Expert reviews of the reports your vendors send you
SOC reports, security programs and continuity plans, each reviewed by a certified assessor and summarized in a written review report you can act on and show an examiner. Order them standalone, or alongside the platform and our assessment services.
The review you need, at the depth it deserves
Each review has a defined scope, is performed by a certified assessor and ends in a written review report for the vendor.
SOC Report Review
SOC 1 and SOC 2 reports reviewed end to end: period and bridge letters, scope, opinion, exceptions, carve-outs and CUECs mapped to your controls. With optional AI assistance.
AICPA SOC 1 (SSAE 18) and SOC 2 Trust Services Criteria
Information Security Program Review
Governance, risk management, access control, vulnerability and patch management, incident response and third-party management, against the framework you choose.
Frameworks such as ISO/IEC 27001 and NIST CSF 2.0
Business Continuity Program Review
Business impact analysis, BCP and DR plans, RTO and RPO alignment with your needs, test evidence and crisis communications.
ISO 22301 and relevant regulator expectations, for example FFIEC business continuity guidance
SOC Report Review
A clean opinion is where a SOC review starts, not where it ends. Our assessors read the whole report, including what it leaves out and what it expects you to operate, and tell you what it means for your relationship with the vendor. Available with optional AI assistance.
What is covered
- Report type (SOC 1 or SOC 2, Type I or Type II), the period covered and its currency, including bridge letters
- Scope and the services covered, checked against the services you actually use
- Auditor opinion, including any qualification or emphasis
- Exceptions and deviations found in testing, with management’s response and their relevance to you
- Subservice organizations, and whether the carve-out or inclusive method applies
- Complementary user entity controls (CUECs) mapped to your own controls
Measured against: AICPA SOC 1 (SSAE 18) and SOC 2 Trust Services Criteria
- A written SOC review report with a clear conclusion
- Findings with severity, and the follow-up questions for the vendor
- CUECs listed against your controls, ready to assign owners
A certified VendRisk360 assessor performs the review, and a second expert quality-reviews it before the report is delivered.
Our assessorsInformation Security Program Review
When a vendor has no SOC report, or you need more than one, an expert review of its information security program shows how it is governed and run, measured against the framework you choose.
What is covered
- Governance, policies and security organization
- Risk management: how the vendor identifies, assesses and treats risk
- Access control, including privileged access and joiner, mover and leaver processes
- Vulnerability and patch management, including penetration test results
- Incident response, notification commitments and lessons learned
- Third-party management: how the vendor oversees its own suppliers
Measured against: Frameworks such as ISO/IEC 27001 and NIST CSF 2.0
- A written review report with a result for each program area
- Findings with severity and recommended remediation
- Gaps mapped to the framework you measure against
A certified VendRisk360 assessor performs the review, and a second expert quality-reviews it before the report is delivered.
Our assessorsBusiness Continuity Program Review
A continuity plan only matters if it would work for the services you depend on. Our assessors check the vendor’s program against your recovery needs and against the evidence that it has been tested.
What is covered
- Business impact analysis: scope, currency and the services it covers
- Business continuity and disaster recovery plans
- RTO and RPO alignment with your own recovery needs for each service
- Test evidence and results, including issues found and how they were closed
- Crisis communications, including how and when you would be notified
Measured against: ISO 22301 and relevant regulator expectations, for example FFIEC business continuity guidance
- A written review report with an RTO and RPO alignment view
- Findings with severity and recommended remediation
- Evidence gaps, such as tests outside your policy window
A certified VendRisk360 assessor performs the review, and a second expert quality-reviews it before the report is delivered.
Our assessorsCertified assessors, with a second expert on every report
Every review is performed by a VendRisk360 assessor with security, audit and risk credentials and experience in regulated programs. A second expert quality-reviews the work before the report reaches you.
AI is optional. The review is always done by an expert.
AI is an option you choose to switch on, and you can choose expert-only reviews. Where you opt in, it assists the assessor in exactly two places, and nowhere else.
