Agent Registry·Risk·Third-Party Risk Assessor
Riskclaude-opus-4-6Open source · Free to copy

Third-Party Risk Assessor

Reviews vendor questionnaires, SOC reports, and contracts for GRC risk exposure.

Analyzes vendor security questionnaires (SIG, CAIQ, custom), SOC 2 reports, penetration test summaries, and MSAs to produce a vendor risk score and gap list. Flags exceptions, subprocessors, and contractual gaps.

Tools:readglob
Frameworks:SOC 2ISO 27001SIG LiteCAIQNIST CSF
Use case 1
Vendor sends a SOC 2 report and you need to know if the qualifications and exceptions matter
Exception analysis, CUEC review, period gap calculation, and a clear accept / reject recommendation with conditions
Use case 2
Vendor sends a 200-question SIG Lite or CAIQ and you need to validate without spending a week
Scored response analysis with red-flag answers highlighted, follow-up questions queued, and risk-weighted score
Use case 3
Annual vendor review cycle for SOC 2 supplier management criterion
Refreshed vendor risk register and prioritized list of contracts requiring renegotiation or termination

Try a sample prompt:

third-party-risk-assessor · live demo · gemini-flash
◇ Curated sample output (real format)

Vendor Risk Assessment · Vanta Inc.

Vendor type: SaaS / Compliance automation · Data shared: evidence artifacts, system metadata, user lists

Documents reviewed: SOC 2 Type II (period: Jan 1 – Dec 31, 2024), CAIQ v4.0.3, DPA v2.1

Risk Score: 4 / 10 (Low–Moderate) · Recommendation: APPROVE with annual review


SOC 2 Report Analysis

Report period: Jan 1, 2024 – Dec 31, 2024 (12 months)

Opinion: Unqualified

Auditor: A2LA-accredited CPA firm (recognized)

Report age: 16 weeks since opinion date — well within 12-month freshness window

Exceptions Noted

The auditor identified ONE exception:

> CC8.1 — During testing of change management, the auditor identified 2 of 25 sampled changes that lacked documented peer review prior to production deployment. Vanta management has implemented additional automated gate controls and the issue did not recur in the final quarter.

Assessment: Low impact. Management response is credible (automated gates verifiable). Monitor for recurrence in next report.

Complementary User Entity Controls (CUECs)

Vanta lists 11 CUECs that Acme is responsible for:

1. Acme manages user provisioning for Vanta admin accounts (we do this)
2. Acme reviews access quarterly (we have evidence)
3. Acme retains responsibility for accuracy of integrated tool credentials (we do)
4. Acme is responsible for reviewing audit log alerts from Vanta within 5 business days (NO PROCESS DOCUMENTED — gap to close)
5. Acme classifies and approves evidence prior to auditor sharing (handled by GRC team)

6 – 11. (all green)

One gap to close: Document Vanta alert review process and assign owner.

CAIQ Analysis

221 of 261 questions answered "Yes" with evidence references. Red flags:

- DSI-04 (data deletion): Vanta retains backups for 90 days post-termination. Verify against our DPA termination clause.

- HRS-09 (background check standard): Vanta confirms checks but does not disclose criteria. Acceptable for SOC 2; insufficient for FedRAMP if we ever expand.

DPA Analysis

ClauseStatus
Subprocessor list Disclosed (AWS, Stripe, Datadog, Sendgrid)
Subprocessor notification 30 days
Audit rights Customer has rights via SOC 2 only, not direct audit
Breach notification 72 hours
Data location US-only confirmed
Termination data return 30 days, encrypted format
Indemnification Capped at 12 months of fees — negotiate uplift if data volumes grow

Pen Test Evidence

External pen test attestation provided dated 2025-09 (8 months old) . Two high findings remediated per attestation. Acceptable.


Red Flags Summary

None blocking. Three watch items:

1. CC8.1 exception — monitor next report
2. Acme CUEC #4 alert review process — close internally (90 days)
3. Audit rights limited to SOC 2 — negotiate direct audit clause if regulated data expands

Recommended Next Steps

1. Approve onboarding with conditions above
2. Set annual review for 2027-05 (report freshness check + CUEC verification)
3. Add Vanta to vendor concentration risk matrix (currently 14% of GRC spend)
Cmd+Enter to send