Why UprootSecurity asks you to review vendors — and what your auditor expects
UprootSecurity asks you to review your vendors because your auditor expects you to keep a complete list of the third parties you rely on, judge how risky each one is at least once a year, collect their security assurance reports, and keep that documentation on file. A vendor review is how you do all four in one pass — and completing a review is what turns your work into the evidence the compliance tests read.
What the control actually asks for
Every vendor review exists to satisfy four things. Get these right and the tests take care of themselves.
- A complete inventory. Your list has to match reality — every third party you depend on, not just the big ones. The tests can only check vendors that are already on the list, so a missing vendor is invisible to UprootSecurity and a classic audit finding.
- A risk judgment on record, refreshed at least yearly. You set each vendor's Risk Level. UprootSecurity's AI suggests a value, but the rating is yours to own — an auditor wants your judgment on file, not the tool's.
- Their assurance reports, collected and reviewed. A vendor's SOC 2 report (or SOC 3, or an equivalent) is the independent proof that their controls actually work. You collect it and attach it to the review.
- The documentation, retained. Completing a review keeps the reports and answers on file, timestamped, so you can show your work later.
What your auditor looks for
When an auditor tests this, they want to see four things line up: a vendor list that matches your contracts and invoices, a risk rating for each vendor that you can defend, evidence that you actually reviewed each key vendor within the last year, and the assurance reports on file. The recurring part is what they press on — a one-time review from two years ago reads as "we did this once for the audit," not "we manage vendor risk." Recent and complete is the standard.
Why yearly
The default Review Cycle is Yearly, and that's the floor most frameworks expect. A vendor's security posture drifts between reviews — they swap subprocessors, their SOC 2 lapses or renews, they have an incident. A review that's a year old is stale evidence. You can tighten the cycle to Half Yearly or Quarterly for a higher-risk vendor, but whatever cadence you pick, the review has to stay current. Once a vendor's next-review date passes, its status becomes Due for Review and the Vendor security reviews test starts failing until you complete a fresh one.
How a completed review becomes evidence
When you complete a review, UprootSecurity records the review date, sets the next-review date one cycle out from the day you complete it, marks the vendor Completed, and files whatever you uploaded. The four tests then read that record.

Two things trip people up here:
- Not every report satisfies a test. Only a SOC 2 report or SOC 3 report satisfies the Vendor SOC 2 reports check, and only a Service Agreement satisfies Third-party system connections. An ISO Report or a Pentest / VAPT Report is still worth collecting, but it doesn't satisfy any of these four — those feed your risk findings, not the tests.
- Each test needs every vendor covered. One overdue or never-reviewed vendor fails the whole test, not just its own row.
The Vendor risk level assessments check is the odd one out: it passes for every vendor simply because a Risk Level is always set. So treat the rating as an auditor question, not a test question. A tier you can't defend is an audit problem no matter what the test says.
Where this maps in your framework
You don't need to memorize the crosswalk — UprootSecurity maps these tests to the right controls for you. At a high level, this work ladders up to the vendors-and-business-partners criterion in SOC 2 and the supplier-relationship controls in ISO 27001. The behavior underneath every framework is the same: know your vendors, rate their risk, collect their assurance, and keep it current.
Common mistakes
- Treating a review as one-and-done. Vendor reviews expire. Complete a fresh one before the next-review date passes, or the vendor goes Due for Review.
- Uploading an ISO or pentest report and expecting the SOC 2 test to pass. Only a SOC 2 or SOC 3 report satisfies that one.
- Leaving the risk rating at the AI's suggestion without checking it. The suggestion is a starting point; the judgment on record has to be yours.
- Expecting any admin to run reviews. The review workflow runs as the assigned vendor owner. Assign an owner to every vendor so someone can actually complete its reviews.
