Vendor security assessment

A structured review of a vendor's security controls, usually through a questionnaire, evidence such as audit reports, and follow-up questions.

Common formats include standard questionnaires, such as the Shared Assessments SIG or the Cloud Security Alliance’s CAIQ, and the vendor’s own trust center; evidence includes SOC 2 reports, ISO 27001 certificates and penetration test summaries. An assessment is a snapshot, so it is repeated on a schedule and paired with monitoring of what the vendor changes in between.

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.