River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Vendor Risk Assessment Template

Four documents and four sheets that score a SOC 2 report against what you actually rely on, carve-outs and exceptions included.

Free download  ·  No account needed

Findings Memo

Callant Support Cloud, reviewed 12 August 2026

EvidenceSOC 2 Type II, period 1 Feb to 31 Oct 2025
OpinionUnqualified, Security and Confidentiality
Reliance points34, derived from our own data flow

Coverage

Tested in scope, no exception1955.9%
Tested, deviation in section 4411.8%
Carved out to a subservice organisation617.6%
Conditional on a control we have not implemented38.8%
Outside the criteria the vendor selected25.9%

A clean opinion is a scope, not a score

The opinion is unqualified and it answers 19 of the 34 things this data flow depends on. The other 15 are not a criticism of the report. They are what the report says once it is read against a flow it was never scoped around.

Staleness

285 days since the audited period ended. 224 days with no coverage of any kind, because the bridge letter is management’s own assertion and it stops at 31 December.

An unqualified SOC 2 opinion is not coverage, it is a scope. The vendor picked which trust services criteria the audit covers, which subservice organisations to carve out of it, and which controls to assume you operate yourself. Deviations get disclosed in a results section most readers never reach. All four of those can work against you at once while the cover page still reads clean, which is why the cover page is where most reviews stop.

So this pack scores the report against a list the vendor did not write. Derive one reliance point per thing your data flow depends on, then mark each as tested clean, deviated, carved out, conditional on a control you have not implemented, or outside the criteria entirely. On the worked example a support platform's clean report answers 19 of 34, which is 55.9%, and the 15 it misses each name an owner.

The second number is a date subtraction. The audited period ended 31 October and the report issued in December. A bridge letter carried the vendor's own assertion to 31 December, and the review ran the following August, which is 285 days past the period and 224 with no coverage at all. Send River the report, the subprocessor list and the questionnaire response, or take the Word documents and CSV sheets blank. Dating the renewal itself is a vendor renewal tracker job, and one contract read for the obligations you owe is another.

The five things that happen to a reliance point, and only one is coverage

The Reliance Map, the carve-outs behind six of its rows, and the controls the report assumes you operate.

Reliance Map

Eight of 34 illustrative rows for a fictional reviewer, Alderline, assessing a hosted support desk.

IDReliance pointStatusLocator
RP-01Ticket data encrypted in transittested cleanS4 p.61 CC6.7
RP-03Terminated vendor staff lose access in one daydeviationS4 p.66 CC6.2
RP-06Security logs reviewed on a defined cadencedeviationS4 p.74 CC7.2
RP-08Multi-factor authentication enforced on our usersCUEC-dependentS5 p.91
RP-14Ticket text in the search index is confidentialcarved outS3 p.35
RP-18Tier-1 triage sees only assigned ticketscarved outS3 p.35
RP-29Our data deleted within 30 days of exittested cleanS4 p.81 C1.2
RP-33Reachable during our support hoursout of scopeS1 p.3 opinion

RP-18 is the one to look at. An offshore desk reads ticket content directly, and the only place it appears in this report is a table row in the boundaries section.

No status without a locator. A blank status stays unanswered and goes on the questionnaire, because unanswered quietly becoming a pass is how a review produces a false clean.

Carve-outs

Six of the 34 reliance points sit behind four providers, all carved out of the description and the opinion both.

ProviderRolePtsEvidenceVerdict
Cloud hostingCompute, storage, backup3Current SOC 2 Type IIaccepted
Email and SMSNotifications1Current SOC 2 Type IIaccepted
Managed searchTicket search index1ISO 27001 onlypartial
Offshore deskFirst-line triage1noneopen

Four of six close on the subprocessors’ own reports. Two do not, and they are the two with people rather than platforms behind them.

Partial is not equivalent. The search provider’s ISO 27001 scope statement covers a management system without the confidentiality commitments the vendor made to us.

Cross-check the report’s table against the subprocessor list on the vendor’s own site. A provider on one and absent from the other is a gap neither document will ever show you.

User Entity Controls

Six listed at the very end of the report. Three not implemented, so three conclusions do not hold for this tenant.

