Skip to content
Report-Specific Reviews

Expert reviews of the reports your vendors send you

SOC reports, security programs and continuity plans, each reviewed by a certified assessor and summarized in a written review report you can act on and show an examiner. Order them standalone, or alongside the platform and our assessment services.

Three targeted reviews

The review you need, at the depth it deserves

Each review has a defined scope, is performed by a certified assessor and ends in a written review report for the vendor.

SOC Report Review

SOC 1 and SOC 2 reports reviewed end to end: period and bridge letters, scope, opinion, exceptions, carve-outs and CUECs mapped to your controls. With optional AI assistance.

AICPA SOC 1 (SSAE 18) and SOC 2 Trust Services Criteria

Information Security Program Review

Governance, risk management, access control, vulnerability and patch management, incident response and third-party management, against the framework you choose.

Frameworks such as ISO/IEC 27001 and NIST CSF 2.0

Business Continuity Program Review

Business impact analysis, BCP and DR plans, RTO and RPO alignment with your needs, test evidence and crisis communications.

ISO 22301 and relevant regulator expectations, for example FFIEC business continuity guidance

SOC 1 and SOC 2

SOC Report Review

A clean opinion is where a SOC review starts, not where it ends. Our assessors read the whole report, including what it leaves out and what it expects you to operate, and tell you what it means for your relationship with the vendor. Available with optional AI assistance.

What is covered

  • Report type (SOC 1 or SOC 2, Type I or Type II), the period covered and its currency, including bridge letters
  • Scope and the services covered, checked against the services you actually use
  • Auditor opinion, including any qualification or emphasis
  • Exceptions and deviations found in testing, with management’s response and their relevance to you
  • Subservice organizations, and whether the carve-out or inclusive method applies
  • Complementary user entity controls (CUECs) mapped to your own controls

Measured against: AICPA SOC 1 (SSAE 18) and SOC 2 Trust Services Criteria

What you receive
  • A written SOC review report with a clear conclusion
  • Findings with severity, and the follow-up questions for the vendor
  • CUECs listed against your controls, ready to assign owners
Who performs it

A certified VendRisk360 assessor performs the review, and a second expert quality-reviews it before the report is delivered.

Our assessors
Security program

Information Security Program Review

When a vendor has no SOC report, or you need more than one, an expert review of its information security program shows how it is governed and run, measured against the framework you choose.

What is covered

  • Governance, policies and security organization
  • Risk management: how the vendor identifies, assesses and treats risk
  • Access control, including privileged access and joiner, mover and leaver processes
  • Vulnerability and patch management, including penetration test results
  • Incident response, notification commitments and lessons learned
  • Third-party management: how the vendor oversees its own suppliers

Measured against: Frameworks such as ISO/IEC 27001 and NIST CSF 2.0

What you receive
  • A written review report with a result for each program area
  • Findings with severity and recommended remediation
  • Gaps mapped to the framework you measure against
Who performs it

A certified VendRisk360 assessor performs the review, and a second expert quality-reviews it before the report is delivered.

Our assessors
Resilience

Business Continuity Program Review

A continuity plan only matters if it would work for the services you depend on. Our assessors check the vendor’s program against your recovery needs and against the evidence that it has been tested.

What is covered

  • Business impact analysis: scope, currency and the services it covers
  • Business continuity and disaster recovery plans
  • RTO and RPO alignment with your own recovery needs for each service
  • Test evidence and results, including issues found and how they were closed
  • Crisis communications, including how and when you would be notified

Measured against: ISO 22301 and relevant regulator expectations, for example FFIEC business continuity guidance

What you receive
  • A written review report with an RTO and RPO alignment view
  • Findings with severity and recommended remediation
  • Evidence gaps, such as tests outside your policy window
Who performs it

A certified VendRisk360 assessor performs the review, and a second expert quality-reviews it before the report is delivered.

Our assessors
Who performs the reviews

Certified assessors, with a second expert on every report

Every review is performed by a VendRisk360 assessor with security, audit and risk credentials and experience in regulated programs. A second expert quality-reviews the work before the report reaches you.

