Do you have a Vendor Management Policy approved by the Board? I have had a Vendor Management Program (a document used by management) and plan to turn it into a Board-approved Policy since third-party risk is getting so much attention now. Thoughts?
We have a policy and it is reviewed and ratified by the board annually. Personally I agree, whether you call it a program, policy, etc, it's such a "hot button" these days I would involve the board.