Skip to content

Use case: vendor and third-party review

Decide what an outside company is allowed to hold, with the proof for it in the room.

A vendor review is a decision about what a company outside your control may hold, for how long, and on whose accountability. Bring the vendor's answers, the artifacts behind them, the contract that binds them, and the person who will carry whatever risk survives.

Request access

Access is limited. A person reviews every request.

The occasion

The review is convened by a date, not by an appetite for review.

Nobody opens a vendor review because it is interesting. It opens because a renewal is due, because a new data class is about to cross a boundary, or because someone asked a question the last review cannot answer. The occasion sets the deadline, and the deadline is usually why a review gets settled on the strength of a questionnaire.

What puts it on the calendar

  • A renewal or auto-renewal date lands, and the current terms carry forward unless someone decides otherwise.
  • A new data class, region, or subprocessor enters the vendor's path after the original clearance was given.
  • An incident, breach notice, or audit finding at the vendor forces the earlier clearance to be read again.
  • A customer or a regulator asks who holds their data and on what basis.

What has to be present before anything can be settled

  • The data classes actually crossing the boundary, not the ones the original request described.
  • A dated subprocessor list, rather than the one attached to the last review.
  • The contract clauses that bind retention, deletion, region, and breach notice.
  • The person who will carry the residual risk if it is accepted, present or represented.

A review that opens without these can still produce a decision. It cannot produce one that survives being read six months later.

Contested claims

Most of a vendor review is a set of claims nobody has tested.

A questionnaire is a list of assertions written by the party with the most to gain from them. The review is the work of putting each one against the artifact that would support it, and marking the ones where no artifact exists. The claims below recur in almost every vendor review, and the last one is not the vendor's.

  1. 01As stated

    The vendor is certified, and attaches the certificate.

    What the room asks of it

    A certificate names a scope and a period. The question is whether the systems that will hold your data sit inside that scope, and whether the period has lapsed.

    What would settle it

    The scope section of the report itself, read against the systems named in the integration, with the report date visible beside it.

  2. 02As stated

    Data stays in your region.

    What the room asks of it

    Residency answers usually describe primary storage. Backups, support tooling, and subprocessors are where the answer quietly stops being true.

    What would settle it

    A dated subprocessor list with regions, plus the contract clause that makes residency enforceable rather than aspirational.

  3. 03As stated

    Findings from the last security test are remediated.

    What the room asks of it

    Remediated by whom, verified how, and are the findings that were accepted rather than fixed written down anywhere the buyer can read them?

    What would settle it

    A remediation summary with dates and an owner, or an explicit acceptance from someone with the authority to accept it.

  4. 04As stated

    There is no alternative and the date cannot move.

    What the room asks of it

    The date is usually real. The absence of an alternative usually is not. A review that cannot say what the fallback costs is not weighing anything.

    What would settle it

    A named fallback with its cost and its date, or a statement on the record that no fallback was examined.

The room

Who is in the room, and what each of them answers for.

A vendor review fails when the person who wants the vendor is also the person who clears it. The room makes the separation explicit and keeps it visible in the record. Agents participate on the same terms as the people: each is answerable for a specific part of the evidence, including for reporting what it could not reach.

  • Risk owner

    Human

    Accepting or declining the residual risk under their own name, and the date that acceptance expires.

  • Requesting team

    Human

    The business need, the deadline, and the fallback if the vendor is declined.

  • Reviewer

    Human

    Reading the artifacts against the claims, and marking every claim no artifact supports.

  • Research agent

    Agent

    The vendor's public record, prior incidents, and current disclosures, with the sources it could not reach reported rather than omitted.

  • Document agent

    Agent

    Locating the contract and report passages each claim depends on, and quoting them with their source location.

Settled or held

A review ends in one of two states, and both of them are readable.

Either the decision is settled, with an owner and a date attached to it, or it is held, with the proof that is missing named. The second state is the one most tools cannot represent, and it is the one that keeps a deadline from deciding on the evidence's behalf.

Example of a settled decision. Not a customer record.

Cleared for the two data classes named, with regional processing restricted by contract.

Owner
The named risk owner, recorded as having accepted it.
Next reading
Read again at the renewal date, or sooner if a subprocessor changes.

Example of a held verdict. Not a customer record.

Held. The vendor cannot be cleared on the questionnaire alone.

Missing proof

  • The subprocessor list the vendor returned omits the two regions the contract restricts.
  • No named owner has accepted the residual risk the security test report leaves open.
  • The certificate attached covers a product line that does not include the service being bought.

What to bring: Bring the completed questionnaire and the artifacts behind it, the contract or the draft, the data classes actually in scope, and the name of the person who will carry the residual risk. Share only material you are authorized to bring into this review.

Access

Start an account, or request access to the cohort.

Request access for a bounded cohort settling vendor clearances with the artifacts, the contested claims, and the named acceptance held in one place.

An account is the door to the product as it stands today. Availability of the limited alpha is a separate question: a request is reviewed by a person and does not grant admission, an invitation, an account, a Room, entitlement, or payment access.