Minimum supplier security requirements
Our Security Requirements for Suppliers
Our Minimum Supplier Security Requirements (MSSRs) form part of our standard contractual agreement with Suppliers that have access to ClearBank information. These requirements are aligned with industry best practice and are communicated to Suppliers during onboarding and contract renewals. Unless otherwise agreed, all MSSRs are considered binding Supplier obligations. ClearBank will monitor Suppliers' compliance with the MSSRs throughout the duration of the relationship.
Version: 2.0
Last Updated: 21 August 2026
Transition Period Ends: 30 November 2026
ClearBank periodically reviews and updates the MSSRs to ensure they remain aligned with industry best practice, emerging threats, regulatory expectations, and our evolving risk appetite. Where material changes are made, an updated version of the MSSRs will be published here on the ClearBank website. To support Suppliers in understanding and implementing changes, both the new and previous versions of the MSSRs will remain available.
When a new version is published, existing Suppliers will have a 90-day transition period during which compliance with either the previous or updated version of the MSSRs will be accepted. Following this period, Suppliers will be expected to comply with the latest published version unless otherwise agreed with ClearBank.
Minimum Security Requirements (Information Security)
HR-001
Personnel / Human Resources Security
Where permitted by local legislation, Suppliers will perform background checks on all new personnel, via appropriate agencies, that includes but is not limited to the following:
• Checking valid, original photographic identity evidence, and retaining evidence.
• Check for criminal convictions, and retain evidence of such checks.
One time
These checks can help to determine whether personnel are who they say they are (authentication), reduce the risk of falsified information being used to obtain employment, and guard against the unauthorised disclosure of confidential data by individuals with criminal or malicious intent.
IS-001
Access Control
Electronic, mechanical or digital physical access controls are to be deployed and managed in all Supplier premises. All security systems are to be installed, operated and maintained in accordance with applicable legal and regulatory requirements.
Continuous
Effective access control is part of a layered approach to protecting premises from unauthorised access and to ensure the security of business assets.
IS-002
Data Centre Management
All data centres and cloud provider facilities relied upon by Suppliers must be secured to prevent unauthorised access or damage to ClearBank data.
All data centres are to have layered technical and physical controls and procedures in place to protect the perimeter, building and integrity of the data halls. Appropriate controls include, but are not limited to, security cameras, intruder detection systems, physical access controls and security personnel.
Where Supplier’s utilise public cloud services to store ClearBank data, Suppliers must ensure that formal due diligence is conducted to ensure that layered technical and physical controls and procedures in place to protect Supplier’s assets.
Continuous
To protect data and assets held within data centres from the risk of loss, damage or theft resulting from unauthorised access.
IS-003
Information Security Policy and supporting documents
Suppliers must establish an Information Security Policy to ensure there is organisation-wide understanding of people, process, technology environment, and the effectiveness of their information security controls. The information security policy must be documented and include administrative, technical, and physical measures to protect data from unauthorised access, loss, misuse, alteration, or destruction.
Suppliers must establish an Information Classification Standard that outlines clear guidelines and specific measures required for the handling and sharing of different types of information. The classification policy must outline the criteria for data classification and the types of data that need to be classified.
Suppliers must publish acceptable use requirements on systems and data to inform all personnel of their individual responsibilities in this area. Appropriate steps should be taken to ensure compliance to these requirements (e.g. training, testing, monitoring and disciplinary action).
Continuous
An effective security policy and classification of data sets the overall security tone and posture for the organisation, and ensures employees treat all data according to its risk level.
Information Classification standards reduce the likelihood of accidental data breaches or mishandling
Acceptable use requirements help to underpin the control environment protecting data and assets.
IS-004
PII Subprocessor Management
If Supplier will be processing ClearBank Personally Identifiable Information (PII), Suppliers must implement controls to adequately protect ClearBank information in line with industry best practice and EU GDPR requirements, including:
• Providing timely notification to ClearBank of new and existing subprocessors performing activities relating to ClearBank information or services.
