A critical vendor will not share their SOC 2 report. What are our options?
If a critical vendor refuses to share their SOC 2 report, the primary options involve negotiating for a redacted version focusing on relevant controls, requesting alternative assurance documentation such as an ISO 27001 certificate or a detailed security questionnaire, or ultimately seeking an alternative vendor. This situation significantly elevates third-party risk, necessitating a thorough risk acceptance process if the vendor remains critical and non-compliant with information sharing requests, as the organisation must formally acknowledge the reduced assurance.
Vendors may withhold SOC 2 reports due to confidentiality concerns regarding their internal controls, competitive intelligence, or simply a policy to limit distribution. Practitioners must first ascertain the specific reasons for refusal and clarify the scope of the request, distinguishing between a Type 1 (design effectiveness) and Type 2 (operating effectiveness) report. Engaging in direct negotiation for a redacted report, focusing on the Trust Services Criteria relevant to the services provided, or requesting specific control descriptions and evidence, is often a pragmatic first step. Contractual agreements should ideally pre-empt such issues by mandating report sharing, specifying the type and frequency of reports.
Should direct report sharing or redaction prove impossible, alternative assurance mechanisms must be explored. An ISO 27001 certification, if available, provides a robust framework for information security management, though it is not a direct substitute for a SOC 2 report's specific control testing and scope. Other options include requesting a detailed security questionnaire (e.g., CAIQ, SIG), reviewing the vendor's internal audit reports (if shared under non-disclosure agreement), or, in rare cases for highly critical vendors, conducting an on-site audit, provided such rights are contractually established. Each alternative requires increased internal effort for review and validation, and the organisation must formally accept the residual risk associated with the reduced assurance.
Sources
- AICPA, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (SOC 2)
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements