top of page

xBxBio Third-Party & Supplier Risk Management Policy

Effective Date: June 3, 2025

Last Updated: October 5, 2026

​

1. Purpose and Public Assurance

This policy establishes xBxBio's public-facing principles for identifying, evaluating, engaging, governing, monitoring, changing, and offboarding third parties and suppliers whose products, services, personnel, data access, technology, facilities, or other dependencies may affect xBxBio, its customers, patients, research activities, or regulated obligations. Its purpose is to provide assurance that supplier relationships are governed according to risk and are not treated as unmanaged extensions of the xBxBio environment.

​

2. Public Disclosure Boundary

This is a governance and assurance policy, not a supplier inventory, security architecture document, procurement manual, or technical integration specification. Public disclosure is intentionally limited to risk, privacy, security, quality, clinical-safety, continuity, legal, regulatory, and governance principles. Supplier identities, commercial terms, technical configurations, credentials, integration details, security findings, internal scoring methods, and other confidential or security-sensitive information are maintained separately under appropriate controls.

​

3. Scope

This policy applies, as appropriate, to current and future vendors, suppliers, contractors, consultants, subprocessors, service providers, cloud and hosting providers, software and data providers, laboratories, device-related providers, integration partners, research collaborators, professional-services providers, and other external parties used by or on behalf of xBxBio.

​

4. Technology-Neutral and Future-Capability Scope

The absence of a particular vendor, product class, service model, technology, country, data category, device, modality, interface, or delivery method from an illustrative list does not by itself exclude a third-party relationship from this policy where the relationship falls within the defined scope.

​

5. Risk-Based Supplier Governance

Supplier governance should be proportionate to reasonably foreseeable risk, including the sensitivity of information involved, access level, service criticality, clinical or patient impact, regulatory significance, integration depth, recoverability, concentration risk, substitutability, and potential consequences of supplier failure or compromise.

​

6. Definitions and Interpretation

A third party or supplier is an external organization or individual providing goods, services, technology, data, access, facilities, expertise, or other capabilities to xBxBio or in support of xBxBio activities. A subprocessor or downstream provider is a party engaged by another supplier to perform relevant services or processing.

​

7. Governance

Third-party and supplier risk should operate under defined governance with assigned responsibilities for business ownership, procurement, security, privacy, legal, quality, clinical, technology, compliance, and other functions as appropriate to the relationship.

​

8. Business Ownership

Each material supplier relationship should have an accountable xBxBio owner or sponsoring function responsible for the business need, expected service, relationship oversight, material changes, and escalation of unresolved supplier issues.

​

9. Segregation of Responsibilities

Supplier selection, technical evaluation, security and privacy review, contracting, approval, access provisioning, invoice or commercial administration, and ongoing monitoring should use appropriate separation of duties where warranted by risk.

​

10. Supplier Inventory

xBxBio should maintain an appropriate inventory of relevant third-party and supplier relationships sufficient to support governance, risk assessment, ownership, lifecycle management, and response to material changes or incidents.

​

11. Supplier Classification

Suppliers should be classified or tiered using risk-relevant characteristics such as access to regulated or sensitive information, service criticality, patient or clinical impact, operational dependence, privileged access, hosting or processing role, and potential effect on regulated activities.

​

12. Critical Suppliers

Suppliers whose failure, compromise, delay, or unavailability could materially affect patient safety, essential operations, regulated records, data integrity, privacy, security, or contractual commitments should receive heightened governance appropriate to that risk.

​

13. Due Diligence

Risk-appropriate due diligence should be performed before material supplier engagement and should consider the supplier's ability to meet relevant security, privacy, quality, continuity, legal, regulatory, operational, and service expectations.

​

14. Security Due Diligence

Security review should consider, as appropriate, the supplier's governance, access controls, data protection, vulnerability management, monitoring, incident response, resilience, software or service security practices, and other controls relevant to the contemplated service without requiring public disclosure of detailed security architecture.

