SOC 2 vendor management workflow (CC9.2, CC3.4)
A SOC 2-ready vendor management workflow: due diligence, risk assessment, contracting, ongoing monitoring, and offboarding, with approval gates and reviewer signatures captured for the Type II audit window.
How it works
Set the risk tiers before you draw
Two or three tiers are enough. Define them by data access and operational criticality, not contract value.
Put the approval where the decision actually gets made
If security has veto power over data processors, it needs its own approval step.
Draw reassessment as a real loop
Both the annual reassessment and the event-triggered reassessment (CC3.4) need to lead back into the process.
Name the evidence for every step
Note in the comment field what the documentation actually is: the assessment, the agreement, the approval, the offboarding receipt.
Review the diagram with procurement and legal
Vendor management crosses at least three departments.
Frequently asked questions
What does SOC 2 require for vendor management?
CC9.2 (third-party relationships) and CC3.4 (risk assessment for changes affecting controls) require documented procedures for due diligence, contract review, ongoing monitoring, and termination.
How does QueryChart help with a SOC 2 Type II audit?
Every workflow execution is captured in the immutable audit trail with author, timestamp, and approver signatures.
What's the difference between CC9.2 and CC3.4?
CC9.2 covers the vendor relationship itself. CC3.4 covers what happens when something changes and requires a fresh risk assessment.
Does every vendor need the full assessment?
No — classify vendors by data access and operational criticality, and only send the critical ones through the full path.