What Should a Biotech Vendor Contract Require?

A biotech vendor contract should require a right to audit, a breach notification obligation, and a defined off-boarding process, and it should sit inside a lifecycle rather than a signing event. That is the structure Raja Mikkili, Vice President of Core Technologies and Security at Arcutis Biotherapeutics, describes on Open Door Salon. His starting position is that contractual obligations are the first control, not the last, because they are the only leverage that exists before a vendor ever touches a system. What follows the signature matters just as much: continuous monitoring while the relationship runs, and a real process for revoking access when it ends. Anne Herold Li, Shareholder and New York Managing Partner at Brownstein Hyatt Farber Schreck, adds the scope question that most programs get wrong, which is how far down the supply chain the obligation has to reach.
What comes before the contract?
Knowing which vendors matter. Mikkili does not start with clauses, because applying the same standard to every vendor produces a program nobody can sustain.
"I think one of the things companies can do is have a tiered classification. They need to be able to classify the vendors, know who the vendors are, obviously, and understand from a data perspective."
The classification runs on access rather than on spend, and procurement-led programs tend to miss that.
"What vendors are actually accessing my data? Where are they accessing from? Right. And what critical systems are they engaging with in terms of access, in terms of integrating, sharing data?"
"And then you classify those vendors, high, medium, low, whatever works for you. Right. So that you don't give the same emphasis and focus to your low priority vendors, but focus on the critical or high."
A small vendor with deep system integration outranks a large vendor with none. Building the tiering off contract value inverts the risk.
What are the clauses that have to be in the agreement?
Mikkili frames the pre-signature moment as the point of maximum leverage.
"One of the things that you first can do is contractual obligations. That's the first and foremost thing is before you engage with a vendor, what are the five things that a vendor should do, must do, and what obligations should they have?"
The first is a right to audit, and his reasoning is that no review conducted at signing can be complete.
"Right. One thing that comes to my mind is definitely you cannot catch everything at the time of the contractual signatures, the time period and the review period, but have the right to audit so that you can go back and then review and examine certain processes, the systems, their procedures."
The second is breach notification.
"Have that clause in there. Also have breach notification clause where a vendor should notify you if something were to go wrong."
He then applies it to a live example, and the conditional in his phrasing is the whole argument for writing the clause in advance.
"In the case of West Pharmaceuticals, I hope most of their customers have actually had that clause in there. So they were notified so that they know how to protect themselves, you know, so that the data that has been exfiltrated is not impacting them."
A customer without that clause learns what happened at the same time as everyone else, which is too late to be useful.
Does the obligation end at signature?
No, and this is where Mikkili says most programs stop.
"I think that's going to be absolutely key. And when you set up everything, it's also something that you need to do on an ongoing basis, not something that you do at the onboarding."
"It's not a one-time exercise, but a continuous monitoring because things change, landscapes change, systems change, people change."
Every element of a vendor assessment has a shelf life. The staff who answered the questionnaire leave. The subprocessors change. The architecture gets rebuilt. An assessment from onboarding describes a company that no longer exists.
What happens when the relationship ends?
Access gets removed on purpose, which is the step Mikkili finds missing most often.
"And at the end, when you're done with the vendor, make sure that you have an off-boarding process. So you are effectively taking away their access, the system integrations, any other data that needs to be preserved."
"All of those are factored in. So it has to be a full lifecycle program for vendor risk management."
A terminated vendor with live credentials is an unowned door. Nobody is monitoring it, nobody is renewing its assessment, and no commercial relationship exists to make anyone responsible for it.
Is a security questionnaire enough?
Mikkili is direct that it is a floor rather than a program.
"Somebody is going to answer that, saying we're doing A, B, C controls and we have encryption, we have certifications. Those matter, but those won't be comprehensive if you want to secure your organization."
Certifications and control attestations are self-reported and point-in-time. They tell you a vendor could describe a control on the day they filled in the form. The right to audit exists because that is not the same as the control working.
How far down the supply chain does this reach?
Further than most cybersecurity programs currently look, and Herold Li argues the industry already has a working model for it.
"So I think I think this is something that companies, they need to start by looking at the entire supply chain all the way down where they are to the next guy, to the next guy, to the next guy, to the next guy."
Her comparison is to forced-labor compliance, where companies already trace suppliers to the origin of the raw material. Under the Uyghur Forced Labor Prevention Act, importers must be able to document their supply chains to that depth or face detention of goods.
"If you're making a pharmaceutical derived from fruit 17 vendors later, you've got to go all the way down and certify to the U.S. government that you are not using forced labor in your supply chain. This is a full level audit down to the roots."
The practical recommendation is to reuse what exists rather than build something parallel.
"This is something the compliance officers at companies who are already familiar with this idea from the forced labor statutes. They need to start doing this with cybersecurity and build up or even maximize, utilize that company infrastructure that they already have for this."
That is a genuinely useful shortcut. The mapping capability, the supplier relationships, and the documentation discipline are already in the building, sitting in a compliance function that is not currently pointed at cyber risk. The mechanics of building that map are covered in how to map sub-tier supply chain risk in biotech, and the sourcing question behind it in alternatives to Chinese biotech suppliers.
Herold Li, who is the lawyer in the room, notes the oddity of where the argument came from.
"you know it's bad when the non-lawyer on this podcast is talking about contractual obligations, right?"
The contract is a security control, and the security leader treating it as one is the point. Which vendors deserve that scrutiny follows from why small biotechs are a bigger cyber target than big pharma, and the data-rights half of the same document is covered in who owns the data in a biotech collaboration agreement.
This post draws on the recorded, on-the-record conversation with Raja Mikkili and Anne Herold Li on Open Door Salon. Watch or listen to the full episode, Nation States Aren't Targeting Big Pharma, or read more about Raja Mikkili and Anne Herold Li.
Open Door Salon brings the people who build, fund, and fight for global healthcare into one room. If your organization wants to reach that audience, see our sponsorship options.
