1. Scope & Applicability

This document outlines the mandatory baseline requirements for any third-party entity entering into a commercial, technical, or operational relationship with Aevum Zenth Conglomerate. Requirements apply across all business units, including Energy, Aerospace, Healthcare, Financial Services, Defense, and Digital Infrastructure.

⚠️ Critical Notice

Failure to meet or maintain these requirements may result in immediate contract suspension, exclusion from the approved vendor registry, and legal action under the terms of the Master Services Agreement (MSA).

Applicable Parties

  • Strategic Partners: Long-term collaborators with shared IP or joint ventures
  • Service Providers: IT, logistics, facilities, and professional services
  • Raw Material Suppliers: Component manufacturers and commodity vendors
  • Subcontractors: Tier-2/3 vendors acting under prime contractor agreements

2. Regulatory & Compliance Standards

All vendors must demonstrate active compliance with applicable local, national, and international regulations relevant to their industry sector and geographic operations.

r>
Regulatory Framework Requirement Level Evidence Required
ISO 9001 (Quality Management) Mandatory Certification copy + annual audit report
ISO 14001 (Environmental) Mandatory Certificate + carbon footprint disclosure
GDPR / CCPA / Data Privacy Laws Mandatory DPA execution + data processing inventory
FCPA / UK Bribery Act Mandatory Anti-corruption policy + training records
Industry-Specific (FDA, FAA, SEC, etc.) Contextual Licenses, approvals, or compliance attestations

3. Cybersecurity & Data Protection

Aevum Zenth operates in highly regulated and mission-critical environments. Vendors with access to corporate networks, customer data, or operational technology must satisfy strict security controls.

Baseline Security Controls

  • Encryption: AES-256 at rest, TLS 1.3+ in transit
  • Access Management: MFA enforcement, least-privilege access, quarterly access reviews
  • Vulnerability Management: Monthly patching, quarterly pen tests, 72-hour critical patch SLA
  • Incident Response: Documented IR plan, 4-hour notification SLA for breaches
  • Personnel Screening: Background checks for all staff with system or facility access
🔒 SOC 2 / ISO 27001 Attestation

Vendors handling sensitive or classified data must provide a valid SOC 2 Type II report or ISO 27001 certification within 30 days of contract execution. Exceptions require written approval from Aevum Zenth Chief Information Security Officer (CISO).

4. Quality Assurance & Performance Metrics

Operational excellence is non-negotiable. All vendors are measured against defined KPIs and must participate in continuous improvement initiatives.

Standard KPIs

  • Delivery Accuracy: ≥ 98.5% on-time, in-full (OTIF)
  • Defect Rate: ≤ 0.5% for hardware/components, ≤ 1% for services
  • Response Time: ≤ 2 hours for critical issues, ≤ 24 hours for standard inquiries
  • SLA Adherence: ≥ 99.9% compliance with contracted service levels

Vendors falling below thresholds for two consecutive quarters will be placed on Performance Improvement Plans (PIP) with defined remediation timelines.

5. Sustainability & Ethical Sourcing

Aevum Zenth is committed to net-zero operations by 2045. All supply chain partners must align with our ESG framework and responsible sourcing guidelines.

Key Expectations

  • Transparent supply chain mapping to Tier-2 suppliers
  • Prohibition of forced labor, child labor, and conflict minerals
  • Annual sustainability reporting (GHG emissions, water usage, waste diversion)
  • Preference for circular economy practices and recyclable packaging
⚖️ Ethics & Conduct

Vendors must adopt and enforce an anti-discrimination policy, maintain safe working conditions per OSHA/ISO 45001 standards, and provide open channels for employee reporting without retaliation.

6. Vendor Onboarding Process

New partners must complete the following steps before receiving a Vendor ID and gaining procurement system access.

  1. Initial Screening: Submit corporate registration, tax IDs, and insurance certificates
  2. Risk Assessment: Complete the Third-Party Risk Questionnaire (TPRQ)
  3. Security Validation: Provide architectural diagrams, data flow maps, and compliance attestations
  4. Contract Execution: Sign MSA, DPA, and NDA via the vendor portal
  5. System Provisioning: Receive API keys, procurement credentials, and SLA dashboards

7. Ongoing Monitoring & Auditing

Compliance is not a one-time event. Aevum Zenth reserves the right to conduct scheduled and unscheduled audits of vendor facilities, systems, and processes.

Audit Rights

  • Quarterly compliance self-assessments submitted via vendor dashboard
  • Annual third-party audit (vendor-paid or Aevum-sponsored based on risk tier)
  • Right to inspect facilities, logs, and training records with 5 business days notice
  • Immediate audit trigger for reported incidents, data breaches, or whistleblower allegations

Findings will be categorized as Major (requires corrective action within 30 days) or Minor (requires remediation within 90 days). Unresolved major findings result in contract termination.

8. Support & Contact

For questions regarding vendor requirements, onboarding assistance, or compliance exceptions, contact the Third-Party Risk Management (TPRM) team.

d
Email vendors@aezumzenth.com
Portal Support portal-support@aezumzenth.com (Mon–Fri, 0900–1800 UTC)
Security Incidents security@aezumzenth.com (24/7 SOC Hotline: +1-800-AEVUM-SEC)
Legal & Contractslegal-contracts@aezumzenth.com

Document Version: 5.1.2 | Last Updated: November 2025 | Owner: Office of the Chief Compliance Officer