Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ask vendors for evidence that matches the service’s risk, the data it handles, its access to your systems, and the impact of a failure. A practical review packet usually includes a completed security questionnaire, relevant independent assurance, security and privacy control information, applicable testing and remediation evidence, incident-response procedures, continuity and recovery evidence for important services, and details about subprocessors. Then verify that the evidence covers the actual service and review period. No certificate or document packet proves that a vendor is safe in every respect.

Start with the service and its risk

Define what the vendor will do before requesting documents: what data it receives, where it is processed, what systems it connects to, whether vendor staff can access your environment, and how much your operations depend on the service. The Federal Reserve’s interagency guidance says due diligence should be proportionate to the risk and complexity of the relationship. That guidance is directed at banking organizations, but the principle is useful more broadly: a supplier with no access to sensitive data does not need the same review as a critical cloud service.

For comparable vendors, apply the same core criteria. Add or deepen checks when a service has materially greater data exposure, system access, or business impact. Your request should be specific enough to establish what service, product version, environment, locations, and subcontractors the evidence covers.

What documents and evidence should you request?

1. A completed questionnaire tied to the engagement

Ask the vendor to complete your security questionnaire or an accepted framework-based equivalent. Include questions specific to the service: data flows, hosting, system connections, support access, and controls that matter to the planned use. A company-wide questionnaire alone may not explain how the particular product or engagement is secured. Google’s published supplier process separates organizational questions from project-specific questions and may result in remediation actions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Relevant independent assurance

Request an applicable SOC report, ISO 27001 certificate, or other independent assessment or certification. Check the covered organization and service, the report period or certification scope, exceptions, and any complementary customer responsibilities. A report is evidence to assess, not a blanket guarantee. The Federal Reserve advises considering whether an assessment’s scope and results are relevant to the activity being reviewed; Google lists SOC 2 Type II reports, SOC 3 reports, and ISO 27001 certifications among evidence it may request.

3. Security and privacy control information

Depending on the risk, request policies or a controlled summary of the vendor’s security and privacy practices. Useful topics include:

  • Access control, authentication, and workforce access management
  • Encryption and data handling
  • Logging, monitoring, and retention
  • Vulnerability management and patching
  • Secure development practices for software
  • Workforce security training

CISA’s supplier-assessment template asks about policies, controls, and practices. Federal Reserve guidance gives examples including multifactor authentication, end-to-end encryption, and secure source-code management.

4. Security testing and remediation evidence

For exposed software, cloud services, or integrations, consider requesting a recent penetration-test executive summary, the test’s scope and date, vulnerability-management evidence, and the status of material findings. A credible summary and follow-up may answer your risk questions without exposing sensitive exploit details. Google says it may request a penetration test depending on the documentation and may require one for SaaS used by Google; its criteria discuss scope and manual testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Incident-response procedures

Ask for the incident-response plan or a suitable summary, including how the vendor detects and investigates incidents, escalates them, assigns responsibility, and notifies customers. Make required notification timing and cooperation obligations explicit in the contract, tailored to the relationship and applicable law. CISA’s template addresses incident detection and response capabilities, while Federal Reserve guidance highlights documented processes, timelines, and accountability.

6. Continuity, backups, and recovery evidence

When an outage could cause meaningful harm, request continuity and disaster-recovery plans or a suitable summary. Ask about backup and restoration, recovery time and recovery point objectives, recent exercise results, redundancy, and material dependencies. Also establish how you could recover or transfer data and operations if the vendor cannot continue. Federal Reserve guidance recommends evaluating recovery plans, timeframes, test results, and resilience arrangements.

7. Subprocessor and software supply-chain information

Ask which material subcontractors or subprocessors support the service or handle your data, what they do, where relevant processing occurs, and how the vendor assesses and monitors them. For software supply-chain exposure, request provenance or component information—such as a software bill of materials (SBOM)—when useful and feasible, along with information about secure build, delivery, and update practices. NIST SP 1326 identifies provenance and supply-chain tiers as due-diligence components; NIST software supply-chain guidance discusses SBOMs, supplier attestations, and software-security information.

8. Contract terms that make the evidence actionable

Connect the review to written commitments appropriate to the service: permitted data use, security obligations, incident notice and cooperation, access to audit evidence, remediation, subprocessor changes, continuity, data return or deletion, and exit support. Federal Reserve guidance discusses tailoring contract provisions to relationship risk, including audit, remediation, and continuity obligations. Google’s process also notes contractual protections for sensitive data or integrations, including logging, hardening, data handling, and testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

9. Supplier identity and viability for critical services

For a critical supplier, technical controls may not be enough. Depending on the relationship, assess ownership and control, provenance, financial condition, operational experience, key personnel, resilience, and supply-chain tiers. NIST SP 1326 includes these considerations, while Federal Reserve guidance discusses ownership, financial condition, business experience, and personnel.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to evaluate the evidence

Do not treat a document’s presence as proof that the relevant risk is addressed. Review each item against these questions:

  • Relevance: Does it cover the service, product version, environment, data, and subcontractors in scope?
  • Independence and period: Who performed the assessment, what period or point in time does it cover, and what limitations apply?
  • Exceptions and response: What findings or control gaps were identified? Who owns remediation, and what is the target date?
  • Risk fit: Could a gap materially affect confidentiality, integrity, availability, compliance, customers, or critical operations in this relationship?
  • Continuity and exit: Can you recover or transfer data and operations if the service is interrupted or the supplier fails?

For vendor comparisons, use consistent criteria: assurance scope and freshness; control coverage and testing and remediation quality; data and subprocessor exposure; incident handling; recovery capability; and transparency of evidence. Do not assume that one report age, certification, or checklist applies to every service: the sources do not establish a universal report-age threshold or mandatory certification for all vendors.

What if a vendor cannot share a full report?

Ask whether the vendor can provide a redacted report, executive summary, independent attestation letter, controlled review under an NDA, or equivalent evidence. If the information remains unavailable, record the gap and consider added monitoring or controls, accepting the remaining risk, or selecting another provider. Federal Reserve guidance recognizes these alternatives when a third party does not provide desired information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Tailor the review to applicable obligations

The right packet depends on the jurisdiction, sector, data, contract, and service. Federal Reserve guidance is specifically for banking organizations, CISA’s template is a government supplier-assessment resource, NIST SP 1326 focuses on ICT suppliers, and NIST’s software supply-chain recommendations are particularly relevant to software. Google’s process describes Google’s own supplier requirements, not a universal standard. Have security, privacy, legal, and compliance stakeholders align the review and contract with the obligations that apply to your organization.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.