NIST SP 800-53 Revision 5.1 HIGH CA-3: Information Exchange
Approve and manage exchange of information with external systems using ISA, MOU, contract; review annually.
What else in your programme already covers this
This control maps to 31 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
SOC2-CC6.7 Transmission of data is restricted to authorized users
SOC2-P6.4 Obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses those parties' compliance on a periodic and as-needed