
Cyber Diligence Governance
- 27 installs
- 7 repo stars
- Updated May 20, 2026
- daemon-blockint-tech/agentic-enteprises-skill
Runs cyber due diligence and governance: M&A and vendor security assessments, questionnaire and evidence review, control maturity gaps, and IC/board briefs.
About
An agent skill for cyber due diligence and governance, covering M&A and investment diligence, third-party assessments, questionnaire and evidence review, control maturity gaps, and IC/board cyber briefs. An operator uses it for target or vendor security diligence, deal committee packs, or post-close integration planning.
- SIG/CAIQ review and control maturity gap assessment
- IC/board cyber briefs and governance cadence; draft only, approvers sign off
Cyber Diligence Governance by the numbers
- 27 all-time installs (skills.sh)
- Ranked #1,533 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill cyber-diligence-governanceAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 27 |
|---|---|
| repo stars | ★ 7 |
| Last updated | May 20, 2026 |
| Repository | daemon-blockint-tech/agentic-enteprises-skill ↗ |
What it does
Runs cyber due diligence and governance: M&A and vendor security assessments, questionnaire and evidence review, control maturity gaps, and IC/board briefs.
Files
Cyber Diligence & Governance
When to Use
- Scope and run M&A or investment cyber diligence on a target or portfolio company
- Plan vendor and third-party security assessments (onboarding, renewal, concentration)
- Review security questionnaires (SIG, CAIQ, custom) and map answers to evidence
- Perform control maturity and gap analysis for diligence or governance (not full audit)
- Assess integration and transition risk (identity, data, tooling, contracts, talent)
- Prepare investment committee, deal team, or board cyber briefs with red flags and asks
- Design ongoing security governance cadence (committee packs, exception reviews, metrics)
- Coordinate diligence workstreams with legal, IT, HR, and product without owning closing
When NOT to Use
- Execute authorized penetration tests or exploit validation →
penetration-tester,web-pentester,network-pentester - Classify AI use cases, model cards, or AI vendor data terms →
ai-risk-governance - Maintain enterprise risk registers, FAIR scoring, or risk appetite without deal/vendor lens →
security-risk-analyst - Stand up GRC programs, framework scope, or audit walkthrough prep →
compliance-specialist - Automate SOC 2/ISO evidence collection →
compliance-engineer - Negotiate contract redlines, DPAs, or liability terms →
commercial-counsel - Run closing matrix, signatures, funds flow, or data room logistics →
transaction-manager - Deploy IAM, SIEM, EDR, or remediate findings →
information-security-engineer - Define CISO program strategy, risk appetite, or board operating model →
chief-information-security-officer - Lead active incidents or SOC triage →
incident-responder,soc-analyst - Operate standing TPRM intake, scoring, and continuous vendor monitoring →
vendor-cyber-risk-analyst
Related skills
| Need | Skill |
|---|---|
| AI use-case tiers, model governance, AI vendor review | ai-risk-governance |
| Risk registers, inherent/residual scoring, treatment | security-risk-analyst |
| GRC program, audit prep, questionnaire response library | compliance-specialist |
| Contract, DPA, indemnity, and commercial terms | commercial-counsel |
| Deal timeline, diligence coordination, closing | transaction-manager |
| Control implementation and remediation engineering | information-security-engineer |
| Executive security strategy and board operating model | chief-information-security-officer |
| Pentest findings as diligence input | penetration-tester |
| Enterprise security program and IR policy | cybersecurity |
| Standing vendor TPRM operations and monitoring | vendor-cyber-risk-analyst |
Core Workflows
1. Scope and charter
Define diligence or governance boundaries, stakeholders, timeline, and deliverables.
See `references/cyber_diligence_governance_scope.md`.
2. M&A and investment diligence
Request lists, evidence review, finding severity, deal protections, and integration themes.
See `references/ma_and_investment_diligence.md`.
3. Vendor and TPRM assessments
Tier vendors, depth of review, concentration, and renewal triggers.
See `references/vendor_and_tprm_assessments.md`.
4. Questionnaire and evidence review
Consistent answers, evidence pointers, stale-response controls, and SME routing.
See `references/questionnaire_and_evidence_review.md`.
5. Governance cadence and reporting
Committee rhythms, IC/board packs, metrics, and exception governance.
See `references/governance_cadence_and_reporting.md`.
6. Red flags and remediation
Severity rubric, deal terms, integration backlog, and acceptance criteria.
See `references/red_flags_and_remediation.md`.