CISSP
CISA
CISM
CRISC
ISO/IEC 27001 Lead Auditor
ISO/IEC 27001 Lead Implementer
PCI DSS implementation experience
Optional AI assistance

AI is optional. The review is always done by an expert.

AI is an option you choose to switch on, and you can choose expert-only reviews. Where you opt in, it assists the assessor in exactly two places, and nowhere else.

What AI does, if you opt in

Completeness checks and key-date extraction

On the evidence the vendor provides: expiration and effective dates, the period covered, the issuer, the document type and the scope. Missing, expired or out-of-scope items are flagged for follow-up.

An AI-assisted first pass on SOC reports

Within SOC Report Review only: a first pass that the expert assessor verifies, corrects and completes before anything is recorded or reported.

What AI does not do
  • Perform the review of a SOC report, a security program or a continuity program
  • Rate risk, raise findings or reach a conclusion
  • Write or sign the review report
  • Replace the second-expert quality review
  • Run at all, unless you choose to switch it on

Prefer expert-only? Choose it when you order. Every review, rating and conclusion is made by a certified assessor either way, and the reviewer is named in the report.

Reporting

A written review report for every vendor

Every review ends in a report you can act on, file and hand to an examiner. If you use the platform, the results land on the vendor record too.

The review report

Scope and documents reviewed, a summary conclusion, what was covered, findings with severity, recommended remediation, and the named reviewer and quality reviewer. Delivered as PDF.

On the vendor record

On the platform, the conclusion, findings and CUECs are recorded against the vendor, so remediation can be tracked and the next assessment starts from them.

In board and examiner reporting

Review results flow into executive dashboards, board decks and the examiner package, alongside every other assessment. See board and executive reporting.

How to order

Standalone, or alongside what you already use

Order a single review when a report arrives, or build reviews into your program.

Standalone

Send us the vendor and the report, or let us request it from the vendor. You receive the written review report, whether or not you use the platform.

With the platform

Your team runs its program on the platform and orders a review for any vendor. The report and its findings are recorded on the vendor record.

With our services

Add targeted reviews to Comprehensive Vendor Risk Assessment Services or Continuous Monitoring Services, for example when a monitoring signal calls for a closer look.
FAQ

Report review questions

What is a report-specific review?

A targeted expert review of one vendor report or program: a SOC 1 or SOC 2 report, the vendor’s information security program, or its business continuity program. Each review is performed by a certified VendRisk360 assessor and ends with a written review report for that vendor.

Do we need the platform or the assessment services to order one?

No. Report-specific reviews are available standalone, or alongside the Vendor Lifecycle Management Platform and our Comprehensive Vendor Risk Assessment and Continuous Monitoring services. If you use the platform, the results are recorded on the vendor record as well.

Is AI used in the reviews?

Only if you choose it. AI is an optional capability. Where you opt in, it assists in two places: completeness checks and key-date extraction on the documents the vendor provides, and an AI-assisted first pass on SOC reports that the assessor verifies. Every review, rating and conclusion is made by a certified assessor. You can choose expert-only reviews.

What does AI not do?

AI does not perform the review, rate risk, raise findings, reach conclusions or sign off. Information Security Program Reviews and Business Continuity Program Reviews are performed by assessors, with AI used at most for completeness checks and key-date extraction if you opt in.

Who performs the reviews?

Certified VendRisk360 assessors holding credentials such as CISSP, CISA, CISM, CRISC and ISO/IEC 27001 Lead Auditor and Lead Implementer, with PCI DSS implementation experience. A second expert quality-reviews the work before the report is delivered.

What do we receive?

A written review report for the vendor: the scope and documents reviewed, a summary conclusion, what was covered, findings with severity, recommended remediation and the names of the reviewer and quality reviewer. On the platform, the conclusion and findings are also recorded on the vendor record.

Can a review feed our board reporting?

Yes. On the platform, review conclusions and findings are part of the vendor record, so they flow into the executive dashboards, board decks and examiner package like any other assessment result.

Get started

Send us the report. Get an expert answer.

Tell us which vendors and reports you need reviewed, and whether you want AI assistance or expert-only review, and we will scope it with you.