GRC & Audit Support · Lesson 6 of 8
Reviewing a vendor
A vendor review should reflect the service, information, and access involved. A low-risk newsletter tool and a payroll processor deserve different scrutiny.
Follow the data into the vendor
Fictional shipping vendor assessment.
- Your organization
Shares customer addresses needed for shipping.
- Vendor boundary
Stores and processes those addresses; administrator access is not required.
- Review the lifecycle
Ask about protection, retention, deletion, and incident communication.
Read the visualWould a polished security brochure settle the review?
No. Seek evidence that addresses the particular service, data, access, and requirements.
Map the relationship
Identify the data handled, access granted, business dependency, and service scope.
Evaluate relevant evidence
Ask whether available reports cover the actual service and period. Record exceptions and unanswered questions.
Track a decision
Assign follow-up work and the authorized approval. A questionnaire is one input, not proof of security.
Put it in context
A vendor would store customer addresses but does not need administrator access. Your review records those boundaries and asks about protection, deletion, and incident communication.
Review the actual service and its risk, not just a company logo.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.