An effective vendor management program is critical for any organization that relies on third-party services to achieve its business objectives. The purpose of this document is to highlight the critical elements of a vendor management process and, when applicable, discuss how the SOC 2® report aligns with that process.
The intended audiences for this document are:
Organizations looking to implement (or improve) a vendor management program
Auditors and other third-party program assessors who are reviewing controls and processes around a vendor management program
This paper explores the following key components of a successful vendor management program:
Governance
Policy
Third-party risk assessment reviews
Due diligence procedures
Evaluation of vendor controls
Ongoing monitoring