Vendor security reviews · Public sector & education
Vendor Security Review & Questionnaire Support for Public Agencies & Crown Corporations
Privacy Horizon reviews the SaaS platforms, managed file transfer services and subcontractors a public body relies on, then turns the findings into contract terms and a due-diligence file your audit committee or a ministry reviewer can actually read. Agencies bring us in before a new MFT or citizen-portal vendor is onboarded, after a peer body's vendor becomes the incident everyone is asking about, or when a procurement rule expects proof the vendor was assessed rather than assumed safe.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What a vendor review has to cover in an agency's supply chain
Public bodies buy differently than private companies: procurement rules, central providers and subcontractor chains all sit between your program data and the vendor that ultimately touches it, so a review has to trace further than a single contract.
Managed file transfer platforms
MFT tools move claims, licensing and benefit records between your body, ministries and other vendors, and the Nova Scotia experience showed one compromised platform can expose a jurisdiction's holdings at once.
SaaS behind citizen and case-management portals
Claims systems, licensing platforms and citizen self-service tools are frequently built on a commercial SaaS layer, and its hosting, access model and export terms deserve the same scrutiny as the program itself.
Subcontractors behind the named vendor
The prime contract rarely lists everyone who touches your data; a review traces the subcontractor chain the way regulators now do after the PowerSchool investigation, and asks who the vendor has quietly delegated access to.
Central and shared-service providers
SSC or a provincial data centre may sit beneath your systems without your having selected them, so the exercise shifts from a go/no-go decision to inventorying which service-level and security commitments already exist on paper and where the record falls silent.
Vendors with a path into operational technology
Utilities and transit operators bring in equipment suppliers and remote-maintenance contractors whose access reaches SCADA and control environments, a class of vendor a private-sector review rarely needs to consider.
Regulatory map
Why agencies can't treat vendor vetting as optional
Vendor risk sits inside statutes and central directives that bind a public body directly, so an unreviewed vendor is not just an operational gap, it is a documented compliance question waiting for an auditor or commissioner to ask it.
GO-ITS 25.0 and the OPS Procurement Directive
Ontario agencies work under a directive expecting compliance with the OPS Procurement Directive and alignment with GO-ITS 25.0, whose threat and risk assessment and pre-production testing expectations extend naturally to vendor-delivered systems.
FIPPA's safeguards duty follows the data
Ontario's designated agencies have owed personal information a statutory safeguards duty wherever it sits since mid-2025, which puts a vendor's security posture squarely inside your own compliance obligation rather than a separate question.
FOIPPA's reasonable-security standard
BC's FOIPPA holds Schedule 2 Crowns to a reasonable-security test under s. 30, and the OIPC increasingly wants to know how that test was applied to the vendors a body selected and continues to rely on, not only to systems it runs itself.
Alberta's privacy management program
Required from June 11, 2026, POPA's program presumes documented oversight of the service providers a public body relies on, alongside its own policies, training and breach process.
The CCSPA horizon for designated operators
Parliament passed Bill C-8 into law in mid-2026, and a designated operator under the coming Critical Cyber Systems Protection Act will eventually owe documented assurance over the vendors delivering its critical systems, not only over its own network, once the Act takes effect.
What goes wrong
The vendor failures already documented in this sector
None of the following are hypothetical: each is an incident that reached a Canadian public body through a vendor, subcontractor or shared provider rather than through the institution's own front door.
A file-transfer vendor exposing a jurisdiction
Nova Scotia's MOVEit incident reached close to 100,000 people's SINs, banking and health-card data through one platform, and the resulting investigation is now the standard regulators cite for adequate vendor oversight.
Subcontractor oversight under the microscope
The IPC's PowerSchool investigation examined contract terms and oversight practices in detail, and its findings are now the template regulators apply to any public body's vendor and subcontractor relationships.
A relocation vendor holding personnel records
The Cyber Centre's threat reporting names Brookfield Global Relocation Services among supplier breaches that reached military and foreign-service personnel data, a reminder that HR-adjacent vendors carry real exposure.
Compromise arriving through a central provider
Global Affairs Canada's employees had personal information accessed through an SSC-managed VPN, an incident no vendor questionnaire caught because the dependency itself was never mapped.
Our vendor security reviews for public agencies & crown corporations
What the review delivers for your body
The engagement produces a working vendor file, not a one-time report, sized to how procurement actually runs in your organization.

