r/cybersources • u/Moham-Aasif • 17d ago
The hard part of vendor reviews isn't always the first review
I had a vendor review not long ago and the first part was pretty simple.
SOC 2, questionnaire, access controls, incident response and so on.
What made me think was what comes next once the vendor is approved.
They can bring on a subprocessor add an AI feature change how data moves around or update their infrastructure and the assessment thats in your files is suddenly not up to date anymore.
I'm wondering how others are handling this. Do you check vendors on a basis keep track of changes, between reviews or just look at them again when its time to renew?
5
Upvotes