Vendor and third-party risk management
Vendor and third-party risk management requires an organization to identify, assess, and monitor the security risks posed by external service providers. The goal is to ensure that vendors who handle sensitive data or provide critical infrastructure maintain a level of security consistent with your own internal controls.
What it means
In practice, this control focuses on the "supply chain" of your security posture. Because you likely rely on cloud providers (like AWS or GCP) and SaaS tools for core operations, an auditor wants to see that you aren't blindly trusting these entities. You must prove that you have a formal process for vetting vendors before they are onboarded and a mechanism for monitoring them throughout the relationship.
The scope typically includes any third party with access to your production environment or customer data. It is not just about the technical security of the vendor, but also their financial stability and operational resilience to ensure they can continue providing services without unplanned outages.
How to meet it
- Maintain a comprehensive inventory of all third-party vendors, categorized by the criticality of the service provided and the sensitivity of the data accessed.
- Establish a pre-onboarding due diligence process, such as requiring vendors to complete a security questionnaire or provide their latest SOC 2 Type II report.
- Incorporate mandatory security clauses into contracts, including breach notification requirements, right-to-audit clauses, and confidentiality agreements (NDAs).
- Implement a periodic review cycle (e.g., annually) to re-evaluate the security posture of critical vendors by reviewing updated audit reports or certificates.
- Define a risk-based approach where "High Risk" vendors undergo more rigorous vetting than "Low Risk" tools.
Evidence an auditor asks for
- A Vendor Inventory List showing all active third parties and their assigned risk levels.
- Completed security assessment records (questionnaires, checklists) for newly onboarded critical vendors.
- Copies of signed contracts or Data Processing Agreements (DPAs) containing security requirements.
- Documentation proving the annual review of vendor SOC 2 reports, specifically noting that "Complementary User Entity Controls" (CUECs) were reviewed and implemented.
Common pitfalls
- Collecting a vendor's SOC 2 report but failing to document a review of it; simply possessing the PDF is not evidence of risk management.
- Performing due diligence only during initial onboarding and neglecting ongoing annual monitoring.
- Maintaining an incomplete inventory that misses "shadow IT" or small tools used by specific teams that have access to production data.