Skip to content

    Articles tagged: Vendor Risk

    17 articles on Vendor Risk from the Top Floor insights library.

    • 2026-08-25

      What Is a Complementary User Entity Control (CUEC)?

      A CUEC is a control a vendor assumes you operate, and its auditor does not test it. Every SOC 2 report you receive hands you a list of them, and every report you issue should contain one. How to identify the ones you have inherited, evidence them, and write your own without shifting your obligations onto customers.

    • 2026-08-25

      How Long Does a Customer Security Review Take?

      From the seller's side, a customer security review takes as long as the buyer's process plus your own response latency, and only the second half is yours to move. The reviews that stall are rarely stalled by a missing control.

    • 2026-08-25

      Do Your Subprocessors Need Their Own SOC 2?

      No. Neither the SOC 2 description criteria nor the GDPR require a third party to hold its own SOC 2 report. What your report needs is evidence that you monitor the vendors whose controls you rely on, and the AICPA lists a vendor SOC 2 report as one monitoring method among several. What to do when a vendor has none.

    • 2026-08-23

      What Belongs in an AI System Inventory

      Nine fields, one row per system, and a definition of system that includes the tools you did not buy. The inventory is the artifact every AI governance framework assumes you have and the one companies most often do not.

    • 2026-08-23

      What Is a Data Processing Agreement, and When Do You Actually Need One?

      A DPA is the contract GDPR Article 28(3) requires between a controller and a processor, covering eight mandatory subjects. The EDPB's position is that an agreement which merely restates the Regulation is not doing the job.

    • 2026-08-23

      AOC or ROC: Which PCI Document Does Your Customer Actually Want?

      Your customer asks for your PCI report. Send the Attestation of Compliance, which the Council says is the document intended to be shared, and keep the Report on Compliance in house. Which one you must produce is decided by your acquirer, not by you and not by your assessor.

    • 2026-08-23

      How to Choose a SOC 2 Readiness Partner

      Three things you can verify about a SOC 2 partner before you sign, none of which is a testimonial: that your CPA firm is licensed and in peer review, that nobody sits on both sides of the readiness and opinion line, and that any arrangement between your partner, your platform and your auditor is on the table.

    • 2026-08-22

      Carve-Out or Inclusive? Subservice Organizations in Your SOC 2

      Almost every SOC 2 report carves out its cloud provider, and mostly for a reason that has nothing to do with preference. What carving out actually obliges you to disclose, and the one case where inclusive is worth the trouble.

    • 2026-08-21

      HITRUST Inheritance: What You Can Actually Reuse

      HITRUST says organisations can inherit as much as 70 to 85 percent of requirements from participating cloud providers. AWS attaches a conditional to that number which is where most of it goes. What inheritance moves, what it does not, and what HITRUST's public pages decline to explain.

    • 2026-08-20

      How to Answer the AI Questions on Security Questionnaires

      Enterprise reviewers ask three AI questions, and you do not need a certificate to clear them. Four documented artifacts do most of the work: an AI policy, an AI system inventory, a sub-processor list that names your model providers, and a written framework alignment statement.

    • 2026-08-19

      AI Vendor Risk Assessment: The Questions That Matter

      Six questions do most of the work in an AI vendor review. The standard instruments have caught up in form (CSA's AI-CAIQ runs to 320 questions) but length is not signal, and vendors still clear reviews that never press on the six.

    • 2026-08-16

      What a DORA Addendum Actually Asks You to Sign

      Nine baseline terms under Article 30(2), six more under Article 30(3) when your service supports a critical or important function. A clause-by-clause read of the addendum European financial customers are sending their technology vendors.

    • 2026-08-16

      What the EU Cyber Resilience Act Requires in an SBOM

      Annex I Part II makes a machine-readable software bill of materials a legal requirement, with top-level dependencies as the floor. It is documentation you hold and produce on request, not a file you publish.

    • 2026-08-16

      How to Read a Vendor's SOC 2 Report in Twenty Minutes

      Most vendor reviews open the exception table first and never check whether the report covers the product they are buying. Here is the order that catches real problems: opinion, period, scope, the controls the report assumes you operate, then exceptions.

    • 2026-08-16

      Do You Need a BAA? A Decision Guide for SaaS Vendors

      If protected health information can sit on your systems, plan on signing one, even encrypted, even if you never look at it. HHS said so in the Omnibus preamble in 2013 and the conduit exception is narrower than almost everyone assumes.

    • 2026-08-16

      Merchant or Service Provider? The PCI AOC Your Customers Want

      A merchant accepts cards for its own goods. A service provider handles or can affect the security of card data on someone else's behalf. Many SaaS companies are both, and sending the wrong attestation is how a vendor review stalls.

    • 2026-03-07

      Building a Vendor Risk Management Program from Scratch

      A step-by-step guide to inventorying vendors, classifying risk tiers, running assessments, and meeting SOC 2, ISO 27001, and NIST CSF supply chain requirements.