​

15. Privacy Due Diligence

Privacy review should consider the nature of personal information involved, processing purpose, roles and responsibilities, geographic considerations, onward transfers, retention, deletion, individual-rights support, incident notification, and applicable contractual safeguards.

​

16. Quality Due Diligence

Where supplier activities can affect product, service, data, analytical, validation, research, or regulated quality, due diligence should evaluate whether the supplier can support applicable quality expectations, records, change controls, corrective actions, and evidence requirements.

​

17. Clinical-Safety Due Diligence

Where a supplier can affect clinically relevant information, devices, interfaces, workflows, analytics, or patient-facing or clinician-facing functions, the relationship should be assessed for reasonably foreseeable patient-safety and human-oversight implications.

​

18. Operational Due Diligence

Operational review should consider capacity, availability, support, service management, dependency risks, recovery capability, geographic constraints, change practices, and other factors that could materially affect reliable service delivery.

​

19. Contractual Controls

Material supplier relationships should be supported by written terms appropriate to the service and risk. Contracts should address relevant responsibilities, confidentiality, data protection, security, service expectations, incident notification, audit or assurance rights, change, subcontracting, termination, and other obligations as appropriate.

​

20. Confidentiality

Suppliers with access to confidential information should be subject to confidentiality obligations appropriate to the information and relationship, including restrictions on unauthorized use or disclosure.

​

21. Data Protection Terms

Where a supplier processes personal information for or on behalf of xBxBio, appropriate contractual data-protection terms should define processing instructions, safeguards, permitted uses, retention, deletion or return, assistance obligations, and other requirements applicable to the relationship.

​

22. HIPAA Business Associate Arrangements

Where a supplier relationship creates a business-associate or subcontractor relationship under HIPAA, xBxBio should use appropriate written arrangements addressing permitted uses and disclosures, safeguards, reporting, downstream obligations, and return or destruction of protected health information, as applicable.

​

23. Processor and Subprocessor Arrangements

Where privacy law requires controller-processor or processor-subprocessor terms, xBxBio should use appropriate contractual provisions governing processing instructions, confidentiality, security, subprocessors, assistance, international transfers, deletion or return, and compliance support.

​

24. Regulated Quality Agreements

Where supplier activities materially affect regulated quality responsibilities, xBxBio should establish quality-related responsibilities in contracts, quality agreements, statements of work, or other controlled arrangements appropriate to the relationship.

​

25. Service-Level Expectations

Where service performance is material, contracts or service documents should define appropriate expectations for availability, support, responsiveness, restoration, communication, and other measurable service obligations without implying that all services require identical targets.

​

26. Security Requirements

Supplier agreements should include security obligations proportionate to risk, including protection of credentials and data, access control, incident reporting, personnel safeguards, vulnerability and patch expectations, secure change practices, and cooperation with investigations where applicable.

​

27. Incident Notification

Suppliers should be required, as appropriate, to notify xBxBio of suspected or confirmed incidents that may affect xBxBio information, systems, customers, patients, services, or obligations within timeframes suitable to the risk and applicable legal or contractual requirements.

​

28. Breach Cooperation

Where a supplier incident may involve personal information or protected health information, the supplier should cooperate with reasonable investigation, risk assessment, evidence preservation, notification, remediation, and regulatory-response activities appropriate to its role.

​

29. Subcontractor Governance

Material subcontracting or subprocessing should be governed according to risk. Suppliers should remain accountable for applicable obligations assigned to them and should impose relevant protections on downstream providers where required.

​

30. Subprocessor Transparency

Where required by law, contract, or risk, xBxBio should maintain appropriate visibility into material sub-processors or downstream providers and address notification, objection, approval, or contractual requirements applicable to changes.

​

31. Data Location and International Transfers

Supplier relationships involving cross-border processing or storage should be assessed for applicable data-location, transfer-mechanism, contractual, regulatory, customer, and security requirements.

​

32. Minimum Necessary Access

Supplier access to xBxBio information, systems, facilities, and services should be limited to what is reasonably necessary for authorized responsibilities and should not be broader or longer-lived than required.

