{"id":5011,"date":"2023-10-10T10:54:29","date_gmt":"2023-10-10T14:54:29","guid":{"rendered":"https:\/\/www.trincoll.edu\/lits\/help-support\/security\/information-technology-policies-procedures\/third-party-vendor-risk-assessments\/"},"modified":"2026-08-05T11:18:19","modified_gmt":"2026-08-05T15:18:19","slug":"third-party-vendor-risk-assessments","status":"publish","type":"page","link":"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/third-party-vendor-risk-assessments\/","title":{"rendered":"Architecture and Security Risk Review"},"content":{"rendered":"<p>The Architecture and Security Risk Review (ASR) at Trinity College is designed to evaluate and manage risks associated with third-party vendors. This process ensures that any external entity handling Trinity College\u2019s data complies with our security and privacy standards, safeguarding the confidentiality, integrity, and availability of our information<\/p>\n<h2>Do I Need an ASR?<\/h2>\n<p>If your department is planning to purchase, renew, implement, or use a technology product or service, you may need an Architecture and Security Risk Review (ASR) before moving forward. Submit a request if the product or vendor will:<\/p>\n<ul>\n<li>Store, process, or access <a href=\"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/information-technology-policies-procedures\/data-classification-collaboration\/data-classification\/\">Trinity College data<\/a><\/li>\n<li>Require login using Trinity credentials or integrate with existing Trinity systems (e.g., Banner, Slate, Microsoft 365)<\/li>\n<li>Handle student, employee, financial, research, or other sensitive information<\/li>\n<li>Include artificial intelligence (AI), machine learning, or generative AI features<\/li>\n<li>Require a contract, purchase order, subscription, or terms of service agreement<\/li>\n<\/ul>\n<p><strong>Not sure if your request qualifies? Submit anyway.<\/strong> The Information Security team will help determine the appropriate level of review.<\/p>\n<h2>Before You Submit<\/h2>\n<p>Having the following information ready will help ensure a smooth and timely review. You do not need everything on day one, but the more you can provide upfront, the faster the process moves.<\/p>\n<ul>\n<li>Vendor name and product or service name<\/li>\n<li>Business purpose and intended use<\/li>\n<li>Your department and expected implementation or go-live date<\/li>\n<li>Contract, quote, proposal, or order form (if available)<\/li>\n<li>Vendor security documentation (HECVAT, SOC 2 report, ISO 27001 certificate, etc.)<\/li>\n<li>Description of what <a href=\"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/information-technology-policies-procedures\/data-classification-collaboration\/data-classification\/\">Trinity data<\/a> the vendor will access, store, or process<\/li>\n<li>Whether the product includes AI capabilities or data processing features<\/li>\n<\/ul>\n<p>Having the vendor complete the Higher Education Community Vendor Assessment Tool (HECVAT) helps the Information Security team review vendor security and privacy practices faster, reducing delays in approval and implementation. <strong>Most vendors who work with higher education institutions already have a completed HECVAT on fil<\/strong>e, as it is a widely recognized standard across colleges and universities. If they do not have a HECVAT, a SOC 2 report or equivalent security documentation is an acceptable alternative.<\/p>\n<p><a href=\"https:\/\/www.trincoll.edu\/lits\/technology\/security\/services\/third-party-vendor-risk-assessments\/higher-education-community-vendor-assessment-toolkit-hecvat\/\"><strong>Learn how to complete and submit the HECVAT with your request<\/strong><\/a><\/p>\n<h2>Purpose<\/h2>\n<p>The Architecture and Security Risk Review (ASR) at Trinity College is designed to evaluate and manage risks associated with third-party vendors. This process ensures that any external entity handling Trinity College&#8217;s data complies with our security and privacy standards, safeguarding the confidentiality, integrity, and availability of our information.<\/p>\n<h2>Why It Matters<\/h2>\n<p>Engaging with third-party vendors introduces potential risks to the institution&#8217;s data and information. Completing an ASR is not optional; it is required before entering into any agreement with a vendor who will handle <a href=\"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/information-technology-policies-procedures\/data-classification-collaboration\/data-classification\/\">Trinity College data<\/a>. This review ensures vendors meet our security standards and keeps the institution compliant with applicable regulations including FERPA, GLBA, HIPAA, the Connecticut Data Privacy Act, and the FTC Safeguards Rule.