SimplyCPA
Quick Sheets/ISC/Third-Party & Vendor Risk

ISC — Quick Sheet

Third-Party & Vendor Risk

Read time: ~5 minutes

One-minute revision

  • You can outsource the process, never the responsibility
  • Life cycle: due diligence → contracting (SLAs, right to audit, data return, breach notice) → ongoing monitoring → exit
  • SOC review checks: period covered, exceptions, CUECs implemented, scope, subservice treatment
  • Inclusive method = subservice covered; carve-out = excluded, need separate assurance
  • Watch fourth-party and concentration risk