SOC 2 Control Implementation Guide

Vendor Risk

Ongoing Vendor Monitoring for SOC 2

Critical and high-risk vendors are reassessed and monitored based on risk, incidents, service changes, contract renewals, and control reliance.

Use this guide to put the control into operation, decide what records to retain, and check that an auditor can trace the evidence back to the work your team performed.

Maintained by GreenHat Security · Reviewed August 21, 2026

What this control should accomplish

Critical and high-risk vendors remain acceptable after onboarding because the company detects assurance changes, incidents, service deterioration, control concerns, and expanded use, then responds based on risk.

First SOC 2 program

A credible starting point

Set an annual review date for critical and high-risk vendors and subscribe to their security advisories and status notices. At each review, obtain current assurance information, compare it with the prior year, revisit open findings, and confirm that data use and service reliance have not changed.

As the company scales

Make it repeatable

Combine scheduled reassessment with continuous signals, contract renewal, architecture change, incident, financial-health, and performance workflows, routing material changes to vendor-risk, security, resilience, privacy, and business owners.

How to implement Ongoing Vendor Monitoring

  1. 1

    Set a monitoring plan by risk

    For each vendor tier, define reassessment frequency, required updated evidence, monitored signals, trigger events, accountable reviewers, and escalation thresholds.

    You should end up with: A monitoring plan and next-review date for every critical and high-risk vendor.

  2. 2

    Collect ongoing signals

    Monitor security advisories, status events, incidents, assurance expirations, control findings, contract renewals, service performance, ownership changes, and significant scope changes.

    You should end up with: Dated monitoring records with source, affected vendor, signal, and disposition.

  3. 3

    Perform periodic reassessment

    Obtain current assurance material, confirm the vendor profile and tier, reassess relevant findings, and verify that the reviewed evidence still covers the service in use.

    You should end up with: A completed reassessment with current scope, evidence, findings, tier, and risk decision.

  4. 4

    Compare changes over time

    Identify new report exceptions, expired certifications, changed external providers, incidents, reduced coverage, new data use, or greater service dependence since the prior review.

    You should end up with: A documented change analysis linked to updated risk and required actions.

  5. 5

    Respond to material signals

    Open findings, require vendor remediation, add safeguards, update contracts, reclassify the vendor, invoke continuity plans, or escalate continued use for risk acceptance as appropriate.

    You should end up with: A traceable decision and action record for each material concern.

  6. 6

    Report portfolio health

    Summarize overdue reviews, expired evidence, open high-impact findings, concentration, incidents, and risk decisions for management and service owners.

    You should end up with: A periodic vendor-risk dashboard with decisions and assigned follow-up.

Evidence to keep, and what it should prove

Build the evidence set in three layers: what defines the control, who approved or reviewed it, and what proves it operated. Collect operating records when the work happens so they remain dated, attributable, correctly scoped, and traceable to the underlying activity.

Before sharing, remove unrelated personal or customer data, never expose passwords, tokens, or secret values, preserve enough source context to authenticate the record, and use the secure exchange approved for the engagement.

Approval / review evidence

Records showing that an accountable person reviewed, approved, challenged, or accepted the work.

Annual reviews

  • Confirm what the record proves

    Critical and high-risk vendors received a scheduled reassessment of current use, tier, assurance, findings, incidents, service performance, and continued acceptability.

  • Include this context

    vendor and review identifier

  • Include this context

    tier and review period

  • Include this context

    reviewer and completion date

  • Include this context

    current-use and scope confirmation

  • Include this context

    findings and changes

  • Include this context

    decision and next review date

Weak evidence to avoid

A vendor record whose review date was advanced one year with no updated evidence, scope confirmation, findings comparison, reviewer, or continued-use decision.

SOC report reviews

  • Confirm what the record proves

    Updated service-auditor reports were assessed for current scope, opinion, exceptions, subservice organizations, complementary responsibilities, bridge-period considerations, and impact on vendor risk.

  • Include this context

    vendor service and report period

  • Include this context

    scope and opinion

  • Include this context

    exceptions and vendor response

  • Include this context

    subservice and user responsibilities

  • Include this context

    reviewer and review date

  • Include this context

    risk impact and actions

Weak evidence to avoid

A newly uploaded report with an updated reviewed date but no comparison of scope, exceptions, complementary responsibilities, coverage gap, or risk impact.

status page/security advisory reviews

  • Confirm what the record proves

    Vendor outage and security-advisory signals were monitored, assessed against company use and dependency, and escalated when material.

  • Include this context

    vendor and monitored source

  • Include this context

    event or advisory identifier

  • Include this context

    published and reviewed timestamps

  • Include this context

    affected vendor service

  • Include this context

    company impact decision

  • Include this context

    disposition or escalation

Weak evidence to avoid

An inbox subscription full of unread vendor notices with no review timestamps, affected-service mapping, impact decision, owner, or escalation record.

Operating / technical evidence

Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

monitoring logs

  • Confirm what the record proves

    Scheduled and event-driven vendor signals were collected and dispositioned, including evidence expirations, incidents, service changes, findings, and contract milestones.

  • Include this context

    vendor and signal type

  • Include this context

    source and event date

  • Include this context

    monitoring or review date

  • Include this context

    owner

  • Include this context

    materiality result

  • Include this context

    action and closure status

Weak evidence to avoid

A list of automated vendor ratings with no review owner, threshold, affected service, disposition, or evidence that a major score change was investigated.

