Vendor Security Review

Vendor Security Review

Vendor Security Review

A vendor security review examines certifications and audit reports, architecture and hosting arrangements, access controls, encryption practices, subprocessors, data location and retention, incident history, and contractual protections.

It typically combines a security questionnaire with review of the vendor's SOC 2 or ISO 27001 documentation.

Alternative Names:

Vendor Due Diligence, Security Assessment

Why it Matters?

A firm cannot promise clients better protection than its vendors contractually provide, which makes vendor review the mechanism by which confidentiality representations become accurate. The findings that most often matter are the ones vendors do not volunteer: which subprocessors handle data, where it is physically stored, and what happens to it after termination. Reviews should be repeated at renewal rather than performed once.

Frequently Confused with

Related terms

Frequently asked questions

What questions matter most in a vendor security review?

What questions matter most in a vendor security review?

Where data is stored, which subprocessors touch it, who holds encryption keys, what happens to data at termination, and whether the SOC 2 report contains exceptions.

How often should reviews be repeated?

How often should reviews be repeated?

At least at contract renewal, and whenever the vendor materially changes its architecture, subprocessors, or ownership.