• Ensure appropriate contractual obligations are enforced and audited regularly for subprocessors performing activities relating to ClearBank information or services.
Continuous
To provide assurance that Suppliers will maintain appropriate security and privacy controls to protect ClearBank PII.
IS-005
Supply Chain Security Assurance
Suppliers must maintain a Supplier security assurance process to ensure their subcontractors are risk assessed, subject to appropriate due diligence, commit to contractual security obligations protecting any ClearBank data they may access, and are subject to regular oversight to ensure that all critical security controls remain design and operationally effective.
Suppliers must provide timely notification to ClearBank of all new and existing operationally critical subcontractors (4th parties) supporting the delivery of services to ClearBank.
Continuous
To provide assurance that Suppliers will maintain appropriate security controls in their supply chains to protect ClearBank’s interests.
IS-006
Security Awareness and Training
Suppliers must have a security awareness program established for all employees, contractors, and third-party users of its systems. This will include regular updates on current security threats and relevant procedures, processes and policies.
Suppliers must ensure that all personnel undertake mandatory information security training within one month of joining the organisation, and at least annually thereafter. Training content should include coverage of common threats/attacks, essential controls and policies as well as an assessment to confirm the content was understood.
Where Suppliers provide any development services for ClearBank, including contractors and outsourced resources, Suppliers must ensure developers undergo specialist secure coding / development training on an annual basis, including OWASP Top 10 application risks.
Continuous
Effective personnel training and security awareness education supports all other controls protecting data and assets.
IS-007
Security Incident Management
Suppliers must establish a Security incident management process that effectively validates, contains and mitigates security incidents in Suppliers’ environment, including physical facilities relied upon by the Supplier. Suppliers must regularly test incident response plans to ensure effectiveness of response. Suppliers will maintain procedures to manage security incidents and undertake investigations where appropriate.
Annual
An incident management and response process helps to ensure that incidents are quickly contained and prevented from escalating. Failure to maintain an appropriate incident management procedure may lead to inappropriate or inefficient action being taken following an
incident.
IS-008
Breach Notification
Suppliers must notify ClearBank within 48 hours of identifying any actual or suspected security incident impacting or involving ClearBank data processed by the supplier (or by a sub-processor of the Supplier), ClearBank systems or ClearBank sites and facilities.
Suppliers must keep records of all investigations and remedial actions relating to the Security incident, including identifying the impact of the incident and steps taken to mitigate the effects.
Continuous
Breach notification requirements ensure ClearBank and other relevant stakeholders are informed about incidents that may impact the bank and can respond in an appropriate and timely manner.
IS-009
Network Security
Suppliers must ensure all IT Systems operated by it (or are operated on its behalf by a sub-contractor) are protected from lateral movement of threats within its (and any relevant sub-contractors’) network. Suppliers must monitor the flows of data transiting its networks to identify and analyse anomalous access patterns or activities in the data.
Continuous
If Network Security controls are not implemented, external or internal networks could be subverted by attackers and unauthorised access could be gained to data and/or systems.
IS-010
Log Management
Suppliers must maintain an effective log management process that confirms key IT systems including applications, networking equipment, security devices and servers are set to log key events. Logs must be centralized, secured, and retained by Suppliers for a minimum period of 12 months. If ClearBank data is stored in logs, Suppliers must retain audit logs that include logging of user activities and access attempts attributed to named individuals.
Continuous
If this control is not implemented, Suppliers will not be able to detect and respond to inappropriate or malicious or anomalous activities within reasonable timescales.
IS-011
Malware Defenses
Suppliers must have policies, procedures and supporting processes and technical measures in place to prevent the execution of malware on end-point devices (i.e. staff laptops, and mobile devices) and IT infrastructure network and systems components.
Continuous
Anti-malware solutions are vital for protection against the impact of Malicious Code.