<\/p>\n<h2>AI-Enabled Products<\/h2>\n<p>If the product includes artificial intelligence features, generative AI, machine learning, AI assistants, or AI-powered data processing, additional review questions will be required as part of the ASR. This applies whether AI is the core function of the product or a secondary feature. Do not activate or enable AI features within a product until the review has been completed.<\/p>\n<h2>Roles and Responsibilities<\/h2>\n<table>\n<thead>\n<tr>\n<th>Role<\/th>\n<th>Responsibility<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Requesting Department \/ Business Unit Sponsor<\/strong><\/td>\n<td>Identifies the need, initiates the request, gathers required documentation, and coordinates with the vendor<\/td>\n<\/tr>\n<tr>\n<td><strong>LITS IT Procurement and Business Services<\/strong><\/td>\n<td>Oversees the procurement process, evaluates vendors, and ensures institutional standards are met<\/td>\n<\/tr>\n<tr>\n<td><strong>Information Security Office (ISO)<\/strong><\/td>\n<td>Reviews security, privacy, and technology risks; provides findings and mitigation recommendations<\/td>\n<\/tr>\n<tr>\n<td><strong>Vendor<\/strong><\/td>\n<td>Provides requested security documentation (e.g., HECVAT, SOC 2) and responds to follow-up questions<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Key Definitions<\/h2>\n<ul>\n<li><strong>Third-Party Vendor<\/strong>: An external company, individual, or service provider that offers products, services, or software interacting with, storing, processing, or transmitting <a href=\"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/information-technology-policies-procedures\/data-classification-collaboration\/data-classification\/\">Trinity College data<\/a>.<\/li>\n<li><strong>Business Unit Sponsor<\/strong>: The individual within a department or business unit who initiates the request to purchase a product, service, or software. The sponsor ensures the product aligns with the unit&#8217;s goals and coordinates the procurement process, including necessary assessments and approvals.<\/li>\n<li><strong>Sensitive Data<\/strong>: Any information protected by law or institutional policy due to its confidential or private nature, such as personally identifiable information (PII), financial records, medical data, and academic records.<\/li>\n<li><strong>LITS IT Procurement and Business Services<\/strong>: The departments responsible for overseeing the procurement process, evaluating potential vendors, and ensuring that technology services, software, and hardware meet Trinity College&#8217;s institutional standards and security requirements.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The Architecture and Security Risk Review (ASR) at Trinity College is designed to evaluate and manage risks associated with third-party vendors. This process ensures that any external entity handling Trinity College\u2019s data complies with our security and privacy standards, safeguarding the confidentiality, integrity, and availability of our information Do I Need an ASR? If your [&hellip;]<\/p>\n","protected":false},"author":336,"featured_media":0,"parent":11137,"menu_order":1,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":true,"footnotes":""},"class_list":["post-5011","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.5 (Yoast SEO v27.8) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Architecture and Security Risk Review - Library &amp; Information Technology Services<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/third-party-vendor-risk-assessments\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Architecture and Security Risk Review\" \/>\n<meta property=\"og:description\" content=\"The Architecture and Security Risk Review (ASR) at Trinity College is designed to evaluate and manage risks associated with third-party vendors. This process ensures that any external entity handling Trinity College\u2019s data complies with our security and privacy standards, safeguarding the confidentiality, integrity, and availability of our information Do I Need an ASR? If your [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/third-party-vendor-risk-assessments\/\" \/>\n<meta property=\"og:site_name\" content=\"Library &amp; Information Technology Services\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-05T15:18:19+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/technology\\\/security\\\/governance-risk-and-compliance\\\/third-party-vendor-risk-assessments\\\/\",\"url\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/technology\\\/security\\\/governance-risk-and-compliance\\\/third-party-vendor-risk-assessments\\\/\",\"name\":\"Architecture and Security Risk Review - Library &amp; Information Technology