SOC 2 vendor risk triage
Most vendor registers treat forty suppliers as forty equal problems. This sorts yours into three tiers, so the review effort lands on the handful that could actually hurt you.
Vendor management is the control most likely to be started three weeks before fieldwork, because it is paperwork rather than engineering and it feels like it can wait. It cannot, for one specific reason: the register has to be rebuilt from expense records rather than written forward, and that takes days rather than hours once a company is past twenty people.
The other reason teams stall is that the register arrives with forty rows and no way to tell which of them matter. A file storage provider holding every customer document and a stock photo subscription are not the same risk, and running the same assessment on both wastes the effort that should have gone on the first one.
Tick the kinds of vendor you use and answer four questions about your data. This returns three tiers with the review depth for each, what your auditor will ask about a vendor in that tier, and the Canadian privacy obligations that attach where personal information leaves your systems.
The tiering appears on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Allow one working day. If you would rather talk it through, book a time.
What actually decides a tier
Two questions, in this order. Could this vendor see or hold customer data, and could its failure stop you serving customers. A vendor that answers yes to either is in the top tier regardless of what it costs, and cost is a poor proxy in both directions: a free error tracking tool can receive production stack traces containing personal information, while an expensive design subscription holds nothing at all.
The third question, which changes the paperwork rather than the tier, is whether the vendor processes personal information on your behalf. Under PIPEDA you remain accountable for personal information transferred to a third party for processing, and the mechanism the law expects is contractual. That is why a data processing agreement sits in the evidence list next to the security report.
Reading a vendor report rather than filing it
Collecting a vendor's own audit report and putting it in a folder is not a review, and an auditor asking what you did with it is the moment that becomes obvious. Four things to actually read. The opinion itself, because a qualified one changes your answer. The period covered, because a report ending eight months ago leaves a gap you have to bridge. The exceptions listed, and whether any of them touch how you use the service. And the complementary user entity controls, which is the section listing what the vendor assumes you are doing, and which is where your own obligations quietly live.
Write four sentences per report recording what you found and date it. That note is the evidence. The report is only the input. The vendor management policy page covers what the policy has to say, and CC9 risk mitigation covers where this sits in the criteria.
Common questions
Does every vendor need a security review?
No, and treating them equally is the reason registers stall. What every vendor needs is a row: name, what it does, what data it holds, who owns the relationship, and its tier. Only the top tier needs a report read and a documented assessment. The middle tier needs a questionnaire or a published security page on file. The bottom tier needs the row and nothing else.
What if a vendor has no audit report to give us?
That is common below a certain vendor size and it is not automatically disqualifying. Ask for what they do have: a security page, a questionnaire response, a certification, a penetration test summary. Record what you asked for, what you received, and why you accepted the risk. A documented decision to accept a gap is a control operating. An undocumented one is a gap.
How often does a vendor review have to happen?
Annually for the top tier is the standard position, plus a review at selection and whenever the relationship materially changes. Your own policy sets the cadence and the auditor tests you against it, so avoid writing quarterly into a policy for a task you will do once a year.
Do contract developers count as vendors?
Yes, and they are frequently missed because they arrive through payroll rather than procurement. Anyone with access to production, source code or customer data belongs in the register with a signed confidentiality agreement, and they also belong in the population your access review is reconciled against.
Want the register built rather than described
Send your vendor list and what each one holds, and Canadian firms that do readiness work will tier it and write the assessments.
Get matched