Completeness checks and key-date extraction
On the evidence the vendor provides: expiration and effective dates, the period covered, the issuer, the document type and the scope. Missing, expired or out-of-scope items are flagged for follow-up.
An AI-assisted first pass on SOC reports
Within SOC Report Review only: a first pass that the expert assessor verifies, corrects and completes before anything is recorded or reported.
- Perform the review of a SOC report, a security program or a continuity program
- Rate risk, raise findings or reach a conclusion
- Write or sign the review report
- Replace the second-expert quality review
- Run at all, unless you choose to switch it on
Prefer expert-only? Choose it when you order. Every review, rating and conclusion is made by a certified assessor either way, and the reviewer is named in the report.
A written review report for every vendor
Every review ends in a report you can act on, file and hand to an examiner. If you use the platform, the results land on the vendor record too.
The review report
Scope and documents reviewed, a summary conclusion, what was covered, findings with severity, recommended remediation, and the named reviewer and quality reviewer. Delivered as PDF.
On the vendor record
On the platform, the conclusion, findings and CUECs are recorded against the vendor, so remediation can be tracked and the next assessment starts from them.
In board and examiner reporting
Review results flow into executive dashboards, board decks and the examiner package, alongside every other assessment. See board and executive reporting.
Standalone, or alongside what you already use
Order a single review when a report arrives, or build reviews into your program.
Standalone
With the platform
With our services
Works with the rest of VendRisk360
Vendor Lifecycle Management Platform
Manage vendors, request evidence, review, record and sign off
Learn moreVendor lifecycle
Intake to offboarding in one governed record
Learn moreNth-Party Intelligence
Fourth parties, concentration and systemic risk, CUECs
Learn moreBoard & Executive Reporting
Board packs, executive briefings and examiner-ready exports
Learn moreComprehensive Vendor Risk Assessment
You onboard the vendor; our certified assessors do the rest
Learn moreContinuous Monitoring
Outside-in monitoring: attack surface, shadow infrastructure, compromise
Learn moreReport review questions
What is a report-specific review?
A targeted expert review of one vendor report or program: a SOC 1 or SOC 2 report, the vendor’s information security program, or its business continuity program. Each review is performed by a certified VendRisk360 assessor and ends with a written review report for that vendor.
Do we need the platform or the assessment services to order one?
No. Report-specific reviews are available standalone, or alongside the Vendor Lifecycle Management Platform and our Comprehensive Vendor Risk Assessment and Continuous Monitoring services. If you use the platform, the results are recorded on the vendor record as well.
Is AI used in the reviews?
Only if you choose it. AI is an optional capability. Where you opt in, it assists in two places: completeness checks and key-date extraction on the documents the vendor provides, and an AI-assisted first pass on SOC reports that the assessor verifies. Every review, rating and conclusion is made by a certified assessor. You can choose expert-only reviews.
What does AI not do?
AI does not perform the review, rate risk, raise findings, reach conclusions or sign off. Information Security Program Reviews and Business Continuity Program Reviews are performed by assessors, with AI used at most for completeness checks and key-date extraction if you opt in.
Who performs the reviews?
Certified VendRisk360 assessors holding credentials such as CISSP, CISA, CISM, CRISC and ISO/IEC 27001 Lead Auditor and Lead Implementer, with PCI DSS implementation experience. A second expert quality-reviews the work before the report is delivered.
What do we receive?
A written review report for the vendor: the scope and documents reviewed, a summary conclusion, what was covered, findings with severity, recommended remediation and the names of the reviewer and quality reviewer. On the platform, the conclusion and findings are also recorded on the vendor record.
Can a review feed our board reporting?
Yes. On the platform, review conclusions and findings are part of the vendor record, so they flow into the executive dashboards, board decks and examiner package like any other assessment result.
Send us the report. Get an expert answer.
Tell us which vendors and reports you need reviewed, and whether you want AI assistance or expert-only review, and we will scope it with you.