Services\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/#website\"},\"datePublished\":\"2023-10-10T14:54:29+00:00\",\"dateModified\":\"2026-08-05T15:18:19+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/technology\\\/security\\\/governance-risk-and-compliance\\\/third-party-vendor-risk-assessments\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/technology\\\/security\\\/governance-risk-and-compliance\\\/third-party-vendor-risk-assessments\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/technology\\\/security\\\/governance-risk-and-compliance\\\/third-party-vendor-risk-assessments\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Technology\",\"item\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/technology\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Information Security\",\"item\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/technology\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Governance Risk and Compliance\",\"item\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/technology\\\/security\\\/governance-risk-and-compliance\\\/\"},{\"@type\":\"ListItem\",\"position\":5,\"name\":\"Architecture and Security Risk Review\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/#website\",\"url\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/\",\"name\":\"Library &amp; Information Technology Services\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.trincoll.edu\\\/lits\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Architecture and Security Risk Review - Library &amp; Information Technology Services","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/third-party-vendor-risk-assessments\/","og_locale":"en_US","og_type":"article","og_title":"Architecture and Security Risk Review","og_description":"The Architecture and Security Risk Review (ASR) at Trinity College is designed to evaluate and manage risks associated with third-party vendors. This process ensures that any external entity handling Trinity College\u2019s data complies with our security and privacy standards, safeguarding the confidentiality, integrity, and availability of our information Do I Need an ASR? If your [&hellip;]","og_url":"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/third-party-vendor-risk-assessments\/","og_site_name":"Library &amp; Information Technology Services","article_modified_time":"2026-08-05T15:18:19+00:00","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/third-party-vendor-risk-assessments\/","url":"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/third-party-vendor-risk-assessments\/","name":"Architecture and Security Risk Review - Library &amp; Information Technology Services","isPartOf":{"@id":"https:\/\/www.trincoll.edu\/lits\/#website"},"datePublished":"2023-10-10T14:54:29+00:00","dateModified":"2026-08-05T15:18:19+00:00","breadcrumb":{"@id":"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/third-party-vendor-risk-assessments\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/third-party-vendor-risk-assessments\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/third-party-vendor-risk-assessments\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.trincoll.edu\/lits\/"},{"@type":"ListItem","position":2,"name":"Technology","item":"https:\/\/www.trincoll.edu\/lits\/technology\/"},{"@type":"ListItem","position":3,"name":"Information Security","item":"https:\/\/www.trincoll.edu\/lits\/technology\/security\/"},{"@type":"ListItem","position":4,"name":"Governance Risk and Compliance","item":"https:\/\/www.trincoll.edu\/lits\/technology\/security\/governance-risk-and-compliance\/"},{"@type":"ListItem","position":5,"name":"Architecture and Security Risk Review"}]},{"@type":"WebSite","@id":"https:\/\/www.trincoll.edu\/lits\/#website","url":"https:\/\/www.trincoll.edu\/lits\/","name":"Library &amp; Information Technology Services","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.trincoll.edu\/lits\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.trincoll.edu\/lits\/wp-json\/wp\/v2\/pages\/5011","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.trincoll.edu\/lits\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.trincoll.edu\/lits\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.trincoll.edu\/lits\/wp-json\/wp\/v2\/users\/336"}],"replies":[{"embeddable":true,"href":"https:\/\/www.trincoll.edu\/lits\/wp-json\/wp\/v2\/comments?post=5011"}],"version-history":[{"count":7,"href":"https:\/\/www.trincoll.edu\/lits\/wp-json\/wp\/v2\/pages\/5011\/revisions"}],"predecessor-version":[{"id":13051,"href":"https:\/\/www.trincoll.edu\/lits\/wp-json\/wp\/v2\/pages\/5011\/revisions\/13051"}],"up":[{"embeddable":true,"href":"https:\/\/www.trincoll.edu\/lits\/wp-json\/wp\/v2\/pages\/11137"}],"wp:attachment":[{"href":"https:\/\/www.trincoll.edu\/lits\/wp-json\/wp\/v2\/media?parent=5011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}