The Architecture and Security Risk Review (ASR) at Trinity College is designed to evaluate and manage risks associated with third-party vendors. This process ensures that any external entity handling Trinity College’s data complies with our security and privacy standards, safeguarding the confidentiality, integrity, and availability of our information

Do I Need an ASR?

If your department is planning to purchase, renew, implement, or use a technology product or service, you may need an Architecture and Security Risk Review (ASR) before moving forward. Submit a request if the product or vendor will:

  • Store, process, or access Trinity College data
  • Require login using Trinity credentials or integrate with existing Trinity systems (e.g., Banner, Slate, Microsoft 365)
  • Handle student, employee, financial, research, or other sensitive information
  • Include artificial intelligence (AI), machine learning, or generative AI features
  • Require a contract, purchase order, subscription, or terms of service agreement

Not sure if your request qualifies? Submit anyway. The Information Security team will help determine the appropriate level of review.

Before You Submit

Having the following information ready will help ensure a smooth and timely review. You do not need everything on day one, but the more you can provide upfront, the faster the process moves.

  • Vendor name and product or service name
  • Business purpose and intended use
  • Your department and expected implementation or go-live date
  • Contract, quote, proposal, or order form (if available)
  • Vendor security documentation (HECVAT, SOC 2 report, ISO 27001 certificate, etc.)
  • Description of what Trinity data the vendor will access, store, or process
  • Whether the product includes AI capabilities or data processing features

Having the vendor complete the Higher Education Community Vendor Assessment Tool (HECVAT) helps the Information Security team review vendor security and privacy practices faster, reducing delays in approval and implementation. Most vendors who work with higher education institutions already have a completed HECVAT on file, as it is a widely recognized standard across colleges and universities. If they do not have a HECVAT, a SOC 2 report or equivalent security documentation is an acceptable alternative.

Learn how to complete and submit the HECVAT with your request

Purpose

The Architecture and Security Risk Review (ASR) at Trinity College is designed to evaluate and manage risks associated with third-party vendors. This process ensures that any external entity handling Trinity College’s data complies with our security and privacy standards, safeguarding the confidentiality, integrity, and availability of our information.

Why It Matters

Engaging with third-party vendors introduces potential risks to the institution’s data and information. Completing an ASR is not optional; it is required before entering into any agreement with a vendor who will handle Trinity College data. This review ensures vendors meet our security standards and keeps the institution compliant with applicable regulations including FERPA, GLBA, HIPAA, the Connecticut Data Privacy Act, and the FTC Safeguards Rule.

AI-Enabled Products

If the product includes artificial intelligence features, generative AI, machine learning, AI assistants, or AI-powered data processing, additional review questions will be required as part of the ASR. This applies whether AI is the core function of the product or a secondary feature. Do not activate or enable AI features within a product until the review has been completed.

Roles and Responsibilities

Role Responsibility
Requesting Department / Business Unit Sponsor Identifies the need, initiates the request, gathers required documentation, and coordinates with the vendor
LITS IT Procurement and Business Services Oversees the procurement process, evaluates vendors, and ensures institutional standards are met
Information Security Office (ISO) Reviews security, privacy, and technology risks; provides findings and mitigation recommendations
Vendor Provides requested security documentation (e.g., HECVAT, SOC 2) and responds to follow-up questions

Key Definitions

  • Third-Party Vendor: An external company, individual, or service provider that offers products, services, or software interacting with, storing, processing, or transmitting Trinity College data.
  • Business Unit Sponsor: The individual within a department or business unit who initiates the request to purchase a product, service, or software. The sponsor ensures the product aligns with the unit’s goals and coordinates the procurement process, including necessary assessments and approvals.
  • Sensitive Data: Any information protected by law or institutional policy due to its confidential or private nature, such as personally identifiable information (PII), financial records, medical data, and academic records.
  • LITS IT Procurement and Business Services: The departments responsible for overseeing the procurement process, evaluating potential vendors, and ensuring that technology services, software, and hardware meet Trinity College’s institutional standards and security requirements.

How the Process Works

The process begins when a business unit or department identifies the need for a third-party product, service, or software. If the product involves processing, storing, or transmitting Trinity College’s data, it should not be purchased or committed to until the need is reviewed and confirmed as unique.

Upon identifying the need, the business unit sponsor contacts the LITS IT Procurement and Business Services to initiate the risk assessment process. This involves completing a Third-Party Vendor Risk Assessment Questionnaire and submitting any relevant documentation.

The submitted materials are reviewed by the Information Security Office (ISO) to assess potential risks associated with the vendor. This evaluation considers factors such as data handling practices, security measures, compliance with relevant regulations, and the vendor’s overall security posture.

Based on the assessment, the ISO provides recommendations to mitigate identified risks. These may include contractual clauses, security controls, or alternative solutions to address potential vulnerabilities.

Once all risks are addressed and mitigated, the vendor engagement can proceed. The business unit sponsor, in collaboration with LITS IT Procurement and Business Services, finalizes the procurement process, ensuring all necessary approvals are obtained.

Ready to move forward?

Submit your request below and the Information Security team will guide you through the rest.

Submit a Request

Please Note: Departments must ensure that any technology product or service involving the transmitting, accessing, or storing of customer information subject to the Gramm Leach Bliley Act (GLBA), as well as all technology additions, major architecture changes, and updated contract terms, must go through an ASR. The GLBA applies to the college in connection with financial activities. Customer information is any record containing non-public personal information about recipients of college, whether in paper, electronic, or other form, that is handled or maintained by or on behalf of the college.

Frequently Asked Questions (FAQs)

The ASR is Trinity College’s process for evaluating third-party vendors to ensure they meet the institution’s security and privacy standards before handling any college data.

The business unit sponsor—typically the department requesting the product or service—initiates the review by contacting LITS IT Procurement and Business Services.

An ASR is required whenever a vendor will process, store, or transmit Trinity College data, when integrating third-party products into existing systems, or when entering new contracts involving sensitive or regulated data.

Sensitive data includes any information protected by law or college policy, such as personally identifiable information (PII), financial records, medical records, or academic records.

The Higher Education Community Vendor Assessment Tool (HECVAT) helps vendors document their security and privacy practices, enabling faster review and reducing delays in approvals.

The Information Security Office reviews the submitted materials, recommends risk mitigation strategies, and works with the business unit sponsor to address any concerns before final approval and onboarding.

The Information Security Office (ISO) evaluates potential risks, security controls, and regulatory compliance to ensure the vendor meets Trinity College standards.

No. Any vendor handling Trinity College data should not be purchased or contracted until the ASR is complete and all risks have been addressed.