The core principle
IMPORTANT: An organization can outsource a process, but it cannot outsource responsibility. Management remains accountable for the effectiveness of internal control over its financial reporting and for the protection of its data, no matter who performs the work.
Vendor risk management life cycle
- Due diligence before selection — financial stability, security posture, references, regulatory history, requesting a SOC report
- Contracting — service levels, security requirements, right to audit, data ownership and return on exit, breach notification timelines, subcontractor (fourth-party) restrictions, liability
- Ongoing monitoring — annual SOC report review, SLA performance, incident history, periodic reassessment based on criticality
- Termination / exit — data return or certified destruction, access revocation, transition support
Reviewing a SOC report properly
Receiving a SOC report is not the same as reading one. The user organization should evaluate:
- Does the period covered align with the user's reporting period? Is there a gap requiring bridge-letter follow-up?
- Is the opinion unmodified, and are there exceptions noted in the testing results?
- Are the complementary user entity controls (CUECs) actually implemented at the user organization?
- Does the scope cover the systems the user actually relies on?
- Are subservice organizations handled by the inclusive method (covered in the report) or the carve-out method (excluded, requiring separate assurance)?
EXAMPLE: A payroll provider's SOC 1 report uses the carve-out method for its cloud hosting subservice organization. The user entity cannot assume the hosting controls are covered — it must obtain separate assurance over the hosting provider or accept the residual risk.
EXAM TIP: Fourth-party risk — your vendor's vendors — is increasingly tested. Concentration risk also matters: if many critical vendors depend on the same cloud region, a single outage becomes an enterprise-level event.