SOC 2 vendor management workflow (CC9.2, CC3.4)
A SOC 2-ready vendor management workflow: due diligence, risk assessment, contracting, ongoing monitoring, and offboarding — with approval gates and reviewer signatures captured for the Type II audit window.
Frequently asked questions
What does SOC 2 require for vendor management?
CC9.2 (third-party relationships) and CC3.4 (risk assessment for changes affecting controls) require documented procedures for due diligence, contract review, ongoing monitoring, and termination.
How does QueryChart help with a SOC 2 Type II audit?
Every workflow execution is captured in the immutable audit trail with author, timestamp, and approver signatures.