SOC 2 vendor management workflow (CC9.2, CC3.4)

A SOC 2-ready vendor management workflow: due diligence, risk assessment, contracting, ongoing monitoring, and offboarding, with approval gates and reviewer signatures captured for the Type II audit window.

Use this template

How it works

  1. Set the risk tiers before you draw

    Two or three tiers are enough. Define them by data access and operational criticality, not contract value.

  2. Put the approval where the decision actually gets made

    If security has veto power over data processors, it needs its own approval step.

  3. Draw reassessment as a real loop

    Both the annual reassessment and the event-triggered reassessment (CC3.4) need to lead back into the process.

  4. Name the evidence for every step

    Note in the comment field what the documentation actually is: the assessment, the agreement, the approval, the offboarding receipt.

  5. Review the diagram with procurement and legal

    Vendor management crosses at least three departments.

Frequently asked questions

What does SOC 2 require for vendor management?

CC9.2 (third-party relationships) and CC3.4 (risk assessment for changes affecting controls) require documented procedures for due diligence, contract review, ongoing monitoring, and termination.

How does QueryChart help with a SOC 2 Type II audit?

Every workflow execution is captured in the immutable audit trail with author, timestamp, and approver signatures.

What's the difference between CC9.2 and CC3.4?

CC9.2 covers the vendor relationship itself. CC3.4 covers what happens when something changes and requires a fresh risk assessment.

Does every vendor need the full assessment?

No — classify vendors by data access and operational criticality, and only send the critical ones through the full path.

Use this template

More in Process flowchart templates

Browse all SOC 2 process templates