IS-012
Secure Configuration Standards
Suppliers must have an established framework to ensure that all systems and networking equipment are securely configured. Suppliers must ensure that endpoints used to access ClearBank Data are hardened to protect against attacks.
Endpoint security build must include:
• Disk Encryption.
• Disabling all un-needed software/services/ports
• Disabling administration rights for local users.
Continuous
If this control is not implemented, endpoints may be vulnerable to attacks. Standard build controls help to protect systems/data from unauthorised access.
IS-013
Encryption
Suppliers must ensure that data is encrypted at rest within the Supplier’s environment, using industry-standard encryption algorithms (AES 256-bit encryption or better). Suppliers must encrypt all customer data in transit, including personal data and backups, using industry-standard cryptographic protocols (TLS1.2 or better).
Continuous
Encryption is crucial to maintain the confidentiality and integrity of data at rest and in transit.
IS-014
Data Loss Prevention
Suppliers must maintain measures to protect against inappropriate data leakage including, but not limited to, monitoring and responding to the following:
• Email and other communication channels for unauthorised transfer of information outside Suppliers network.
• Internet / Web Gateway (including online storage and webmail)
• Loss or theft of data on portable electronic media (including data on laptops, mobile devices, and portable media).
• Unauthorised transfer of Information to portable media.
• Insecure Information exchange with third parties (e.g., subcontractors).
• Inappropriate printing or copying of data.
Continuous
Appropriate controls must be operated effectively in order to ensure that confidential information is restricted to those who should be allowed to access it (confidentiality), protected from unauthorised changes (integrity) and can be retrieved and presented when it is required (availability).
IS-015
Secure Development Practices
Where Suppliers are providing ClearBank with development services, developer consultants, or will be developing applications for the Supplier's internal use or ClearBank's use, a Secure Development Lifecycle (SDLC) framework must be established to prevent security breaches and to identify and remediate vulnerabilities in the code during the development process. Applications must be developed in a secure environment and ClearBank data must not be used for any of the Supplier’s development activities. Suppliers must ensure developers implement secure coding best practices, including OWASP Top 10 application risks.
Continuous
Controls protecting application development help to ensure that applications are secure prior to deployment.
IS-016
Penetration Testing
Suppliers must engage with an independent external security tester to perform an assessment of their IT infrastructure and web applications. Penetration testing must be conducted on an annual basis at minimum to identify, prioritise and resolve any actively exploitable vulnerabilities in a timely manner.
Critical findings should follow a predetermined remediation timeline reflective to industry standards.
Annual
If this control is not implemented, Suppliers may be unable to assess the cyber threats they face and the appropriateness and strength of their defenses.
IS-017
Vulnerability Management
Suppliers must maintain policies, procedures and supporting processes and technical measures to enable the timely detection of vulnerabilities within its applications, infrastructure, network and system components. Critical findings should follow a predetermined remediation timeline reflective to industry standards.
Quarterly
If this control is not implemented, attackers could exploit vulnerabilities within systems to carry out attacks against Suppliers’ systems.
IS-018
Logical Access Management
Suppliers must establish a Joiner, Leaver, Mover process to manage user identities and access privileges throughout the employee lifecycle. Suppliers must regularly review all employees access, including guest user access rights.
Access to Suppliers’ systems and data must be restricted and should be managed in line with the following principles:
• The need-to-know principle that people should only have access to Information they are required to know in order to perform their authorised duties;
• The principle of Least Privilege that states people should only have the minimum level of privilege necessary to perform their authorised duties; and
• The separation of duties principle that at least two individuals are responsible for the separate parts of any task to prevent error and fraud.
Continuous
Access controls enhance security and operational efficiency by ensuring timely updates to access rights and access to information restricted to only users who require it.