​

33. Identity and Access Management

Supplier identities and access should be governed using appropriate authentication, authorization, approval, review, modification, and revocation controls proportionate to the sensitivity and privilege of the access.

​

34. Privileged Access

Third-party privileged or administrative access should receive heightened authorization, monitoring, time limitation, or other controls appropriate to risk and should not be treated as ordinary user access.

​

35. Remote Access

Remote supplier access should be authorized, protected, and monitored according to risk, with access methods and permissions appropriate to the service and without public disclosure of internal remote-access architecture.

​

36. Access Reviews

Supplier access should be reviewed periodically and upon significant role, contract, service, or organizational changes to confirm continuing business need and appropriate privilege.

​

37. Termination of Access

Supplier access should be revoked or adjusted promptly when no longer required, including upon termination, contract expiration, role change, personnel departure, or material change in service.

​

38. Data Minimization

Suppliers should receive only the data reasonably necessary for authorized purposes. Collection, transfer, duplication, and retention of information should be limited according to applicable legal, contractual, operational, and privacy requirements.

​

39. Purpose Limitation

Supplier use of xBxBio or customer information should be limited to authorized purposes and should not be expanded to unrelated uses without appropriate review and authorization.

​

40. Data Segregation

Where relevant, suppliers should use appropriate measures to preserve separation among customers, tenants, projects, research activities, environments, or other logically distinct data populations.

​

41. Encryption and Protection of Data

Suppliers handling sensitive information should use protection appropriate to the risk and applicable requirements during storage and transmission. Specific cryptographic implementations are managed outside this public policy.

​

42. Data Integrity

Supplier controls should support accuracy, completeness, authorized modification, traceability, version awareness, and other data-integrity needs appropriate to the service, particularly where information contributes to clinical, scientific, quality, or regulated decisions.

​

43. Provenance

Where source identity, lineage, timestamp, transformation history, version, or other provenance information is material to interpretation or auditability, supplier-supported workflows should preserve or provide that context as appropriate.

​

44. Retention and Deletion

Supplier retention of xBxBio, customer, patient, research, or other controlled information should follow applicable instructions, contracts, legal requirements, holds, and approved retention schedules. Secure deletion or return should occur when required and reasonably verifiable.

​

45. Backup and Recovery

Material suppliers should maintain backup, restoration, or recovery capabilities appropriate to the services they provide and the information they handle, where such capabilities are relevant to continuity and recoverability.

​

46. Business Continuity

Critical suppliers should maintain continuity arrangements proportionate to the potential impact of disruption and should support reasonable coordination with xBxBio continuity and recovery activities where dependencies are material.

​

47. Disaster Recovery

Where a supplier provides critical technology or processing, recovery arrangements should be evaluated for their ability to support service restoration, data int

egrity, secure recovery, communication, and customer obligations appropriate to the relationship.

​

48. Concentration Risk

xBxBio should consider whether excessive dependence on a single provider, technology, geography, platform, subcontractor chain, or service class could create disproportionate operational, security, privacy, or continuity risk.

​

49. Fourth-Party Risk

Where material services depend on downstream providers, xBxBio should consider significant fourth-party dependencies to the extent reasonably identifiable and relevant to risk, while recognizing that visibility may vary by service model and contract.

​

50. Supply-Chain Security

Supplier governance should consider risks introduced through software, services, components, updates, dependencies, build or distribution processes, and other elements of the technology supply chain appropriate to the services used by xBxBio.

​

51. Software Components and Dependencies

Third-party software, libraries, packages, services, and components should be governed according to risk, licensing, maintenance, security, provenance, and support considerations relevant to their intended use.

​

52. Software Bill of Materials Support

Where appropriate to the product, service, contract, or regulatory context, xBxBio may require suppliers to provide software-component transparency or related evidence sufficient to support vulnerability, lifecycle, and supply-chain risk management.

​

53. Open-Source Dependencies

Open-source components used by suppliers or within supplier-provided solutions should be managed according to applicable licensing, security, maintenance, provenance, and vulnerability considerations without requiring public disclosure of internal component inventories.

