Software & TechnicalFree
Vendor SOC 2 Report Review
River reads the report against the products you use, then counts the criteria resting on a control you never built or a report you never read.
River's SOC 2 review turns a filed PDF into a register you can act on, one row per open item. The customer-side controls the report assumes you run come back split three ways: evidenced, performed but producing nothing, and not done. Beside them sit the criteria the vendor hands to a subservice organization you have never reviewed, the exceptions with their rates against your own volume, and the days between the examined period and today. Then a document arguing what the opinion is worth.
The guidance on page one is a reading order. Start with the opinion, move to the exceptions, then read the system description and map each complementary user entity control to an owner. That is sound and every one of them says it, which is why the answer everyone produces is a list of tasks nobody finishes. What none of them produces is a number: how many of the criteria the report appears to cover survive once its own assumptions are subtracted.
Built for whoever signs the renewal, and for the engineer handed a PDF and asked whether it is fine. Run it on the report you filed last year without opening, on the one that arrived this week, or on the renewal nobody has questioned in three years. The questionnaire the vendor sent you is a security questionnaire response, the commercial and technical side is a vendor review, and your own report is a SOC 2 evidence pack.
Three conditions, all of them countable
The first is the list of things the report assumes you do. Which of them apply is not a property of the list, it is a property of your account. AWS puts it plainly in its own shared responsibility model: customer responsibility is determined by the services the customer selects. So a list of thirty-four is never thirty-four tasks. Filtering it against the products you actually run is the first move, and it is the one that makes the rest finishable.
The second is the parties the report excludes. A vendor running on someone else's infrastructure carves that provider out and names the criteria it depends on them for. Those criteria are in the report, they look covered, and the evidence for them sits in a document you have not requested. The chain has a depth, and counting how many criteria hang off the end of it takes ten minutes once somebody looks. Asking a vendor for its own vendors' reports is the cheapest finding on the list.
The third is time. A Type 2 report covers a window that closed before it was written and keeps ageing after you file it. The PCAOB's standard on using a service auditor's report states the principle directly: the longer the time elapsed since the test was performed, the less support it provides. A bridge letter spans part of the gap, and it is management's own statement rather than anything an auditor examined.
How it works
Paste the report
Drop in the SOC 2, the products you use, and whatever your own control evidence looks like.
River filters it
Customer-side controls are matched to the products in your account and the rest set aside.
Read the register
One row per open item with an owner, a criterion, and what closing it needs.
Argue the renewal
Take the conditional criteria to the vendor, or to whoever wants the risk accepted.
What you get
- Every customer-side control the report lists, filtered to the products you actually use
- Each one split three ways: evidenced, done but unevidenced, or not done at all
- The criteria handed to a carved-out subservice organization, with the report you need
- Exceptions converted to rates and projected onto your own headcount or volume
- The days between the examined period and your renewal, and what spans them
- A count of the criteria that survive all three conditions, with the list that does not
Common questions
What do I have to give it?
The report, a list of which of the vendor's products you actually use, and whatever your own control evidence looks like. The last one can be thin. Where you cannot say whether a control exists, the row comes back as unknown with the question to ask, which is more useful than an assumed yes.
Why filter the customer-side controls at all?
Because a list written for every customer is not a list of your obligations. Loxbeare's thirty-four are spread across nine products and Ashmere uses four of them, so thirteen fall away with a reason recorded against each. A twenty-one item list gets worked through. A thirty-four item list of mostly irrelevant items gets abandoned in week two.
What is the difference between done and evidenced?
An artifact with a date on it. Seven of Ashmere's twenty-one applicable controls are genuinely performed and produce nothing anyone could show, which holds until an auditor or a customer asks. Those rows get an owner and a named place the evidence will live, rather than being counted as either passing or failing.
The report has a clean opinion. Is that not the answer?
It is the answer to a narrower question than the one you are asking. The opinion covers the vendor's controls over a closed period, on the services in the description, assuming the customer side holds and excluding the parties it carves out. Seventeen of Loxbeare's thirty-eight criteria depend on at least one of those conditions.
How does it handle the gap since the report period ended?
It counts the days and says what spans them. Loxbeare's period closed 152 days before Ashmere's renewal. A bridge letter covers 92 of those, and a bridge letter is management's assertion rather than an examined one. That leaves 60 days covered by nothing, which is a fact worth stating out loud before signing.
Does it do anything with the exceptions?
It converts them to rates and puts them on your numbers. An access removal exception in two of twenty-five sampled leavers, applied to Ashmere's 145 leavers a year, is 11.6 accounts left live past the stated window. The review then names which customer-side control would have compensated, and whether you run it.
We review dozens of vendors. Is this per report?
Per report, and the second one is faster because your own control evidence carries over. The output is a register row rather than a filed PDF, so a renewal a year later starts from what was open. The code your vendors ship you is a separate question, which the supply chain review answers.
Vendor SOC 2 Report Review
Fill in the form and your workspace opens with the work already underway.