IS-019
Patch Management
Suppliers must maintain policies, procedures and supporting processes and technical measures to enable the timely deployment of new security patches to all end-point devices and IT infrastructure, network and system components. If a system cannot be patched, Suppliers must implement appropriate controls to mitigate the risk.
Quarterly
If this control is not implemented, services may be vulnerable to security issues which could compromise data, cause loss of service or enable other malicious activity.
IS-020
Mobile Device Management
Suppliers must maintain policies, procedures, and supporting processes to ensure that where ClearBank data is accessible on mobile devices, appropriate security measures are implemented to protect all ClearBank information accessed, processed, or stored on those mobile devices. Where Supplier’s employees are permitted to use personal devices to access ClearBank data, Suppliers must implement a Bring Your Own Device (BYOD) policy that includes appropriate controls to restrict data to approved applications.
Continuous
Mobile device management solutions implement security policies, settings, and software configurations to identify potential mobile device vulnerabilities and reduce the risk of compromised data through mobile devices.
IS-021
Business Continuity and Disaster Recovery
Suppliers must maintain Business Continuity (BCP) and Disaster Recovery (DR) policies, procedures, and supporting processes to ensure effective response to disruptions and incidents. Suppliers BCP and DR plans must detail critical activities, processes, systems, people and timelines, and must be reviewed and updated on an annual basis.
Continuous
These requirements seek to preserve the resilience of security controls used to protect systems and data.
IS-022
Artificial Intelligence Security and Oversight
Suppliers must implement a formal Artificial Intelligence (AI) governance and security framework covering any AI, machine‑learning (ML), or large‑language‑model (LLM) capabilities used to deliver services involving ClearBank data or systems.
Where AI forms part of the service provided to ClearBank, Suppliers must disclose AI usage in annual security questionnaires and provide evidence of AI governance controls upon request.
Continuous
These requirements ensure AI capabilities adhere to a secure, transparent, and governed lifecycle that protects ClearBank data and prevents emerging AI‑driven threats, aligning with ClearBank’s existing layered security expectations.
Minimum Security Requirements (Supplier Oversight)
SO-001
Security Audit Rights
ClearBank maintains the right to conduct on-site audits of Suppliers’ security controls on an annual basis to verify compliance with the MSSRs.
Annual
Audits provide ClearBank with a mechanism to actively verify Suppliers’ compliance with the MSSRs and to observe the operational effectiveness of specific controls.
SO-002
Annual Security Questionnaires
ClearBank will require Suppliers to complete and return a security compliance questionnaire annually. These questionnaires must be completed as thoroughly as reasonably possible, attaching appropriate evidence as required. Suppliers must notify ClearBank in the event of material changes being made to security controls and infrastructure referred to in their most recent questionnaire submission.
Annual
ClearBank’s security questionnaires provide a high-level, point-in-time overview of Suppliers’ security controls.
SO-003
OSINT Scan
ClearBank will use advanced OSINT (Open-Source Intelligence) tools to non-intrusively assess the security posture of Suppliers on a continuous basis.
Continuous
ClearBank utilises specialist tools to monitor Suppliers’ overall security posture by means of publicly accessible data sources.
SO-004
Critical Finding Remediation
Where ClearBank’s MSSR oversight mechanisms identify Critical findings, Suppliers must engage with ClearBank (and/or Panorays, if appropriate) to challenge or agree remediation plans in order to resolve such findings in a timely manner.
Continuous
Critical findings must be promptly and effectively managed to ensure that both ClearBank and its Suppliers are not exposed to excessive levels of security risk.
SO-005
Certification / Assurance Documentation
Upon request, Suppliers must provide ClearBank with the latest copies of certifications or reports obtained by Suppliers that demonstrate continued achievement of any Information security related certifications communicated to ClearBank during the onboarding process.
Annual
Where Suppliers have referred to achieving independently assessed security standards (e.g. ISO 27001), ClearBank will require evidence that these Suppliers have continued to maintain such standards throughout their relationship with us.