Hello I am looking fore as may replies as possible so I can build a realistic SLA time line for my relationship owners.
How long do you require to clear onboarding for Critical, High and even Moderate inherent vendors . From intake questionnaire (after vendor is selected), meeting with relationship owners and SME's, initial DD request, review of DD and final rating? Does not need to include legal contract review.
Now you and I both know there are too may factors to account for but I must set expectations and I am counting on SMEs from InfoSec, compliance, ops and finance to review docs. I must allow them a full week (and really it is a bit longer) to do the reviews then I have to do another review of their reviews to do the "residual" review. What do you you think is a reasonable expectation to put in a standard and make available in trainings?
Is 30 days reasonable?
We do intake meetings once a week as there are so many people involved (infosec, PMO, legal, compliance, IT architect) and I am still just building this program so I want to set the expectation at 45 days vs the current 30.
But I would love to hear from others and their time frames. Thank you so much