​

54. Vulnerability Management

Material technology suppliers should maintain vulnerability-management practices appropriate to their services, including identification, assessment, remediation, communication, and risk-based handling of material vulnerabilities.

​

55. Patch and Update Practices

Supplier patching and update practices should be assessed where delayed, uncoordinated, or unsupported changes could materially affect security, availability, compatibility, validation, clinical behavior, or regulated state.

​

56. Secure Development Expectations

Where a supplier develops software or technology relevant to xBxBio, xBxBio should evaluate whether the supplier uses risk-appropriate secure-development, review, testing, change, and release practices.

​

57. Change Notification

Suppliers should provide reasonable notice of material changes when those changes could affect security, privacy, service, compatibility, data location, subprocessors, clinical behavior, validated state, or other material obligations.

​

58. Change Assessment

Material supplier changes should be evaluated by xBxBio for downstream impact before or as part of adoption, including effects on interfaces, workflows, data, privacy, security, quality, clinical context, continuity, and customer commitments.

​

59. Validation and Verification Support

Where supplier products or services support regulated, quality-controlled, or clinically relevant functions, xBxBio should obtain or generate evidence sufficient to support applicable validation, verification, qualification, or assurance activities.

​

60. Audit and Assurance Rights

Contracts should provide risk-appropriate rights to obtain assurance regarding supplier controls, performance, compliance, incidents, or remediation, which may include certifications, reports, questionnaires, evidence review, audits, or other reasonable mechanisms.

​

61. Independent Assurance

Independent certifications, audit reports, assessments, or attestations may inform supplier due diligence but should not be treated as conclusive proof that every control, use case, deployment, or regulatory obligation is satisfied.

​

62. Monitoring

Material suppliers should be monitored during the relationship using risk-appropriate information such as service performance, incidents, control changes, assurance reports, complaints, audit findings, regulatory developments, vulnerability information, or other relevant indicators.

​

63. Periodic Reassessment

Supplier risk should be reassessed periodically and following material events such as major service changes, incidents, acquisitions, new subprocessors, regulatory changes, significant performance problems, or expansion of data or access.

​

64. Performance Management

Supplier performance should be reviewed against applicable contractual, service, quality, security, privacy, and operational expectations, with material deviations escalated and addressed proportionately.

​

65. Issue Management

Supplier issues should be documented, assigned, tracked, escalated, and closed according to significance. Unresolved material issues should inform continued use, compensating controls, contract decisions, or transition planning.

​

66. Corrective Action

When supplier deficiencies create material risk, xBxBio should seek appropriate remediation, corrective action, risk acceptance, service limitation, transition, or termination according to severity and applicable obligations.

​

67. Supplier Incidents

Supplier incidents that may affect xBxBio should be governed under xBxBio's incident-response processes, with coordinated investigation, containment, communication, evidence, recovery, notification, and corrective action appropriate to the event.

​

68. Security Incident Coordination

Material security incidents involving suppliers should be escalated promptly to appropriate xBxBio security, privacy, legal, operational, quality, and executive functions according to the nature and potential effect of the event.

​

69. Privacy Incident Coordination

Supplier privacy incidents should be assessed for affected information, individuals, jurisdictions, contractual roles, breach-notification requirements, downstream processing, and other privacy obligations appropriate to the facts.

​

70. Clinical-Safety Escalation

Supplier events that could affect patient safety, clinically relevant information, medical-device interfaces, alerts, source evidence, timing, patient identity, or clinician interpretation should be escalated to appropriate clinical and quality oversight.

​

71. Quality Event Coordination

Supplier deficiencies that may create nonconformity, complaint, validation concern, data-integrity issue, regulated record problem, or other quality-system impact should be coordinated with applicable quality processes.

​

72. Regulatory Cooperation

Suppliers should provide reasonable cooperation with regulatory inquiries, inspections, notifications, records, investigations, or corrective actions where their services or conduct are relevant and such cooperation is required by law, contract, or applicable regulatory responsibility.

