Control detail

Vendor SOC report review

ctl-010 · DETECTIVE · ANNUAL

ctl-010

Critical vendor SOC reports are reviewed annually with exception follow-up.

Key control
Type
DETECTIVE
Automation
MANUAL
Frequency
ANNUAL
Owner
Procurement & TPRM

Control Design Assessment (CDA)

Procedures evaluating whether the control is designed adequately.

  1. 1.Obtain and read the vendor SOC review procedure; confirm it defines the critical-vendor population and the annual review cadence.
  2. 2.Confirm the procedure requires documented follow-up on report exceptions, not just receipt of the report.

Control Operating Effectiveness (COE)

Procedures evaluating whether the control operated over the testing period.

  1. 1.Select 25 critical vendors and confirm each SOC report was reviewed within the annual cadence.
  2. 2.For reports with exceptions, confirm a documented management response exists.
  3. 3.Confirm vendors without a current SOC report on file were escalated for a compensating assessment.

Linked risks

  • Critical vendor failuremitigation 2
  • Incomplete vendor due diligencemitigation 3

Framework mappings & latest test

STA-06STA-12
Latest test:PARTIAL2025-12-15