Vendor Security Review
Vendor risk decisions in 5 days, not 5 weeks
Every new vendor triggers a security review that takes 6-12 weeks. The security team requests SOC 2 reports, DPAs, pen-test summaries, questionnaires; the vendor's security team responds in batches; the reviewer reads a 200-page report to find the same 15 things they check every time. Meanwhile the business owner is blocked, the vendor is losing deal momentum, and the review queue grows. Vendors approved fast enough are the ones nobody actually reviewed.
An hour-by-hour walkthrough.
Step by step.
- 01
Pull public material + trust portal contents
Vendor's trust page, public SOC 2 (via shared trust portals), status page, security disclosures, published subprocessor list. Skip re-requesting what's already public.
Trust portals · Web scraping · Cert transparency - 02
Extract answers to standard dimensions with citations
Data handling, encryption at rest + in transit, access control, incident response, subprocessors, breach history, insurance, jurisdictional posture, sub-processor chain. Every extracted answer cites the source paragraph.
Document parsing · Reasoning · Dimension model - 03
Draft minimal questionnaire for unresolved items
Not a 200-question form — only the dimensions where the public material was silent or ambiguous. Vendor sees 15-30 targeted questions with clear expected answers; response time drops.
Email · Portal · Questionnaire generator - 04
Run external-signal collection + discrepancy check
Domain against breach databases, cert transparency, Shodan, vulnerability databases. Cross-check stated posture vs. observed. A vendor claiming TLS 1.3 with weak-cipher production endpoints is a discrepancy worth surfacing.
HIBP · Shodan · Cert transparency · Vuln databases - 05
Assemble review packet + route for decision
Review packet: risk score, answered dimensions with citations, open questions, discrepancies, recommended conditions (e.g. "approve subject to DPA signature"). Reviewer approves, declines, or requests more.
Web UI · Slack · Approval flow · Vendor management system
What you connect to make this run.
SafeBase · WhistleIC · Vanta Trust
readShared trust portals expose SOC 2, ISO 27001, subprocessor lists, security posture. Sig reads these instead of requesting the same reports vendors publish publicly.
Vendor management system · Coupa · Ironclad
read+writeRead vendor intake requests + attached procurement context. Write completed review packets + risk scores + approval status back to the vendor record. Feeds procurement + legal downstream.
HIBP · Shodan · Cert transparency · CVE feeds
readExternal-signal collection. Discrepancies between stated posture and observed reality are the single strongest signal for a targeted follow-up.
Email · Vendor portals
writeSend targeted questionnaires (not standard forms). Track responses + auto-nudge. Package responses into the review packet on receipt.
Before and after, honestly.
Playbooks that pair with this one.
Customer Security Questionnaire Support
Reverse side — filling out someone else's version of this questionnaire.
SOC2 / Vanta Evidence Collection
The trust-portal contents we publish for our vendors' Sig-equivalent to consume.
Vendor Intake & Onboarding
Runs in parallel with the finance vendor intake; both feed the go-live decision.
Answers about this playbook.
What if the vendor refuses to share their SOC 2 under NDA?
Sig flags this as a signal — refusing to share is common at smaller vendors but noteworthy at any vendor claiming SOC 2 attestation. Reviewer can accept an alternative (attestation letter, summary), require NDA-gated share, or escalate.
How does it handle re-reviews (annual renewals)?
Re-reviews compare the current state against the previous review. Changes in subprocessors, incident history, or posture surface as focused-review items. Same-as-last-year renewals close in minutes.
Can the risk score be customised per data class?
Yes — vendors handling PII, PCI, PHI, or source code have different weighting. A vendor with weak access control is low-risk for a marketing analytics tool, high-risk for a data-processing tool.
What about open-source dependencies (not a vendor per se)?
Different playbook — dependency review runs in CI + Snyk / Dependabot. This playbook is for commercial vendors with a contract and a data-handling relationship.
How does it feed into contract terms?
The review packet flags required contract terms: DPA signature, notification-of-incident SLA, indemnification for breaches, right-to-audit. Legal picks these up in contract negotiation.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.