Checklist
Vendor assessment checklist
What to actually extract from a vendor's SOC 2 report or questionnaire, and how to keep the assessment from going stale.
Before you assess
- Confirm what data the vendor will hold or access, and how sensitive it is.
- Assign a criticality tier: review depth and cadence should match actual exposure, not a flat process for every vendor.
- Identify an internal owner accountable for the vendor relationship and its risk.
Reading a SOC 2 report
- Check the report type (Type I vs Type II) and the audit period covered.
- Confirm the Trust Services Criteria in scope match what you need (Security is required; the rest are optional).
- Read the auditor's opinion: qualified opinions and noted exceptions matter more than the page count.
- Check the complementary user entity controls (CUECs), the controls the vendor expects you to run yourself.
- Note the report's expiration and calendar the next one.
Reading a questionnaire response
- Look for answers backed by specific evidence (a policy, a report, a control) rather than a generic yes.
- Flag any answer that's vague, contradicts the SOC 2/ISO scope, or dodges the question.
- Confirm subprocessor and data-location disclosures match what you were told elsewhere.
Contracts to confirm
- A signed DPA if the vendor will process personal data subject to GDPR or similar laws.
- A signed BAA if the vendor will touch protected health information under HIPAA.
- Security and breach-notification terms appropriate to the vendor's tier.
Rate and schedule reassessment
- Record a risk rating with the rationale: not just a color, but why.
- Set a reassessment cadence by tier so critical vendors are reviewed more often, automatically.
- Keep the vendor's reports, certifications, and DPA linked to the assessment they support, in one register.
Vendor risk keeps this inventory, parses uploaded SOC 2 reports, and schedules reassessment by tier.