SOC2Prep

SOC 2 vendor risk triage

Most vendor registers treat forty suppliers as forty equal problems. This sorts yours into three tiers, so the review effort lands on the handful that could actually hurt you.

Last reviewed 2026-09-14Written by Jacob Masse, TrazTech Inc.

Vendor management is the control most likely to be started three weeks before fieldwork, because it is paperwork rather than engineering and it feels like it can wait. It cannot, for one specific reason: the register has to be rebuilt from expense records rather than written forward, and that takes days rather than hours once a company is past twenty people.

The other reason teams stall is that the register arrives with forty rows and no way to tell which of them matter. A file storage provider holding every customer document and a stock photo subscription are not the same risk, and running the same assessment on both wastes the effort that should have gone on the first one.

Tick the kinds of vendor you use and answer four questions about your data. This returns three tiers with the review depth for each, what your auditor will ask about a vendor in that tier, and the Canadian privacy obligations that attach where personal information leaves your systems.

The tiering appears on this page. Nothing is emailed anywhere unless you ask for it at the end.

Which kinds of vendor do you use?

Tick the category rather than counting individual suppliers. Numbers come later.

What is the most sensitive data you hold?

Answer for the product, not the company. Employee records are handled separately below.

Do you hold personal information about Quebec residents?

Roughly how many vendors are on the company card in total?

Including the small ones. Most teams underestimate this by about half, so look at a statement before answering.

How will you treat your hosting provider in the report?

The carve-out method excludes their controls from your opinion and relies on their own report. The inclusive method pulls them inside yours, which is rare for a small company.

How many people work there?

When does the observation window open?

What actually decides a tier

Two questions, in this order. Could this vendor see or hold customer data, and could its failure stop you serving customers. A vendor that answers yes to either is in the top tier regardless of what it costs, and cost is a poor proxy in both directions: a free error tracking tool can receive production stack traces containing personal information, while an expensive design subscription holds nothing at all.

The third question, which changes the paperwork rather than the tier, is whether the vendor processes personal information on your behalf. Under PIPEDA you remain accountable for personal information transferred to a third party for processing, and the mechanism the law expects is contractual. That is why a data processing agreement sits in the evidence list next to the security report.

Reading a vendor report rather than filing it

Collecting a vendor's own audit report and putting it in a folder is not a review, and an auditor asking what you did with it is the moment that becomes obvious. Four things to actually read. The opinion itself, because a qualified one changes your answer. The period covered, because a report ending eight months ago leaves a gap you have to bridge. The exceptions listed, and whether any of them touch how you use the service. And the complementary user entity controls, which is the section listing what the vendor assumes you are doing, and which is where your own obligations quietly live.

Write four sentences per report recording what you found and date it. That note is the evidence. The report is only the input. The vendor management policy page covers what the policy has to say, and CC9 risk mitigation covers where this sits in the criteria.

Common questions

Does every vendor need a security review?

No, and treating them equally is the reason registers stall. What every vendor needs is a row: name, what it does, what data it holds, who owns the relationship, and its tier. Only the top tier needs a report read and a documented assessment. The middle tier needs a questionnaire or a published security page on file. The bottom tier needs the row and nothing else.

What if a vendor has no audit report to give us?

That is common below a certain vendor size and it is not automatically disqualifying. Ask for what they do have: a security page, a questionnaire response, a certification, a penetration test summary. Record what you asked for, what you received, and why you accepted the risk. A documented decision to accept a gap is a control operating. An undocumented one is a gap.

How often does a vendor review have to happen?

Annually for the top tier is the standard position, plus a review at selection and whenever the relationship materially changes. Your own policy sets the cadence and the auditor tests you against it, so avoid writing quarterly into a policy for a task you will do once a year.

Do contract developers count as vendors?

Yes, and they are frequently missed because they arrive through payroll rather than procurement. Anyone with access to production, source code or customer data belongs in the register with a signed confidentiality agreement, and they also belong in the population your access review is reconciled against.

Want the register built rather than described

Send your vendor list and what each one holds, and Canadian firms that do readiness work will tier it and write the assessments.

Get matched