Skip to main content

Supplier Standard Q&A — Security & Due Diligence

For on-premises deployments. Use these standard answers when responding to third-party supplier information forms from bank prospects. Client-specific variations are noted inline.

1. Service Scope and Data Handling

Q: Is the supplier providing a data storage or data processing service where data storage, backup, or processing is the primary function?

A: The service involves processing customer data as part of the solution. However, data storage is not provided as a managed service by the supplier.

Westpac variation: "Yes. The service involves processing of Westpac data; however, data storage is not provided as a managed service by the supplier."

Q: Will the supplier store or process business-critical data as part of the service?

A: The supplier may process business-critical data strictly as required to deliver the service. All data remains under the customer's ownership and control at all times.

Q: What is the nature of access the supplier will have to customer information or systems?

A: Access is limited to application-level access required to operate and support the service. There is no direct access to core systems unless explicitly approved, provisioned, and controlled by the customer.

2. Data Volume and Retention

Q: What is the volume of records accessed or processed by the supplier?

A: The volume of data processed is determined by the customer's use cases and configurations. No customer data is retained outside of customer-controlled environments.

Q: Where is customer data stored?

A: All customer data is stored exclusively within customer-designated environments.

Q: Is customer data stored on the supplier's infrastructure?

A: No. Data remains on customer-managed infrastructure, either on-premises or within the customer's private cloud environment.

3. Hosting and Deployment Model

Q: Is customer data stored in an internet-facing system?

A: No. Deployments can be configured in non-internet-facing environments in accordance with customer security requirements.

Q: Does the supplier provide a cloud (SaaS) service?

A: No. The supplier does not provide a hosted Software-as-a-Service (SaaS) offering.

Q: Does the supplier use any third-party cloud service to store customer data?

A: No. Customer data is not stored in any third-party public cloud operated by the supplier.

4. Security Classification and Controls

Q: What is the provisional security tier for the service?

A: The security tier is determined by the customer based on the deployment model, data classification, and internal risk assessment.

5. Certifications and Compliance

Q: Does the supplier hold ISO 27001 / ISO 27002 certification?

A: Yes. The organisation is certified to ISO 27001.

Q: Is the ISO certification applicable to the service being provided?

A: Yes. The ISO 27001 certification covers the organisation and the operational scope under which the service is delivered.

Q: Is the certification applicable to the locations where the service is delivered?

A: Yes. ISO 27001 certification applies to the organisation's operational locations relevant to service delivery.

Q: Can the ISO 27001 certificate be provided?

A: Yes. Certification documentation can be provided upon request.

6. Assurance and Independent Testing

Q: Does the supplier have a SOC 2 Type II report for the service?

A: As the solution is deployed on customer-managed infrastructure (on-premises or customer private cloud), a SOC 2 Type II report is not applicable. Customers retain full responsibility for the security, availability, and compliance of the underlying infrastructure.

Standard short form (where forms require a Yes/No): No. A SOC 2 Type II report is not currently available for on-premises deployments.

Q: Can the supplier provide independent penetration testing reports?

A: Yes. Independent penetration testing reports can be made available upon request, subject to confidentiality and NDA requirements.