GRC Oversight
Checklist

Vendor assessment checklist

What to actually extract from a vendor's SOC 2 report or questionnaire, and how to keep the assessment from going stale.

Before you assess

  • Confirm what data the vendor will hold or access, and how sensitive it is.
  • Assign a criticality tier: review depth and cadence should match actual exposure, not a flat process for every vendor.
  • Identify an internal owner accountable for the vendor relationship and its risk.

Reading a SOC 2 report

  • Check the report type (Type I vs Type II) and the audit period covered.
  • Confirm the Trust Services Criteria in scope match what you need (Security is required; the rest are optional).
  • Read the auditor's opinion: qualified opinions and noted exceptions matter more than the page count.
  • Check the complementary user entity controls (CUECs), the controls the vendor expects you to run yourself.
  • Note the report's expiration and calendar the next one.

Reading a questionnaire response

  • Look for answers backed by specific evidence (a policy, a report, a control) rather than a generic yes.
  • Flag any answer that's vague, contradicts the SOC 2/ISO scope, or dodges the question.
  • Confirm subprocessor and data-location disclosures match what you were told elsewhere.

Contracts to confirm

  • A signed DPA if the vendor will process personal data subject to GDPR or similar laws.
  • A signed BAA if the vendor will touch protected health information under HIPAA.
  • Security and breach-notification terms appropriate to the vendor's tier.

Rate and schedule reassessment

  • Record a risk rating with the rationale: not just a color, but why.
  • Set a reassessment cadence by tier so critical vendors are reviewed more often, automatically.
  • Keep the vendor's reports, certifications, and DPA linked to the assessment they support, in one register.

Vendor risk keeps this inventory, parses uploaded SOC 2 reports, and schedules reassessment by tier.