CC9.2
Vendor and Business Partner Risks
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Assess and manage risks arising from vendors, subprocessors, business partners, and other external parties that can affect system commitments.
Points of focus
- Inventory external parties that support in-scope services
- Apply diligence and contract requirements proportionate to vendor risk
- Monitor vendor performance, security changes, and termination obligations
Implementation notes
Route every new SaaS integration through intake that records data classes, privileges, hosting region, and substitutability; block production credentials until risk review and contract terms are complete. Operationalize inventory external parties that support in-scope services in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain vendor inventory with tiering, data access, and service dependencies with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a cloud or ai subprocessor handles customer data but is absent from the risk inventory Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample vendor inventory with tiering, data access, and service dependencies with dates and named reviewers. Be ready to walk through how you detect and correct: a cloud or ai subprocessor handles customer data but is absent from the risk inventory
Evidence auditors typically request:
- Vendor inventory with tiering, data access, and service dependencies
- Completed diligence reviews and security addenda for critical subprocessors
- Renewal reviews, SLA reports, and offboarding evidence
Common gaps
- A cloud or AI subprocessor handles customer data but is absent from the risk inventory
- Procurement collects a SOC report once and never reviews exceptions or material changes
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC9.2 | This control |
| ISO 27001 | A.5.19, A.5.20, A.5.22 | Annex A supplier controls align with CC9.2 vendor diligence. |
| HIPAA | §164.308(b), baa-requirements | BAAs and vendor reviews satisfy HIPAA business-associate obligations. |
| GDPR | Article 28 | Article 28 processor terms parallel CC9.2 subservice oversight. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus