Third-Party Risk Assessor
Reviews vendor questionnaires, SOC reports, and contracts for GRC risk exposure.
Analyzes vendor security questionnaires (SIG, CAIQ, custom), SOC 2 reports, penetration test summaries, and MSAs to produce a vendor risk score and gap list. Flags exceptions, subprocessors, and contractual gaps.
Try a sample prompt:
Vendor Risk Assessment · Vanta Inc.
Vendor type: SaaS / Compliance automation · Data shared: evidence artifacts, system metadata, user lists
Documents reviewed: SOC 2 Type II (period: Jan 1 – Dec 31, 2024), CAIQ v4.0.3, DPA v2.1
Risk Score: 4 / 10 (Low–Moderate) · Recommendation: APPROVE with annual review
SOC 2 Report Analysis
Report period: Jan 1, 2024 – Dec 31, 2024 (12 months) ✓
Opinion: Unqualified ✓
Auditor: A2LA-accredited CPA firm (recognized) ✓
Report age: 16 weeks since opinion date — well within 12-month freshness window ✓
Exceptions Noted
The auditor identified ONE exception:
> CC8.1 — During testing of change management, the auditor identified 2 of 25 sampled changes that lacked documented peer review prior to production deployment. Vanta management has implemented additional automated gate controls and the issue did not recur in the final quarter.
Assessment: Low impact. Management response is credible (automated gates verifiable). Monitor for recurrence in next report.
Complementary User Entity Controls (CUECs)
Vanta lists 11 CUECs that Acme is responsible for:
6 – 11. (all green)
One gap to close: Document Vanta alert review process and assign owner.
CAIQ Analysis
221 of 261 questions answered "Yes" with evidence references. Red flags:
- DSI-04 (data deletion): Vanta retains backups for 90 days post-termination. Verify against our DPA termination clause.
- HRS-09 (background check standard): Vanta confirms checks but does not disclose criteria. Acceptable for SOC 2; insufficient for FedRAMP if we ever expand.
DPA Analysis
| Clause | Status |
| Subprocessor list | ✓ Disclosed (AWS, Stripe, Datadog, Sendgrid) |
| Subprocessor notification | ✓ 30 days |
| Audit rights | ⚠ Customer has rights via SOC 2 only, not direct audit |
| Breach notification | ✓ 72 hours |
| Data location | ✓ US-only confirmed |
| Termination data return | ✓ 30 days, encrypted format |
| Indemnification | ⚠ Capped at 12 months of fees — negotiate uplift if data volumes grow |
Pen Test Evidence
External pen test attestation provided dated 2025-09 (8 months old) ✓. Two high findings remediated per attestation. Acceptable.
Red Flags Summary
None blocking. Three watch items: