Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC9.2Vendor and business partner risk managementSOC 2Risk Mitigation

Official Requirement

The entity assesses and manages risks associated with vendors and business partners.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

Your subservice organizations and key vendors are an extension of your risk surface. If AWS goes down, your service goes down. If your payroll processor has a breach, your employee data is exposed. SOC 2 requires you to have a formal process for assessing vendor risk before onboarding, monitoring it during the relationship, and collecting their security evidence (SOC 2 report or equivalent) annually. Auditors will sample your vendor list and ask to see the SOC reports you collected.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Vendor risk management program with annual SOC report collection

Implementation steps

  1. Maintain a vendor list documenting every third party with access to production systems or sensitive data; for each vendor, record: service provided, data accessed, criticality, and last security review date
  2. Before onboarding a new critical vendor, complete a documented security assessment: review their SOC 2 report or equivalent, assess the controls they cover and any exceptions, and document the decision to proceed
  3. Collect SOC 2 reports or equivalent annually for all critical vendors; log collection date in your GRC platform or a vendor register spreadsheet
  4. Review vendor SOC reports for exceptions that overlap with your control environment; document the review and any compensating controls you rely on locally

Tools / systems

Evidence artifacts

Evidence frequency: Annual collection and review; vendor register updated on new vendor onboarding or offboarding