Vendor management for SOC 2 (CC9)
Vendor reviews are one of the most common first-year exceptions, and the fix takes about an hour a quarter. The register is not the control. Doing something with it is.
SOC 2 tests vendor management under the CC9 risk mitigation criteria, and what an auditor wants is narrow: a register of the vendors that matter, a risk rating you can justify, evidence that you assessed each significant vendor before onboarding them, and evidence that you reviewed them again inside the observation window. Most Canadian companies fail the last one. The register gets built during readiness and nothing happens to it for eleven months.
Which vendors belong in the register
Not all of them. A register with 140 rows including the coffee subscription is a register nobody maintains. The test is whether the vendor touches customer data, holds credentials into your systems, or supports the service your report covers.
| Tier | Examples | Onboarding | Ongoing |
|---|---|---|---|
| Critical | Cloud host, production database provider, managed security provider, payment processor | SOC 2 or ISO 27001 report reviewed, data processing agreement, architecture understood | Annual report review, recorded |
| High | Tools holding customer data, error tracking, analytics, support desk, email delivery | Report or a security questionnaire, data processing agreement | Annual review, lighter |
| Moderate | Internal tools with company data only: HR, payroll, finance | Basic due diligence, agreement in place | Review every one or two years |
| Low | No access to data or systems | Note in the register, nothing further | None |
Some of your critical vendors are also subservice organizations in the audit sense, which is a different classification with different consequences in the report. The subservice organizations page covers the distinction and the carve-out method.
The program, minimally
- Build the register from your expense records and your identity provider, not from memory. Both surfaces show vendors nobody remembers buying.
- Assign a tier to each one, with a sentence explaining why. The sentence is what makes the rating defensible to an auditor.
- For critical and high vendors, collect the current SOC 2 or ISO 27001 certificate and record the review. Reading the report takes half an hour each.
- Set one calendar date a quarter to review a slice of the register, so the whole thing gets covered inside the window without a single painful week.
- Put a security review step into procurement, so new vendors enter the register when they are bought rather than at audit time.
- Record offboarding: when a vendor is dropped, evidence the data was returned or destroyed and the access removed.
What the auditor asks to see
0 of 0 ready ยท
The Canadian layer
Vendor management is where Canadian privacy duties meet the audit, and the audit does not discharge them. Under PIPEDA you remain accountable for personal information transferred to a third party for processing, which is why the agreement matters as much as the report. Alberta's PIPA requires notifying individuals when a service provider outside Canada handles their personal information. Quebec's Law 25 requires a privacy impact assessment before personal information is communicated outside Quebec. None of that appears in a SOC 2 opinion.
The practical consequence is that your register needs two extra columns most templates omit: where the vendor stores data, and whether personal information goes to them. The data residency page covers what is required and what is myth, and GetAudited covers the PIPEDA obligations themselves.
Where the exception comes from
Almost every first-year vendor exception has the same shape: the policy says annual reviews, the register exists, and there is no evidence any review happened. Write the policy to match what you will actually do. If quarterly is fantasy, write annual. You are tested against your own policy, so a modest promise kept beats an ambitious one missed.
Get your third party program reviewed
Canadian firms will assess your vendor program as fixed-scope readiness work before your window starts.
Get matchedCommon questions
Does SOC 2 require a vendor management program?
The CC9 criteria require you to assess and manage risks from vendors and business partners, which in practice means a register, a risk rating, due diligence at onboarding and periodic review. The framework does not prescribe a tool or a format, so a maintained spreadsheet passes as readily as a platform module.
How many vendors should be in the register?
Only the ones that touch customer data, hold system access, or support the audited service. For a 40 person SaaS company that is usually 25 to 60 vendors, not the 150 line items in the expense report. An over-inflated register is harder to maintain and produces more exceptions, not fewer.
What if a critical vendor has no SOC 2 report?
Perform and document your own assessment: a security questionnaire, their published security documentation, contractual commitments, and a risk decision recorded by a named person. Auditors accept that. What they do not accept is a critical vendor with no report and no assessment.
How often do we have to review vendors?
Whatever your own policy says, which is what you will be tested against. Annual for critical and high tier vendors is the common and defensible choice. What matters more than frequency is that the reviews you promised actually happened inside the observation window and left a dated record.