Why Vendor Reviews Matter
Security frameworks like SOC 2, ISO 27001, and others expect your company to review the security posture of every vendor you rely on — especially if they have access to your data or systems.
Whether it's your cloud infrastructure provider, email service, analytics tool, or HR software — you’re responsible for understanding and mitigating the risks associated with each one. That’s where ComplyJet helps.
With ComplyJet, you can maintain a central list of all vendors, evaluate risk levels, assign ownership, and conduct structured reviews — all in one place.
Vendor Page
Once you start adding integrations, ComplyJet automatically lists those tools as vendors. For example, if you connect AWS, GitHub, or Google Workspace, they’ll appear here by default.
You can also manually add custom vendors — for tools or services that don’t have direct integrations. This ensures your full vendor landscape is tracked.
Performing a Vendor Review
For each vendor, your goal is to:
Document key details
What the vendor is used for (e.g., “Primary cloud infrastructure”)
The assigned business owner and security owner
Any additional context or notes
Assess vendor risk
How critical is this vendor to your business?
What kind of data do they handle?
What happens if the vendor goes down?
Request security documentation
Ask for their SOC 2 report, ISO 27001 certification, penetration test results, or DPA.
If needed, send a custom vendor questionnaire.
Review and Approve
Once you’ve reviewed the shared documentation and assessed the risk, approve or reject the vendor.
The vendor’s review status is updated accordingly.
Ongoing Vendor Monitoring
Performing a vendor review is not a one-time activity. Based on your internal Third-Party Risk Management Policy, you should re-review vendors:
Annually, for high-risk vendors
On any major change, like breach reports or new product usage
The Reviewed / In Progress / Never Reviewed tabs at the top of the Vendors page give you a running count of where every vendor stands, so you always know which ones still need attention. ComplyJet helps track the review date for each vendor, so you can stay on schedule and maintain audit-readiness.
Importing, exporting, and bulk editing
The More menu on the Vendors page lets you work with your vendor list in bulk rather than one at a time:
Import via CSV — bulk-add vendors from a spreadsheet.
Export — download your current vendor list as a CSV.
Manage Linked Tests — see which compliance tests are tied to which vendors.
Selecting one or more vendors with the checkboxes also gives you Bulk Edit (to update fields like Security Owner across several vendors at once) and Delete Vendors.
Final Goal
To stay compliant and reduce third-party risk:
Ensure all vendors are tracked in ComplyJet
Conduct and record initial and periodic vendor reviews
Assign owners and maintain visibility over vendor risk
With ComplyJet, your entire vendor risk workflow becomes faster, traceable, and aligned with framework requirements.






