Summary. Most significant data breaches now arrive through a vendor, and most vendor security reviews are a questionnaire nobody reads attached to a contract nobody negotiated. The controls that matter are a small set: knowing what data the vendor receives, tiering the review to the risk, obtaining independent assurance rather than self-attestation, and negotiating a handful of contract terms that determine who bears the loss. This checklist covers inventory and tiering, the diligence appropriate to each tier, the technical and organizational questions worth asking, subprocessors and data location, the contract provisions that allocate breach cost and preserve audit and exit rights, and the ongoing monitoring and offboarding most programs skip.


What this checklist is for. Assessing and contracting with a vendor that will hold or access the company's data. For the contract framework generally, see Cloud and SaaS Agreements: Service Levels, Data Rights, Security, and Exit.


Phase 1 — Know what the vendor gets, and tier accordingly

  • Identify what data the vendor will receive, access, store, or transmit — categories, volume, and sensitivity.
  • Flag regulated data: protected health information, personal data subject to comprehensive privacy statutes, financial account information, children's data, biometric data, government or contract-sensitive information, and anything subject to export control.
  • Identify whether the vendor becomes a business associate under HIPAA, a service provider or processor under privacy statutes, or a third-party service provider under a sector rule that imposes direct diligence obligations.
  • Identify the access path: hosted service, on-premises software, remote administrative access, physical access, or an integration with production systems.
  • Assess business criticality — what happens to operations if the vendor is unavailable for a week.
  • Tier the vendor: critical (regulated or high-volume sensitive data, or operationally essential), moderate, and low. Apply proportionate diligence, because a program that treats every vendor identically either over-invests everywhere or is abandoned.
  • Maintain a vendor inventory with the tier, the data categories, the business owner, the contract dates, the last assessment date, and the renewal or termination dates.

Phase 2 — Independent assurance, not self-attestation

  • Request a current SOC 2 Type II report — Type II tests operating effectiveness over a period; Type I only describes the design, and accepting a Type I where a Type II is available is the most common diligence shortcut.
  • Read the report, do not file it: the scope and the trust services criteria covered, the observation period, the exceptions noted, management's responses, and the complementary user entity controls the company is expected to implement.
  • Confirm the report covers the service and the environment actually being purchased.
  • Alternatively or additionally, request ISO 27001 certification with the statement of applicability, HITRUST, PCI DSS attestation, or FedRAMP authorization where applicable.
  • Request a summary of the most recent penetration test and the remediation status of findings.
  • Request the vulnerability management cadence and the patching service levels by severity.
  • Where no independent assurance exists — common for smaller vendors — escalate the questionnaire, request evidence for the answers, and price the additional risk.

Phase 3 — Technical and organizational questions worth asking

  • Encryption — at rest and in transit, the algorithms, and who manages the keys.
  • Access control — role-based access, least privilege, periodic access reviews, and how administrative access is granted and revoked.
  • Multifactor authentication — required for all remote and administrative access, without exception lists.
  • Logging and monitoring — what is logged, retention, and whether anyone reviews it.
  • Segmentation — whether the company's data is logically or physically separated from other customers'.
  • Personnel — background screening, security training, and the offboarding process.
  • Secure development — code review, dependency scanning, and separation of environments; confirm production data is not used in test environments.
  • Backup and recovery — frequency matched to a stated RPO, offline or immutable copies, and tested restoration with a stated time.
  • Business continuity — the vendor's own plan, its last exercise, and its dependencies.
  • Incident response — the plan, the last test, the notification process, and prior incidents and their handling.
  • Physical security of the facilities holding the data.
  • Governance — a named security leader, a written program, a risk assessment, and board or executive oversight.
  • Regulatory posture — any enforcement history, breach history, and outstanding findings.
  • Financial stability, because a failing vendor cuts security spending first.

Phase 4 — Subprocessors, location, and privacy

  • Obtain the subprocessor list, and confirm the vendor flows down equivalent obligations.
  • Negotiate notice of new subprocessors with a right to object, and — for critical vendors — prior approval.
  • Confirm where the data will be stored and processed, at the country and, where it matters, the region level.
  • For cross-border transfers, confirm the mechanism — an adequacy decision, standard contractual clauses, or another lawful basis — and any localization requirement in the source jurisdiction.
  • Confirm the vendor's ability to support individual rights requests — access, deletion, correction, and portability — within the statutory timelines the company must meet.
  • Confirm the vendor will not use the data for its own purposes, including product improvement, model training, analytics, or benchmarking, without separate written authorization — and get this in the contract, because default terms in many agreements permit exactly that.
  • Confirm the treatment of de-identified or aggregated data, which is the usual mechanism by which the prohibition is circumvented.
  • Confirm the vendor will not sell or share the data as those terms are defined in applicable privacy statutes.
  • Confirm any required data processing agreement, business associate agreement, or state-mandated contract terms are executed before any data is disclosed.