​

73. Customer and Partner Obligations

Supplier governance should support xBxBio's applicable commitments to customers, partners, research organizations, healthcare entities, and other authorized stakeholders without transferring responsibilities that remain with xBxBio.

​

74. Patient and Individual Rights Support

Where suppliers process personal information, contractual and operational arrangements should support xBxBio's ability to respond to applicable access, correction, deletion, restriction, portability, complaint, or other individual-rights obligations as appropriate to xBxBio's role.

​

75. Records and Evidence

Supplier assessments, approvals, contracts, assurances, incidents, changes, exceptions, corrective actions, and other governance evidence should be maintained under document and record controls appropriate to their purpose, sensitivity, retention, and regulatory significance.

​

76. Auditability

Supplier-risk activities should be sufficiently documented to support internal governance, customer assurance, quality review, legal obligations, regulatory inquiry, and continual improvement.

​

77. Exceptions

Exceptions to supplier requirements should be documented, risk-assessed, approved by authorized roles, time-limited where appropriate, and subject to compensating controls or follow-up proportionate to the risk.

​

78. Risk Acceptance

Residual supplier risk that cannot reasonably be eliminated should be explicitly evaluated and accepted by appropriately authorized xBxBio roles based on the nature, magnitude, duration, and potential consequences of the risk.

​

79. Use of Customer-Selected Suppliers

Where a customer requires or selects a particular third party, responsibilities, technical dependencies, data flows, risk ownership, and limitations should be clarified. Customer selection does not automatically remove xBxBio's obligations for activities that remain under xBxBio control.

​

80. Customer-Managed Environments

Where suppliers or integrations operate within customer-managed environments, xBxBio and the customer should clarify responsibilities for access, security, availability, configuration, support, monitoring, incident response, and change management as appropriate.

​

81. Cloud Service Providers

Cloud and hosted-service providers should be governed according to the nature of the service, shared-responsibility model, information involved, geographic scope, criticality, security capabilities, continuity dependencies, and contractual obligations.

​

82. Clinical and Device Ecosystem Suppliers

Suppliers supporting clinical systems, medical devices, imaging, ECG, laboratory, wearable, implantable, remote-monitoring, or other healthcare data sources should be evaluated for interface reliability, data meaning, provenance, safety, security, change, support, and continuity appropriate to their role.

​

83. Laboratory and Data Providers

Laboratories and external data providers should be governed for relevant data quality, identity, provenance, timeliness, transmission, correction, security, privacy, and change considerations appropriate to the information supplied.

​

84. Research Collaborators

Research collaborators and external research service providers should be governed according to applicable study requirements, data-use restrictions, privacy, security, consent, protocol, ethics, publication, retention, and other obligations relevant to the collaboration.

​

85. AI and Model Providers

Where xBxBio uses externally provided AI, model, analytical, or inference services, supplier governance should consider data use, confidentiality, training or secondary-use restrictions, output limitations, provenance, versioning, change, safety, monitoring, and human oversight appropriate to the intended use.

​

86. Generative AI Services

Externally provided generative AI services should be assessed for information handling, retention, training or secondary use, access, output reliability, security, privacy, contractual restrictions, and other risks relevant to the contemplated use.

​

87. Personnel Screening and Training

Where supplier personnel receive sensitive access or perform material regulated activities, xBxBio should consider whether appropriate screening, confidentiality, training, competency, and supervision requirements are addressed according to role and applicable law.

​

88. Business Changes and Acquisitions

Material supplier mergers, acquisitions, ownership changes, insolvency, divestitures, or restructuring should trigger reassessment where they may affect service, control environment, data ownership, regulatory roles, contracts, continuity, or concentration risk.

​

89. End-of-Life and Service Discontinuation

Supplier product end-of-life, support termination, service discontinuation, or material deprecation should be identified and managed early enough to support transition, validation, data preservation, customer communication, and continuity where relevant.

​

90. Exit Planning

Critical supplier relationships should have exit or transition considerations proportionate to the potential impact of termination, including data return or deletion, access revocation, migration, replacement, records, continuity, and unresolved obligations.

