ctl-010
Critical vendor SOC reports are reviewed annually with exception follow-up.
- Type
- DETECTIVE
- Automation
- MANUAL
- Frequency
- ANNUAL
- Owner
- Procurement & TPRM
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Obtain and read the vendor SOC review procedure; confirm it defines the critical-vendor population and the annual review cadence.
- 2.Confirm the procedure requires documented follow-up on report exceptions, not just receipt of the report.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Select 25 critical vendors and confirm each SOC report was reviewed within the annual cadence.
- 2.For reports with exceptions, confirm a documented management response exists.
- 3.Confirm vendors without a current SOC report on file were escalated for a compensating assessment.
Linked risks
- Critical vendor failuremitigation 2
- Incomplete vendor due diligencemitigation 3
Framework mappings & latest test
STA-06STA-12
Latest test:PARTIAL2025-12-15