FORM AWT-1 · AGENT CHECK SHEET · LIBRARY 1.0SCORER 1.0.0 · 8 PUBLIC SCENARIOS · SPECIMEN DATA
AI Agent Compliance Workflow Tester

Home / Rules / SOC 2 (Trust Services Criteria) / SOC 2 CC9.2 Assessing and managing vendor and business partner risk

SOC 2 CC9.2 Assessing and managing vendor and business partner risk

Risk from vendors and business partners is assessed and managed. Points of focus: engagement requirements cover scope and specification, roles, compliance duties and service levels; risks from vendors, partners and their own vendors are assessed periodically; responsibility for managing them is assigned; communication, resolution and exception-handling protocols are set; vendor and partner performance is assessed and issues are addressed; relationships are ended through defined procedures; in confidentiality engagements, confidentiality commitments consistent with the organisation's own are obtained and compliance checked; and in privacy engagements, privacy commitments are obtained, compliance assessed and corrective action taken. The 2022 revision adds: evaluating vulnerabilities created by vendor and partner relationships, including their access to the organisation's systems and network connections; keeping an inventory of vendors and partners and tiering them; considering threats such as a vendor's financial collapse, its security weaknesses, disruption to its operations, or its inability to satisfy business or regulatory obligations; setting review frequency by each vendor's risk; and ending relationships under procedures set in advance, which can cover getting data back securely and having it deleted from the vendor's systems.

SOC 2 (Trust Services Criteria). Edition: 2017 Trust Services Criteria with revised points of focus (2022). Checked 2026-10-07. Our statement of the clause, cited; the standard is licensed and not quoted. Official source. The framework on compliance.theartofservice.com.

Steps that cite it

Evidence commonly asked for

Accepted citation forms are listed on the answer format page.