Skip to content
  • SOC 2
  • Audit

SOC 2 vendor management: what auditors expect from your third-party programme

Updated 7 min read

SOC 2 does not contain the words “vendor management programme”. It contains one criterion that says you assess and manage vendor risk, and an auditor who will ask you to show how. Companies going into their first audit often discover this in the readiness assessment, with fieldwork weeks away and a vendor list nobody has finished.

This guide explains how the Trust Services Criteria treat third parties, what a subservice organisation is and why it matters, exactly what evidence an auditor will sample, and a checklist for having it ready before the audit period closes.

Where vendors appear in the Trust Services Criteria

The 2017 Trust Services Criteria (with the 2022 points of focus) reference third parties in several places. The one that generates most vendor findings is CC9.2.

CriterionWhat it saysWhat the auditor looks for
CC9.2The entity assesses and manages risks associated with vendors and business partners.A vendor inventory, a risk assessment process, contracts with security terms, and evidence that vendors are monitored and reviewed.
CC3.2Risks to objectives are identified and analysed — including those arising from external parties.Vendor risk feeds the entity-level risk assessment, not a separate silo.
CC1.4 / CC2.3Commitment to competence; communication with external parties.Security requirements communicated to vendors, usually through contracts and onboarding.
CC6.1–CC6.3Logical access is restricted, provisioned and removed appropriately.Where vendors or contractors have system access, the same provisioning and review controls apply to them.
CC7.3 / CC7.4Security incidents are evaluated and responded to.Vendor breach notifications feed your incident process; contracts commit vendors to notify.

The points of focus under CC9.2 are worth reading in full. They name the elements the auditor will map your programme against: establishing requirements for vendors, assessing vendor risk, assigning responsibility, communicating expectations, monitoring vendor compliance, and terminating relationships — each with records.

Subservice organisations: the vendors inside your report

Some vendors are not just risks to manage; their controls are part of how you meet the criteria. Your cloud hosting provider is the standard example: your commitment to physical security and infrastructure availability rests on theirs. The reporting framework calls these subservice organisations, and gives you two ways to handle them.

  • Carve-out method (the usual choice). The subservice organisation’s controls are excluded from your report’s scope. Your system description names them, describes the services they provide, and lists the complementary subservice organisation controls (CSOCs) — the controls you assume they operate for your criteria to be met. The auditor expects you to have obtained their SOC report and confirmed those controls are covered.
  • Inclusive method. Their controls are tested within your audit. Rare in practice; it requires the vendor’s cooperation and the auditor’s access.

For a carved-out subservice organisation, your file should contain their current SOC report, a note of the period it covers and any bridge letter for the gap to your own period, the exceptions you noted, and the complementary user entity controls their report asks you to operate — with the name of the person on your side who operates each one.

The evidence an auditor will ask for

Auditors work by population and sample. They will ask for the full list of vendors, pick several — weighted toward the ones that matter — and ask for each one’s file. Expect requests for:

  1. The vendor management policy. Dated, approved, describing tiers, assessment requirements, cadence and exception handling.
  2. The vendor inventory as at the period end, with tier and internal owner for each vendor.
  3. For sampled vendors: the risk assessment (questionnaire and score, or the SOC report review), the evidence reviewed, the decision with approver and date, and the signed contract with security, confidentiality and notification terms.
  4. For subservice organisations: their SOC report, your review of it, the bridge letter if periods do not align, and the mapping of complementary user entity controls to your own controls.
  5. Evidence of monitoring: reassessments dated within the cadence, reviews triggered by incidents or changes, and offboarding records for vendors terminated in the period.
  6. Access records for vendors or contractors with system access, showing they were provisioned, reviewed and removed like employees.

What the auditor tests is operating effectiveness: not whether the policy is good, but whether you did what it says, for every vendor in scope, throughout the period. A single critical vendor with no assessment on file is an exception in the report.

Common vendor findings, and how to avoid them

FindingCauseFix
Vendor inventory incompleteList built from memory; shadow tools missedReconcile against accounts payable, expenses and SSO each quarter
Critical vendor not assessed in periodReview done at onboarding, never repeatedReassessment date set at close of each review; owner reminded automatically
SOC report obtained but not reviewedReport filed as a checkboxOne-page review note: opinion, period, exceptions, CUECs, conclusion
Contracts lack security termsVendor paper signed unreadMinimum clause set in policy; checked at onboarding, gap logged as a condition
Contractor access not reviewedVendors excluded from access reviewsVendor accounts included in the quarterly access review population

Pre-fieldwork checklist

Work through this at least a month before the audit period ends, so anything missing can still be done inside the period.

  • Vendor management policy is written, approved, dated, and describes what you actually do.
  • Vendor inventory is complete, reconciled, and every vendor has a tier and an owner.
  • Subservice organisations are identified and named consistently with the system description.
  • Each subservice organisation's SOC report is on file, reviewed, with a bridge letter if needed and CUECs mapped to owners.
  • Every critical and high-tier vendor has an assessment, evidence and decision dated within the policy's cadence.
  • Contracts for sampled-likely vendors contain security, confidentiality, breach-notification and termination terms.
  • Vendors with system access appear in the access review records.
  • Terminated vendors have offboarding records: access removed, data returned or deleted.
  • Exceptions accepted outside policy have a written rationale and a senior approver.

Where to go next

The assessment records the auditor samples are produced by the process in Vendor due diligence: a practical guide for small and mid-sized businesses; the tiering that decides which vendors need the full treatment is in Vendor risk tiering: how to classify third parties and set a review cadence. If you also hold or are pursuing ISO/IEC 27001, ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence maps the same records to Annex A, so one file serves both audits.

Frequently asked questions

Which SOC 2 criteria cover vendor management?
CC9.2 is the direct one: 'The entity assesses and manages risks associated with vendors and business partners.' It is supported by CC3.2 (identifying risks, including from third parties), CC1.4 and CC2.3 (communicating requirements to external parties), and CC6.x where vendors have access. If a vendor's controls are relied upon, the subservice organisation rules in the reporting framework also apply.
What is a subservice organisation in SOC 2?
A vendor whose controls are necessary, together with yours, to meet the trust services criteria — typically your cloud hosting provider. Your report either carves them out (describing what they do and the complementary subservice organisation controls you rely on) or includes them. Either way, the auditor expects you to have obtained and reviewed their SOC report.
Does every vendor need a SOC 2 report for my SOC 2 audit?
No. The auditor tests that you assess vendor risk in proportion to it. A critical vendor should have a SOC 2 report, ISO 27001 certificate or equivalent that you reviewed; a low-risk vendor needs only to be inventoried and tiered. What fails an audit is having no method, or not following the one you wrote down.
How far back does the auditor look at vendor reviews?
Across the audit period for a Type II report — usually six or twelve months. Vendors in the population during that period should have a review dated within your policy's cadence. A review that predates the period is fine if the cadence says it is still current.