INNPO
HomeCareersES
Contact ↗
SUPPLY-CHAIN SECURITY

Supplier procurement

Security requirements for suppliers that access or exchange information with INNPO.

DOCUMENT05 / 06
DOCUMENTATION
01Legal notice02Privacy policy03Cookie policy04Information security05Supplier procurement06Quality and environment

This English translation is provided for information. The signed Spanish document is the legally authoritative version.

DOCUMENTPOL-05
REVISION02
DATE20.05.2025

011. Purpose

This document establishes procurement guidelines for suppliers that exchange information with INNPO or access INNPO information, whether physically or logically.

022. Procurement policy

032.1. Conditions for engaging suppliers

To prevent the engagement of a supplier from introducing vulnerabilities, such as damage, loss or compromise of data or impacts on application availability and integrity, the following security measures shall generally apply:

  • Confidentiality agreements shall be signed with service providers that may access system information. These agreements must identify the confidentiality, integrity and availability measures applying to assets within scope. Clauses governing confidentiality and the return of assets when the agreement ends are mandatory.
  • Contracts must ensure reliable delivery of products and services, which is particularly important for cloud-service providers.
  • One-off work carried out by a third party must be continuously supervised.
  • The acquisition of systems, applications or resources that process information but are not services must follow INNPO's supplier approval, assessment and monitoring process.
  • Service levels shall be monitored to verify that the contracted service is being delivered. Where incidents occur, contracts shall be reviewed and the third party notified. If the problem is not resolved, Management/CEO may take the legal measures considered appropriate.
  • The person responsible for the system, or their delegate, must record security incidents detected in connection with these contracts so that service quality can be analysed.
  • Following changes, or where service analysis identifies shortcomings, policies, procedures, instructions and controls shall be improved and a new risk assessment performed.
  • Company management, or the Information Security Manager in its absence, decides whether specific third-party background checks are necessary.

04Cloud-service providers

For cloud-service providers, the following shall also be considered:

  • Service Level Agreements (SLAs), including availability and incident-response times.
  • Disaster-recovery and business-continuity capabilities.
  • Physical and logical security mechanisms implemented by the provider.
  • Access-management, encryption and data-deletion policies.
  • Geographical location of data and compliance with data-sovereignty requirements.
  • Audit rights.

Where appropriate, potential suppliers shall be asked to provide evidence of their security controls, such as audit reports, certifications or responses to security questionnaires.

062.2. Monitoring and review of services

  • Service levels, compliance with security clauses, and the reports and records generated by suppliers must be periodically reviewed and monitored. Suppliers may be audited at least once a year; audits shall be on site where a high risk of information loss is identified. A review shall be carried out at least annually.
  • All security incidents related to a supplier's work must be immediately escalated to the person responsible for the system.
  • If a supplier suffers a security breach, appropriate action shall be taken. The relationship may be suspended for a period determined by Management.

072.3. Security requirements in third-party contracts

  • Agreements involving third-party access to information-processing resources must be based on a documented contract setting out the security requirements and incorporating INNPO's security policies and rules, so that signing the contract prevents misunderstandings with the third party.
  • The contract must take account of the specific security requirements recorded in INNPO's supplier security clauses according to the services the third party will provide.

082.4. Changes to or termination of services

  • Any proposed change or contract termination shall be managed. Where necessary, the Information Security Manager shall carry out a new risk assessment before changes are accepted.

092.5. Removal of access rights and return of assets

  • When a contract is changed or terminated, access rights for supplier personnel must be removed in accordance with Policy POL-06: Access Control.
  • The contract owner must also ensure that all equipment, software and information in electronic or paper form is returned when a contract changes or ends.

10Termination of cloud services

For cloud-service providers, a clear process shall be defined for terminating the contractual relationship, including:

  • Confirmation that all data has been securely removed from the provider's systems in accordance with contractual terms and data-retention policies.
  • Procedures for securely migrating data to another provider or to internal systems.

112.6. Non-compliance

Failure to comply with this policy may result in disciplinary action and may have legal or contractual consequences.

Vélez-Málaga (Málaga), 20 May 2025 MANAGEMENT/CEO

INNPO

Technology that adapts. Energy that responds.

© 2026 INNPOLegal noticePrivacy policyCookie policyInformation securitySupplier procurementQuality and environment