ISC — Quick Sheet
Third-Party & Vendor Risk
Read time: ~5 minutes
One-minute revision
- You can outsource the process, never the responsibility
- Life cycle: due diligence → contracting (SLAs, right to audit, data return, breach notice) → ongoing monitoring → exit
- SOC review checks: period covered, exceptions, CUECs implemented, scope, subservice treatment
- Inclusive method = subservice covered; carve-out = excluded, need separate assurance
- Watch fourth-party and concentration risk