​

91. Offboarding

Supplier offboarding should address access removal, credential revocation, asset return, data disposition, contract closure, records retention, open issues, transition support, and confirmation of continuing confidentiality or other surviving obligations.

​

92. Data Return and Destruction

At relationship end or when otherwise required, supplier-held information should be returned, transferred, deleted, or destroyed in accordance with applicable instructions, contracts, legal requirements, retention obligations, and technical feasibility.

​

93. Continuing Obligations

Termination of a supplier relationship does not eliminate obligations that survive termination, such as confidentiality, data protection, records retention, incident cooperation, legal holds, or regulatory duties where applicable.

​

94. Framework Alignment

xBxBio may use recognized frameworks and standards, as applicable, to inform third-party and supplier risk governance, including NIST Cybersecurity Framework 2.0, NIST cybersecurity supply-chain risk-management guidance, ISO/IEC 27001 and related supplier-security practices, privacy frameworks, quality-system expectations, and contractual requirements. Alignment does not by itself constitute certification or regulatory approval.

​

95. Relationship to IT & Security Policy

This policy complements xBxBio's IT & Security Policy by extending security governance to external organizations and services that can affect xBxBio information, systems, operations, or customers.

​

96. Relationship to Privacy Policy

This policy complements xBxBio's Privacy Policy by governing processors, subprocessors, data transfers, supplier access, retention, deletion, and other external-party handling of personal information.

​

97. Relationship to Quality Policy

This policy complements xBxBio's Quality Policy where supplier products or services can affect quality, validation, regulated records, complaints, corrective action, or other controlled activities.

​

98. Relationship to Clinical Safety & Human Oversight Policy

This policy complements xBxBio's Clinical Safety & Human Oversight Policy when third-party products, services, data, devices, integrations, or analytics could affect patient safety, clinical meaning, or human decision-making.

​

99. Relationship to Business Continuity Policy

This policy complements xBxBio's Business Continuity, Disaster Recovery & Operational Resilience Policy by addressing external dependencies that can affect availability, recoverability, restoration, concentration risk, and continuity.

​

100. Relationship to Incident Response Policy

This policy complements xBxBio's Incident Response & Breach Management Policy by defining supplier expectations for notification, cooperation, evidence, investigation, recovery, remediation, and regulatory support when material incidents occur.

​

101. Relationship to Compliance & Regulatory Policy

Supplier governance should be coordinated with xBxBio's Compliance & Regulatory Policy so that applicable healthcare, privacy, security, quality, contractual, and jurisdictional requirements are identified and assigned appropriately.

​

102. Public Information Boundary

This public policy explains governance principles without disclosing xBxBio's supplier list, commercial negotiations, internal risk scores, security findings, technical configurations, credentials, integration details, private contractual terms, security architecture, or other confidential or security-sensitive information.

​

103. Policy Review

This policy should be reviewed periodically and following significant supplier incidents, major regulatory changes, material business or technology changes, new categories of suppliers, expansion into new jurisdictions, or other developments that could materially affect third-party risk.

​

104. Important Third-Party & Supplier Risk Management Disclaimer

This policy describes xBxBio's general public-facing approach to third-party and supplier risk management. It does not guarantee supplier performance, eliminate all third-party risk, constitute legal advice, create clinical authority, represent certification or regulatory approval, or imply that every control applies identically to every supplier. Specific requirements depend on the supplier, service, information, intended use, contract, jurisdiction, risk, and applicable law.

​

105. Global Protection Statement

No country, territory, supplier type, customer configuration, deployment model, facility, technology, interface, service provider, subcontractor chain, or contractual arrangement is intended to eliminate xBxBio's fundamental requirements for patient protection, human accountability, authorized access, information integrity, provenance, privacy, security, quality, resilience, responsible supplier governance, and appropriate regulatory oversight. A country or territory does not need to be individually named in this public policy for the global baseline to apply where xBxBio lawfully conducts relevant activities.

​

END OF XBXBIO THIRD-PARTY & SUPPLIER RISK MANAGEMENT POLICY

bottom of page