A vendor security review examines certifications and audit reports, architecture and hosting arrangements, access controls, encryption practices, subprocessors, data location and retention, incident history, and contractual protections.
It typically combines a security questionnaire with review of the vendor's SOC 2 or ISO 27001 documentation.
Alternative Names:
Vendor Due Diligence, Security Assessment
Why it Matters?
A firm cannot promise clients better protection than its vendors contractually provide, which makes vendor review the mechanism by which confidentiality representations become accurate. The findings that most often matter are the ones vendors do not volunteer: which subprocessors handle data, where it is physically stored, and what happens to it after termination. Reviews should be repeated at renewal rather than performed once.
Frequently Confused with
Related terms
Frequently asked questions
What questions matter most in a vendor security review?
How often should reviews be repeated?





