CC9.2: Vendor and business partner risk
The company assesses the security of vendors that touch its systems or data, puts security and confidentiality commitments in contracts, monitors them over time, and handles offboarding.
Category: Security (common criteria, required in every SOC 2 report) · Series: CC9 (Risk mitigation) · TSC 2017 (2022 points of focus)
That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.
Policies that address CC9.2
The Policyseed crosswalk points CC9.2 at 2 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.
- P16 Vendor and Third-Party Risk Management Policy, sections 4 (Policy Statements) and 5 (Procedures). Owner: Security Owner.
- P22 Privacy and Data Protection Policy, section 4 (Policy Statements). Owner: Security Owner.
Evidence examples for CC9.2
Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.
- Vendor inventory with data access level, criticality tier and review date for each vendor
- SOC 2 report review notes or completed security questionnaire for each critical vendor
- Signed vendor DPA or contract with security and confidentiality clauses
- Annual vendor review record signed by the Security Owner
Related criteria in CC9 (Risk mitigation)
Previous: CC9.1 Mitigating business disruption risk. Next: A1.1 Capacity management. All 38 criteria are listed on the template index.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.