A tiered vendor inventory
Every SaaS platform, MFT service and subcontractor touching program or case data is listed and ranked by sensitivity, starting with the systems holding the most identifiable and financial information.
Full assessment of the critical tier
High-sensitivity vendors receive structured review of hosting, access control, encryption, breach history, subcontractor use and exit terms, benchmarked against the standard your government applies.
Contract and security-terms guidance
Recommended clauses covering breach notification windows, audit rights, subcontractor disclosure, data residency and termination handling, drafted for use in your next agreement or renewal.
Central-provider assurance documentation
Where you cannot choose the provider, we document what assurances exist today, the gaps in that picture, and the escalation path if that provider's systems are compromised.
Evidence evaluation
We read the SOC 2 reports, ISO certificates and GO-ITS-style attestations vendors supply, and translate what each actually covers, so a certificate on a cover page does not stand in for a real answer.
A reusable framework for procurement
Tiering criteria and a review template your procurement team can apply the next time a system is tendered, so vendor vetting becomes routine rather than a scramble before every sign-off.
How the engagement runs
How a review runs inside your procurement cycle
We work with IT, procurement and the privacy office together, so the review lands before a contract is signed rather than after a system is already carrying data.
Step 1
Build the vendor map
We inventory every SaaS platform, MFT service, subcontractor and central-provider dependency touching program or case data, and tier each by what it holds.
Step 2
Assess the critical tier
Vendors holding the most sensitive data get full assessment against your applicable standard, with follow-up questions where the vendor's documentation falls short.
Step 3
Turn findings into terms
Assessment results become specific contract language for the current negotiation or the next renewal, reviewed with your procurement and legal contacts.
Step 4
Fold review into the procurement cycle
We hand over a repeatable process timed to the OPS Procurement Directive or your equivalent rules, so future vendor selections carry the same rigour without a fresh engagement each time.
What it costs
What determines vendor review cost for a public body
Effort scales with the size of your vendor estate, how many sit in the critical tier touching program or case data, whether subcontractor chains need tracing, and how much central-provider or OT-adjacent vendor work is in scope. A single-program tribunal with one MFT vendor is a contained engagement; a utility juggling SaaS, field-equipment suppliers and a shared-services dependency is a larger one.
Vendor and agreement review is also part of what our Virtual Privacy Office retainer covers on an ongoing basis, which suits bodies with a steady stream of renewals and new procurements. As a standalone engagement we quote a fixed fee once we have seen your vendor list and current contracts.
Public Agencies & Crown Corporations: Vendor security reviews questions, answered
At minimum: a defined breach-notification window, audit or evidence-request rights, subcontractor disclosure, data residency and retention terms, and a return-or-destruction commitment at contract end. For MFT specifically, add patching and vulnerability-disclosure commitments, given what one platform's maintenance gap cost Nova Scotia. We draft language your procurement team can carry into the next negotiation.
Start by requiring the prime vendor to name every subcontractor with access to your data, not just those in the original proposal; the IPC's PowerSchool investigation showed how much distance can hide behind a signed contract. We extend the same tiering and evidence review to material subcontractors, and push for language giving you visibility when a list changes, rather than finding out after an incident like the Brookfield relocation-vendor breach.
Enough to verify, not so much you never use it: current security documentation on a defined schedule, rights to commission or see results of an independent assessment for high-sensitivity vendors, notice before material changes to subcontractors or hosting, and cooperation during a breach investigation. A vendor that resists all audit language has already given you a finding.
The directive shapes how the procurement runs; the review supplies the security substance behind it. We help build evaluation criteria reflecting GO-ITS 25.0 expectations, assess bidder responses on their merits rather than their marketing, and carry the winning vendor's commitments into the contract, so meeting the directive and choosing a genuinely vetted vendor become the same outcome.
That refusal is itself the answer for a high-sensitivity vendor. Options include accepting a lower assurance level with compensating contract terms, requiring a structured questionnaire in place of a report, or walking away before the relationship is signed rather than after your data is inside their systems. For lower-tier vendors, a documented risk acceptance signed by someone with authority may be enough.
More for public agencies & crown corporations
Other services for this niche
About this service
Answers & guides
- How do you assess the privacy and security risk of an AI vendor?
- What privacy and security assessments are required before selling to government?
- Do you need a TRA before moving sensitive data to a new cloud provider?
- Building a Third-Party Vendor Risk Assessment Program That Scales
- Before You Move Sensitive Data to a New Cloud: The Case for a TRA
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.