Vendor risk management software is a system of record for the third parties that touch your data or your service: who they are, how much risk each one carries, what evidence you hold about them, and when each was last reviewed. Every major framework asks for that record in some form. SOC 2 puts it under the Common Criteria at CC9.2, ISO/IEC 27001:2022 under Annex A controls 5.19 to 5.22, and HIPAA under 164.308(b)(1) and 164.314(a). The software keeps the record current. It does not make any vendor safer, and it does not decide which vendors matter.
This guide maps what the software does to those requirements, sets out the life cycle the US banking agencies describe in their 2023 guidance, and lists what to check before you buy. It is written for the first compliance hire or the engineering lead who has inherited a spreadsheet of vendors and an audit date.
What the frameworks actually require
None of the major frameworks names a tool. Each asks for a process and the evidence that it ran. The ledger below lists the references an auditor will quote and what each one expects you to produce.
- CC9.2SOC 2: vendor and business partner riskRisks from vendors and business partners are assessed and managed. Evidence: the vendor inventory, risk ratings, reviews of vendor SOC reports, and follow-up on exceptions.Common Criteria
- A.5.19ISO 27001: information security in supplier relationshipsProcesses to manage the risks of using suppliers’ products and services.Annex A
- A.5.20ISO 27001: security within supplier agreementsSecurity requirements written into each agreement, not assumed.Annex A
- A.5.21ISO 27001: the ICT supply chainManaging risk in the technology supply chain behind your suppliers.Annex A
- A.5.22ISO 27001: monitoring and change of supplier servicesRegular monitoring and review of supplier performance and changes.Annex A
- 164.308(b)(1)HIPAA: business associate contractsSatisfactory assurances, through a business associate agreement, before PHI moves to a vendor. The required contents are in 164.314(a).Required
Read together they ask for the same four things: a complete list, a risk rating per vendor, evidence collected at onboarding and at intervals, and a contract that says what the vendor must do. Anything a tool offers beyond those four is convenience, which may be worth paying for but should be priced as such.
The life cycle the banking agencies describe
The clearest public description of the whole process comes from outside the compliance-software market. The Interagency Guidance on Third-Party Relationships: Risk Management, issued by the Federal Reserve Board, the FDIC and the OCC, final as of 6 June 2023 and published in the Federal Register on 9 June 2023, organises it into a life cycle and a governance layer. It is written for banks, but its structure fits any organisation that relies on vendors.
- 1PlanningDecide whether to use a third party at all, and what the relationship will need.
- 2Due diligence and third-party selectionCollect and assess the evidence before signing.
- 3Contract negotiationWrite the security, audit, breach notification and exit terms into the agreement.
- 4Ongoing monitoringRe-review at an interval set by the vendor’s risk, and when something changes.
- 5TerminationExit cleanly: data returned or destroyed, access removed, evidence kept.
- GovOversight, independent reviews, documentation and reportingThe governance layer that sits across all five stages.
The use of third parties does not diminish or remove banking organizations’ responsibilities to ensure that activities are performed in a safe and sound manner and in compliance with applicable laws and regulations.
Interagency Guidance on Third-Party Relationships: Risk Management, Federal Register, 9 June 2023
Most vendor risk tools are strongest at stages 2 and 4, due diligence and monitoring. Stages 3 and 5 are where real programmes break: security terms never negotiated into the contract, and vendors who keep access for months after the relationship ends. Check which stages a tool actually supports before assuming it covers the life cycle.
Not every vendor deserves the same review
The same guidance is explicit that effort should follow risk. It says that not all relationships present the same level of risk, so not all require the same oversight, and that a banking organisation tailors its practices “commensurate with the banking organization’s size, complexity, and risk profile and with the nature of the third-party relationship.” It also says that maintaining “a complete inventory” and periodically assessing each relationship is what lets you see when risk has changed.
- HighHosts customer data or production systemsCloud provider, database host, payroll, support desk with customer records. At onboarding: SOC 2 Type 2 or ISO 27001 certificate, a completed questionnaire, contract security terms, and a BAA if PHI is involved.Annually, and on any breach or change
- MediumSome access to internal data or usersHR tools, analytics, CRM. At onboarding: SOC 2 or ISO evidence where available, a short questionnaire, contract terms.Every one to two years
- LowNo access to sensitive dataOffice supplies, public tools with no login. At onboarding: an inventory entry and an owner.At renewal
That scheme is illustrative, not a requirement of any framework. The intervals are a common starting point; set your own and write the reasoning down, because an auditor will ask why.
What to look for in vendor risk management software
- An inventory you can trust: every vendor, an owner for each, the data it touches, and the tier. If the tool cannot import from your finance system or SSO, the inventory will drift.
- Evidence storage with dates: each SOC report, certificate and BAA attached with its period or expiry, and an alert before it lapses.
- Questionnaires sized to the tier: a short form for medium risk, a full one for high, not the same 300 questions for everyone.
- Monitoring between reviews: breach news, advisories and certification changes surfaced against the vendors you actually use.
- Links to the rest of the programme: a vendor finding should land in the risk register and map to the controls it affects, not live in a separate silo.
- Offboarding: a step that confirms access removed and data returned or destroyed, with the evidence kept.
What vendor risk management software cannot do
- It cannot make a vendor secure. It records what you know about the vendor; the vendor’s controls are the vendor’s.
- It cannot read a SOC report for you in any way an auditor will accept. Exceptions and complementary user entity controls need a person to judge their effect on you.
- It cannot negotiate the contract. Security, audit, breach notification and exit terms are agreed by people, before signature.
- It cannot turn a questionnaire into proof. A completed questionnaire is the vendor’s own statement; independent evidence is the SOC report or the certificate.
- It cannot decide your tiers. The tool applies the scheme; the risk judgement behind it is yours to make and defend.
For a company with fifteen vendors and one owner, a well-kept spreadsheet with dated evidence links meets every requirement above. Software earns its price when the list is long, the owners are many, and evidence lapses without anybody noticing.
Where Evidr fits, and the case against
Evidr’s vendor risk module starts from more than 230 pre-loaded vendors, monitors news, security advisories, CVE databases and regulatory filings for risk indicators, and raises alerts on breaches, CVEs and compliance changes. Each alert carries an impact analysis across SOC 2, ISO 27001 and HIPAA, and vendor risks are linked into the risk register. Evidr also tracks vendors’ public compliance evidence, such as SOC 2 reports, ISO 27001 certificates and HIPAA BAAs. AI-driven vendor risk assessments are included on the paid plans, which start with Growth at $499 a month billed annually.
The case against us is straightforward. If you have a short vendor list and one owner, the spreadsheet in the previous section is enough and costs nothing. And if your obligation is the interagency guidance at a bank, evaluate any tool, including ours, against all five stages and the governance layer, and confirm in a demo which stages it supports end to end, particularly contract negotiation and termination.