Which records should you prepare for the audit?

Type 1

Evidence at the as-of date

Current monitoring requirements by tier, current critical and high-risk monitoring calendar, configured alert sources, and one recently completed reassessment with change analysis as of the examination date.

Type 2

Evidence across the review period

All scheduled reassessments due for critical and high-risk vendors and every incident, assurance expiration, material rating change, service change, contract renewal, or advisory signal requiring review during the period.

Completeness check

Reconcile the high and critical vendor population to the monitoring calendar, assurance expiration dates, incidents, renewals, and subscribed signals, then verify each due or triggered item has a documented disposition and completed follow-up.

Build the record set from

  • vendor risk management platform
  • vendor status and advisory feeds
  • security rating service
  • contract lifecycle management system
  • incident-management system

Keep these fields for each record

  • vendor, tier, and service
  • review or signal identifier
  • scheduled, event, and completion dates
  • source and affected scope
  • reviewer and materiality
  • risk change and decision
  • action status and next review

How an auditor may test this control

Use this checklist to prepare for procedures an auditor may perform. The exact steps and sample selection depend on your engagement scope and the service auditor's professional judgment.

  • Confirm the intended control outcome

    Determine whether the control is designed to achieve this result: Critical and high-risk vendors remain acceptable after onboarding because the company detects assurance changes, incidents, service deterioration, control concerns, and expanded use, then responds based on risk.

  • Confirm ownership and operating cadence

    Compare the documented owner with the intended role (Vendor Risk Owner / CISO / Legal), then compare dated records with the stated cadence: Prior to onboarding; periodic based on risk; at least annually for critical/high.

  • Establish the complete audit record set

    Reconcile the high and critical vendor population to the monitoring calendar, assurance expiration dates, incidents, renewals, and subscribed signals, then verify each due or triggered item has a documented disposition and completed follow-up.

  • Prepare the as-of-date evidence for a Type 1 engagement

    Current monitoring requirements by tier, current critical and high-risk monitoring calendar, configured alert sources, and one recently completed reassessment with change analysis as of the examination date.

  • Prepare period evidence for a Type 2 engagement

    All scheduled reassessments due for critical and high-risk vendors and every incident, assurance expiration, material rating change, service change, contract renewal, or advisory signal requiring review during the period.

  • Inspect the approval / review evidence

    Records showing that an accountable person reviewed, approved, challenged, or accepted the work.

    • Inspect Annual reviews

      For each selected record, confirm it demonstrates Critical and high-risk vendors received a scheduled reassessment of current use, tier, assurance, findings, incidents, service performance, and continued acceptability.

      • vendor and review identifier
      • tier and review period
      • reviewer and completion date
      • current-use and scope confirmation
      • findings and changes
      • decision and next review date
    • Inspect SOC report reviews

      For each selected record, confirm it demonstrates Updated service-auditor reports were assessed for current scope, opinion, exceptions, subservice organizations, complementary responsibilities, bridge-period considerations, and impact on vendor risk.

      • vendor service and report period
      • scope and opinion
      • exceptions and vendor response
      • subservice and user responsibilities
      • reviewer and review date
      • risk impact and actions
    • Inspect status page/security advisory reviews

      For each selected record, confirm it demonstrates Vendor outage and security-advisory signals were monitored, assessed against company use and dependency, and escalated when material.

      • vendor and monitored source
      • event or advisory identifier
      • published and reviewed timestamps
      • affected vendor service
      • company impact decision
      • disposition or escalation
  • Inspect the operating / technical evidence

    Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

    • Inspect monitoring logs

      For each selected record, confirm it demonstrates Scheduled and event-driven vendor signals were collected and dispositioned, including evidence expirations, incidents, service changes, findings, and contract milestones.

      • vendor and signal type
      • source and event date
      • monitoring or review date
      • owner
      • materiality result
      • action and closure status
  • Trace the control from design to operation

    Use the categories that apply to this control: connect any policy or design artifact to its approval or review record, then trace a selected operating record through execution, result, and any exception or remediation.

Common implementation and evidence gaps

  • The same vendor documents are collected each year without assessing scope, changes, exceptions, or continued relevance.
  • Monitoring happens only at contract renewal, leaving long gaps after incidents or material service changes.
  • Advisories and external alerts arrive, but no named owner must assess or close them.
  • Expired reports and certificates remain marked current in the vendor record.
  • Material findings do not change risk, safeguards, contract terms, continuity planning, or the decision to continue use.

Before you call this control ready

  • Does every critical and high-risk vendor have a current monitoring plan, review date, and accountable reviewer?
  • Can the company show how each material signal was assessed and resolved?
  • Do reassessments compare current scope, findings, evidence, data use, and dependency with the prior review?
  • Are expired assurance documents and overdue actions visible and escalated?
  • Does portfolio reporting help management see concentrated dependencies and vendors whose risk is worsening?

Trust Services Criteria references

These identifiers help you navigate related Trust Services Criteria. They do not reproduce the criteria or prove that this control fully addresses them in your environment.

  • CC4.1
  • CC9.2
  • A1.2

Confirm final scope, mappings, and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.