Auditen
Home / Frameworks / SOC 2 / Vendor and third-party risk management
SOC 2 · CC9

Vendor and third-party risk management

Vendor and third-party risk management requires an organization to identify, assess, and monitor the security risks posed by external service providers. The goal is to ensure that vendors who handle sensitive data or provide critical infrastructure maintain a level of security consistent with your own internal controls.

What it means

In practice, this control focuses on the "supply chain" of your security posture. Because you likely rely on cloud providers (like AWS or GCP) and SaaS tools for core operations, an auditor wants to see that you aren't blindly trusting these entities. You must prove that you have a formal process for vetting vendors before they are onboarded and a mechanism for monitoring them throughout the relationship.

The scope typically includes any third party with access to your production environment or customer data. It is not just about the technical security of the vendor, but also their financial stability and operational resilience to ensure they can continue providing services without unplanned outages.

How to meet it

Evidence an auditor asks for

  • A Vendor Inventory List showing all active third parties and their assigned risk levels.
  • Completed security assessment records (questionnaires, checklists) for newly onboarded critical vendors.
  • Copies of signed contracts or Data Processing Agreements (DPAs) containing security requirements.
  • Documentation proving the annual review of vendor SOC 2 reports, specifically noting that "Complementary User Entity Controls" (CUECs) were reviewed and implemented.

Common pitfalls

  • Collecting a vendor's SOC 2 report but failing to document a review of it; simply possessing the PDF is not evidence of risk management.
  • Performing due diligence only during initial onboarding and neglecting ongoing annual monitoring.
  • Maintaining an incomplete inventory that misses "shadow IT" or small tools used by specific teams that have access to production data.