance over the vendors delivering its critical systems, not only over its own network, once the Act takes effect.

Primary source →

What goes wrong

The vendor failures already documented in this sector

None of the following are hypothetical: each is an incident that reached a Canadian public body through a vendor, subcontractor or shared provider rather than through the institution's own front door.

  • A file-transfer vendor exposing a jurisdiction

    Nova Scotia's MOVEit incident reached close to 100,000 people's SINs, banking and health-card data through one platform, and the resulting investigation is now the standard regulators cite for adequate vendor oversight.

    Source →

  • Subcontractor oversight under the microscope

    The IPC's PowerSchool investigation examined contract terms and oversight practices in detail, and its findings are now the template regulators apply to any public body's vendor and subcontractor relationships.

    Source →

  • A relocation vendor holding personnel records

    The Cyber Centre's threat reporting names Brookfield Global Relocation Services among supplier breaches that reached military and foreign-service personnel data, a reminder that HR-adjacent vendors carry real exposure.

    Source →

  • Compromise arriving through a central provider

    Global Affairs Canada's employees had personal information accessed through an SSC-managed VPN, an incident no vendor questionnaire caught because the dependency itself was never mapped.

    Source →

Our vendor security reviews for public agencies & crown corporations

What the review delivers for your body

The engagement produces a working vendor file, not a one-time report, sized to how procurement actually runs in your organization.

Skilled team of developers using modern technologies for testing application online showing to leader, multiracial young crew of students concentrated on working process watching v
  1. A tiered vendor inventory

    Every SaaS platform, MFT service and subcontractor touching program or case data is listed and ranked by sensitivity, starting with the systems holding the most identifiable and financial information.

  2. Full assessment of the critical tier

    High-sensitivity vendors receive structured review of hosting, access control, encryption, breach history, subcontractor use and exit terms, benchmarked against the standard your government applies.

  3. Contract and security-terms guidance

    Recommended clauses covering breach notification windows, audit rights, subcontractor disclosure, data residency and termination handling, drafted for use in your next agreement or renewal.

  4. Central-provider assurance documentation

    Where you cannot choose the provider, we document what assurances exist today, the gaps in that picture, and the escalation path if that provider's systems are compromised.

  5. Evidence evaluation

    We read the SOC 2 reports, ISO certificates and GO-ITS-style attestations vendors supply, and translate what each actually covers, so a certificate on a cover page does not stand in for a real answer.

  6. A reusable framework for procurement

    Tiering criteria and a review template your procurement team can apply the next time a system is tendered, so vendor vetting becomes routine rather than a scramble before every sign-off.

How the engagement runs

How a review runs inside your procurement cycle

We work with IT, procurement and the privacy office together, so the review lands before a contract is signed rather than after a system is already carrying data.

  1. Step 1

    Build the vendor map

    We inventory every SaaS platform, MFT service, subcontractor and central-provider dependency touching program or case data, and tier each by what it holds.

  2. Step 2

    Assess the critical tier

    Vendors holding the most sensitive data get full assessment against your applicable standard, with follow-up questions where the vendor's documentation falls short.

  3. Step 3

    Turn findings into terms

    Assessment results become specific contract language for the current negotiation or the next renewal, reviewed with your procurement and legal contacts.

  4. Step 4

    Fold review into the procurement cycle

    We hand over a repeatable process timed to the OPS Procurement Directive or your equivalent rules, so future vendor selections carry the same rigour without a fresh engagement each time.

What it costs

What determines vendor review cost for a public body

Effort scales with the size of your vendor estate, how many sit in the critical tier touching program or case data, whether subcontractor chains need tracing, and how much central-provider or OT-adjacent vendor work is in scope. A single-program tribunal with one MFT vendor is a contained engagement; a utility juggling SaaS, field-equipment suppliers and a shared-services dependency is a larger one.

Vendor and agreement review is also part of what our Virtual Privacy Office retainer covers on an ongoing basis, which suits bodies with a steady stream of renewals and new procurements. As a standalone engagement we quote a fixed fee once we have seen your vendor list and current contracts.

Public Agencies & Crown Corporations: Vendor security reviews questions, answered

At minimum: a defined breach-notification window, audit or evidence-request rights, subcontractor disclosure, data residency and retention terms, and a return-or-destruction commitment at contract end. For MFT specifically, add patching and vulnerability-disclosure commitments, given what one platform's maintenance gap cost Nova Scotia. We draft language your procurement team can carry into the next negotiation.

Start by requiring the prime vendor to name every subcontractor with access to your data, not just those in the original proposal; the IPC's PowerSchool investigation showed how much distance can hide behind a signed contract. We extend the same tiering and evidence review to material subcontractors, and push for language giving you visibility when a list changes, rather than finding out after an incident like the Brookfield relocation-vendor breach.

Enough to verify, not so much you never use it: current security documentation on a defined schedule, rights to commission or see results of an independent assessment for high-sensitivity vendors, notice before material changes to subcontractors or hosting, and cooperation during a breach investigation. A vendor that resists all audit language has already given you a finding.

Yes, though the review looks different because you cannot select or replace that provider. We document the assurances currently available, identify the gaps, and build the contingency questions your incident response plan needs, so a compromise like the one Global Affairs Canada experienced through an SSC-managed VPN is a scenario you have already thought through.

The directive shapes how the procurement runs; the review supplies the security substance behind it. We help build evaluation criteria reflecting GO-ITS 25.0 expectations, assess bidder responses on their merits rather than their marketing, and carry the winning vendor's commitments into the contract, so meeting the directive and choosing a genuinely vetted vendor become the same outcome.

That refusal is itself the answer for a high-sensitivity vendor. Options include accepting a lower assurance level with compensating contract terms, requiring a structured questionnaire in place of a report, or walking away before the relationship is signed rather than after your data is inside their systems. For lower-tier vendors, a documented risk acceptance signed by someone with authority may be enough.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.