Phase 5 — The contract terms that decide who bears the loss

  • A defined security standard — not "commercially reasonable security," but a stated framework and a specific control set incorporated by reference, with an obligation to maintain certification.
  • A breach notification clock measured in hours, not days — 24 to 72 hours from discovery, with the content specified. The company's own regulatory clocks run from the vendor's discovery in several regimes, so a 30-day vendor clock is unusable.
  • Cooperation obligations in investigation, remediation, and notification, including access to forensic findings.
  • Allocation of notification and remediation costs, which for a large incident is the entire economic question and which a general indemnity does not clearly cover.
  • Indemnification for data breach and privacy violations, and — critically — a carve-out from the liability cap for those obligations. A vendor whose liability is capped at twelve months of fees has effectively insured nothing.
  • Cyber insurance requirements with stated limits, evidence of coverage, and notice of cancellation.
  • Audit rights, or at minimum an annual right to receive the SOC 2 report, penetration test summaries, and remediation status, plus a right to audit on cause after an incident.
  • Subprocessor approval and flow-down.
  • Data ownership stated expressly, with a prohibition on retention beyond the term.
  • Return and deletion on termination, in a usable format, within a defined period, with written certification of deletion including from backups on a stated cycle.
  • Transition assistance on exit, for a defined period at defined rates.
  • Service levels with meaningful remedies, and a termination right for chronic failure.
  • Change control — notice before material changes to the security posture, the architecture, or the hosting location.
  • Compliance with law, and cooperation with the company's regulators.
  • Confirm the order of precedence among the master agreement, the data processing agreement, the security exhibit, and any online terms the vendor incorporates by URL — and confirm the vendor cannot amend the incorporated terms unilaterally.

Phase 6 — Ongoing monitoring and offboarding

  • Reassess on a schedule keyed to the tier — annually for critical, every two years for moderate, at renewal for low.
  • Obtain the updated SOC 2 report each year and read the exceptions, not just the opinion.
  • Track security incidents at the vendor, including publicly reported ones, and require prompt notice of any that could affect the company.
  • Monitor changes: acquisitions, new subprocessors, changed hosting locations, and changes in the vendor's own regulatory posture.
  • Confirm certifications remain current and have not lapsed.
  • Review access annually — which vendor personnel and systems still have credentials, and whether the access remains necessary.
  • Calendar renewal and termination notice dates, because auto-renewal removes the leverage to renegotiate the terms above.
  • On offboarding: revoke all access on a defined schedule, obtain return of data in a usable format, obtain written certification of deletion, confirm removal from any integration, retrieve equipment, and update the inventory.
  • Confirm any retained data the vendor is legally required to keep, and how it is protected.
  • Conduct a short post-mortem on any vendor terminated for performance or security reasons, and feed it into the next diligence cycle.

Common mistakes

  • Accepting a SOC 2 Type I where a Type II is available, or filing a Type II without reading the exceptions.
  • A questionnaire completed by the vendor's sales team, with no evidence requested.
  • "Commercially reasonable security" as the standard, which means whatever the vendor says it means.
  • A 30-day breach notification clock, which is longer than the company's own regulatory deadline.
  • A liability cap with no carve-out for data breach, so the indemnity is illusory.
  • No prohibition on secondary use, permitting the vendor to train models or build products on the company's data.
  • No subprocessor visibility, so the company cannot answer where its data is.
  • No deletion certification, so data persists after the relationship ends.
  • Assessing at onboarding and never again, while the vendor's environment and ownership change.
  • Signing before the data processing or business associate agreement is executed.

Primary authority

  • Federal: the HIPAA Security Rule and business associate requirements, 45 C.F.R. §§ 164.302–164.318 and § 164.504(e); the GLBA Safeguards Rule service provider oversight requirement, 16 C.F.R. Part 314; Section 5 of the FTC Act; the Bank Service Company Act, 12 U.S.C. § 1867(c), and the interagency guidance on third-party relationships; FAR 52.204-21 and DFARS 252.204-7012 flow-down obligations for government contractors.
  • State: comprehensive privacy statutes imposing contract requirements on service providers and processors; state data breach notification statutes; the NAIC Insurance Data Security Model Law's third-party oversight and 72-hour notification provisions as enacted; New York's cybersecurity regulation, 23 NYCRR Part 500, and its third-party service provider requirements.
  • Frameworks: NIST SP 800-161 (supply chain risk management), NIST Cybersecurity Framework, ISO 27001 and 27002, and the AICPA trust services criteria underlying SOC 2.

Related

This checklist is educational and not legal advice. Contractual and regulatory requirements for vendor oversight vary by industry, data type, and jurisdiction. Consult qualified privacy and technology counsel before contracting for services involving regulated data.