Control the report assumes we operateStateOwnerDue
Enforce single sign-on and MFA on the tenantmissingIT30 Sep
Review user access quarterly, remove leaversmissingSupport ops15 Sep
Rotate the customer-managed key annuallymissingIT31 Oct
Configure retention on exported ticket datadone
Restrict API token scope to the minimumdone
Validate data before API submissiondone

Read the list a second time as a map of where the vendor knows its own design is thin. Asking us to enforce MFA says the tenant will accept passwords without it. Asking us to remove leavers says it will not.

These three are internal work and they never go on the vendor’s queue. A review closing with zero internal actions has almost certainly not reached this section.

What's in the pack

01

Reliance Map

One row per thing your data flow depends on, each carrying one of five statuses and the report section and page behind it.

02

Risk Register

One row per reliance point the report left uncovered, which is the only definition of a risk this pack recognises.

03

Exception Tracker

Three kinds of finding kept apart: questions to the vendor, subprocessor evidence requests, and internal actions that are yours alone.

04

Review Calendar

Re-review dates set from each vendor's audit cycle rather than the contract anniversary, because the report is what expires.

05

Risk Review Procedure

The six steps and the four triggers, written so a reviewer can check whether the scope and results are relevant to your own activity.

06

How to Read the SOC 2 Report

Section by section, with what to extract from each and why the last three sections are the ones that decide anything.

07

Findings Memo

The coverage fraction stated next to the opinion, then the deviations, the carve-outs and the date arithmetic behind both.

08

Approval Note

A decision in one of four forms with conditions written so each can be failed, plus the events that reopen it early.

How to use it

  1. 1

    Open in River, or take it blank

    Open the pack in River and hand it the vendor's evidence, or download the Word documents and CSV sheets and work through them yourself.

  2. 2

    Describe the flow first

    What crosses the boundary, and what they can reach without being sent anything. Standing access is the half most reviews never write down.

  3. 3

    Derive, then score

    Reliance points come from the flow. Only then does the report get opened, and each point gets one status and one locator.

  4. 4

    Split the findings, then decide

    Vendor questions, subprocessor requests and internal actions go to different owners. The approval carries their dates as conditions.

Frequently asked questions

Is this template free?

Yes. The zip is Word documents and CSV sheets with no account and no card behind it. Edit with AI is the optional half: River reads the report, derives the reliance points with you and scores each one. Other packs sit in the template library.

What format are the downloaded files?

Four Word documents and four CSV sheets in one zip. The sheets open in Excel, Numbers or Google Sheets untouched, and the memo and approval note open in Word or Pages. Nothing in the download is a proprietary format and nothing needs converting first.

The vendor's SOC 2 is clean. Is that not the answer?

It answers whatever the vendor scoped it to answer. Microsoft's own compliance documentation says most examinations have observations on one or more controls and that this is expected, and it points customers to the user entity responsibilities at the very end of the report. Both sections sit past where most reviews stop.

What is a bridge letter worth?

Less than people assume. Microsoft describes its own bridge letters as self-attestations rather than reports based on examinations by the auditor, issued for a period not yet audited. So a bridge letter extends the vendor's word, not the auditor's, and this pack reports the days with no audited coverage separately.

The vendor has no SOC 2 report at all. Now what?

The reliance map still works and becomes the questionnaire, because every row is a question with no answer yet. Set a fixed clock instead of an audit cycle, and keep the scope narrow until evidence exists. Two rows in the sample Review Calendar are exactly that case.

How do I handle a subprocessor with no report?

Ask for the commitments to flow down contractually, which is what supply-chain guidance asks for: NIST's C-SCRM publication tells readers to identify controls for flow down to sub-level contractors and to include them in agreements with sub-tier parties. That converts a permanent blind spot into somebody's obligation.

Is this the same as assessing our own risks?

No. This is one vendor at your boundary, scored against evidence they produced. Ranking your own exposures on likelihood and impact is a business risk assessment job, deciding whether to keep paying them is a software renewal one, and planning for their outage is continuity. Whether they are actually meeting what their contract promises is a separate performance review against the SLA itself.

Score the report against what you actually rely on

Take the Word documents and CSV sheets blank, or open this pack in River and let it read the report, the subprocessor list and the questionnaire first.

Edit with AI