Beyond SOC 2
What are the 5 stages of third party management?
What are the 5 stages of third party management?
The five stages are planning and sourcing, due diligence and selection, contracting, ongoing monitoring, and termination or offboarding. Together they describe a vendor relationship from before it exists to after it ends. The same lifecycle is often published as the five pillars of vendor management, and some frameworks split contracting from onboarding to make six, but the sequence does not change.
The five stages
| Stage | What happens | Evidence it produces |
|---|---|---|
| Planning and sourcing | Define the need, identify candidates, set risk criteria | Requirements, approved vendor criteria |
| Due diligence | Assess security, compliance, and financial standing | Completed questionnaires, SOC 2 or ISO reports, review records |
| Contracting | Negotiate terms including security obligations | Signed contract, DPA, BAA where PHI is involved |
| Ongoing monitoring | Reassess on a cadence set by risk tier | Periodic review records, refreshed attestation reports |
| Termination | Revoke access, retrieve or delete data, close the record | Offboarding checklist, access revocation evidence |
The two stages that fail
Ongoing monitoring fails because it has no natural trigger. Due diligence happens when someone wants to buy something, so it gets done. A reassessment twelve months later has nobody waiting on it. The usual result is a register full of vendors last reviewed on the day they were onboarded.
Termination fails worse, because it happens after anyone cares. Access is not revoked, data is not retrieved, and the vendor remains in the register indefinitely. This is where auditors find the most durable findings, since a departed vendor with live API credentials is a concrete exposure rather than a paperwork gap.
Risk tiering is what makes the lifecycle affordable
Reviewing every vendor at the same depth is not achievable, and programs that try either stall or become theatre. Tiering by data access and business criticality is what makes it work:
- Critical: processes production data or customer PII, or an outage stops the business. Annual review, SOC 2 or ISO report required.
- Moderate: internal data, replaceable. Lighter review, longer cadence.
- Low: no sensitive data access. Record the vendor, review at renewal.
The four common risk categories a review considers are cybersecurity, compliance and regulatory, operational, and financial, with reputational often added as a fifth. Most real vendors present several at once, which is why tiering by access beats tiering by category.
What SOC 2 and ISO 27001 test
- SOC 2 CC9.2 covers vendor and business partner risk management. The auditor asks for the vendor inventory, the criteria used to assess them, and evidence that reviews happened on the stated cadence.
- ISO 27001 Annex A 5.19 through 5.22 cover supplier relationships, agreements, ICT supply chain, and monitoring of supplier services.
Both test the cadence more than the depth. A program that reviews critical vendors annually and can show the records will do better than one with elaborate questionnaires that were only ever completed once.
The hard part is keeping the register current once the vendor count passes about thirty. See vendor management for how vendors get discovered from your codebase and infrastructure config, risk-tiered, and put on a review cadence automatically.