Your subservice organizations and key vendors are an extension of your risk surface. If AWS goes down, your service goes down. If your payroll processor has a breach, your employee data is exposed. SOC 2 requires you to have a formal process for assessing vendor risk before onboarding, monitoring it during the relationship, and collecting their security evidence (SOC 2 report or equivalent) annually. Auditors will sample your vendor list and ask to see the SOC reports you collected.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Vendor risk management program with annual SOC report collection
Implementation Steps
Maintain a vendor inventory listing all subservice organizations (cloud providers, SaaS tools with access to production data or customer data), categorized by criticality
Define a Vendor Risk Management Policy covering: pre-onboarding security review, contractual security requirements (DPA, BAA where applicable), annual monitoring, and offboarding
Collect SOC 2 Type II reports (or equivalent, ISO 27001 certificate, CAIQ response) from all critical vendors annually; store in your GRC platform with collection date
Review collected SOC reports for material exceptions or gaps that could affect your own control environment; document the review with a summary of findings and any compensating controls applied
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Vendor risk management program with annual SOC report collection
Implementation steps
Maintain a vendor list documenting every third party with access to production systems or sensitive data; for each vendor, record: service provided, data accessed, criticality, and last security review date
Before onboarding a new critical vendor, complete a documented security assessment: review their SOC 2 report or equivalent, assess the controls they cover and any exceptions, and document the decision to proceed
Collect SOC 2 reports or equivalent annually for all critical vendors; log collection date in your GRC platform or a vendor register spreadsheet
Review vendor SOC reports for exceptions that overlap with your control environment; document the review and any compensating controls you rely on locally
Tools / systems
Vendor Register (spreadsheet)
Vendor SOC 2 reports (collected annually)
Vendor Risk Management Policy (governance)
Evidence artifacts
Vendor register showing critical vendors, data access, criticality, and last review date
Vendor Risk Management Policy (or equivalent section in the Risk Assessment and Treatment Policy)
SOC 2 reports collected from critical vendors, at least AWS, Microsoft, or other infrastructure providers used
Vendor SOC report review notes: a brief documented assessment of whether exceptions in the vendor's report affect your own controls
Evidence frequency: Annual collection and review; vendor register updated on new vendor onboarding or offboarding