Skip to main content

Managing Vendors & Conducting Vendor Reviews

Track, assess, and review every vendor you work with — and stay compliant with SOC 2, ISO 27001, and beyond.

Upendra Varma avatar
Written by Upendra Varma
Updated over a week ago

Why Vendor Reviews Matter

Security frameworks like SOC 2, ISO 27001, and others expect your company to review the security posture of every vendor you rely on — especially if they have access to your data or systems.

Whether it's your cloud infrastructure provider, email service, analytics tool, or HR software — you’re responsible for understanding and mitigating the risks associated with each one. That’s where ComplyJet helps.

With ComplyJet, you can maintain a central list of all vendors, evaluate risk levels, assign ownership, and conduct structured reviews — all in one place.

Vendor Page

Once you start adding integrations, ComplyJet automatically lists those tools as vendors. For example, if you connect AWS, GitHub, or Google Workspace, they’ll appear here by default.

You can also manually add custom vendors — for tools or services that don’t have direct integrations. This ensures your full vendor landscape is tracked.

Performing a Vendor Review

For each vendor, your goal is to:

  1. Document key details

    • What the vendor is used for (e.g., “Primary cloud infrastructure”)

    • The assigned business owner and security owner

    • Any additional context or notes

  2. Assess vendor risk

    • How critical is this vendor to your business?

    • What kind of data do they handle?

    • What happens if the vendor goes down?

  3. Request security documentation

    • Ask for their SOC 2 report, ISO 27001 certification, penetration test results, or DPA.

    • If needed, send a custom vendor questionnaire.

  4. Review and Approve

    • Once you’ve reviewed the shared documentation and assessed the risk, approve or reject the vendor.

    • The vendor’s review status is updated accordingly.

Ongoing Vendor Monitoring

Performing a vendor review is not a one-time activity. Based on your internal Third-Party Risk Management Policy, you should re-review vendors:

  • Annually, for high-risk vendors

  • On any major change, like breach reports or new product usage

ComplyJet helps track the review date for each vendor, so you can stay on schedule and maintain audit-readiness.

Final Goal

To stay compliant and reduce third-party risk:

  • Ensure all vendors are tracked in ComplyJet

  • Conduct and record initial and periodic vendor reviews

  • Assign owners and maintain visibility over vendor risk

With ComplyJet, your entire vendor risk workflow becomes faster, traceable, and aligned with framework requirements.

Did this answer your question?