Outputs
- Diligence scope memo — objectives, in/out of scope, timeline, roles
- Request list and tracker — ID, owner, status, evidence received
- Findings register — severity, evidence, recommendation, owner, target date
- IC or board brief — executive summary, top risks, asks, integration implications
- Vendor assessment summary — tier, gaps, conditions, renewal date
- Integration security backlog — Day 1 / 30 / 90 with dependencies
- Governance pack outline — agenda, metrics, exceptions, decisions needed
Principles
- Evidence over assertions — require artifacts; flag questionnaire-only claims
- Materiality and deal context — prioritize what affects valuation, liability, or integration
- Separate roles — diligence analysis ≠ legal advice ≠ control implementation
- Time-boxed depth — match review intensity to tier, deal stage, and access granted
- Explicit handoffs — route legal terms, AI programs, and engineering fixes to peer skills
When to load references
- Boundaries and RACI →
references/cyber_diligence_governance_scope.md - Target or investment diligence →
references/ma_and_investment_diligence.md - Vendor tiers and TPRM →
references/vendor_and_tprm_assessments.md - SIG/CAIQ and evidence →
references/questionnaire_and_evidence_review.md - Committees and board rhythm →
references/governance_cadence_and_reporting.md - Severity and remediation →
references/red_flags_and_remediation.md
Cyber diligence and governance scope
Table of contents
1. Program purpose 2. In scope 3. Out of scope 4. Boundaries vs peer skills 5. Roles and RACI 6. Lifecycle and cadence
Program purpose
Enable informed decisions on cyber risk in transactions and third-party relationships by:
- Structuring diligence so findings are evidence-backed, prioritized, and actionable
- Supporting governance cadence so security posture and exceptions are visible to leadership
- Bridging deal, legal, and engineering without owning closing mechanics or control deployment
This skill covers analysis, synthesis, and governance design—not hands-on testing or tool configuration.
In scope
| Area | Examples |
|---|---|
| M&A / investment diligence | Request lists, VDR review, control maturity, breach history, integration risk |
| Vendor / TPRM | Tiering, assessments, concentration, renewal and offboarding |
| Questionnaires | SIG, CAIQ, custom portals; evidence mapping; consistency checks |
| Gap analysis | Control themes vs baseline (e.g., identity, vuln mgmt, IR, SDLC) for diligence context |
| Integration risk | Identity merge, data separation, tooling overlap, key-person dependency |
| Reporting | IC memo, board appendix, steering updates, remediation trackers |
| Governance | Security committee agenda, metrics, exception register review |
Out of scope
| Topic | Route to |
|---|---|
| Pentest execution and exploit proof | penetration-tester, web-pentester, network-pentester |
| AI use-case classification, model cards, AI policy | ai-risk-governance |
| Enterprise risk register, FAIR, appetite (standing program) | security-risk-analyst |
| GRC framework scope, audit prep, attestation | compliance-specialist |
| Evidence automation from IdP/CSPM/CI/CD | compliance-engineer |
| Contract redlines, DPA negotiation | commercial-counsel |
| Closing matrix, CPs, signing, funds flow | transaction-manager |
| IAM/SIEM/EDR implementation | information-security-engineer |
| CISO strategy, risk appetite, board operating model | chief-information-security-officer |
| Live CSIRT / SOC operations | incident-responder, soc-analyst |
| Standing TPRM intake, scoring, continuous monitoring | vendor-cyber-risk-analyst |
Boundaries vs peer skills
vendor-cyber-risk-analyst
- Vendor analyst owns: ongoing TPRM operations—intake queues, tiering at scale, questionnaire scoring, continuous monitoring, vendor risk dashboards, renewal/offboarding program execution.
- This skill owns: deal- and investment-weighted diligence (M&A, IC/board packs, integration risk) and governance cadence across transactions and leadership forums; vendor assessment in that context or when procurement needs a diligence-style summary.
- Handoff: Day-to-day vendor assessments and monitoring →
vendor-cyber-risk-analyst; M&A target review or IC cyber brief → this skill.
ai-risk-governance
- AI skill owns: model/system documentation, AI use-case tiers, AI acceptable use, AI vendor data/fine-tuning terms, NIST AI RMF / ISO 42001 / EU AI Act–style mapping for AI systems.
- This skill owns: enterprise cyber diligence on a target or vendor as a whole (including AI as one workstream), transaction integration of AI tooling, and board/deal narrative on cyber materiality.
- Handoff: When diligence centers on autonomous agents, training data, or regulated AI products, pull
ai-risk-governancefor tiering and documentation depth; fold summary into deal findings.
security-risk-analyst
- Risk analyst owns: ongoing risk register, inherent/residual scoring, treatment options, KRIs, and standing third-party risk tiers in the enterprise program.
- This skill owns: time-boxed diligence and governance packs for a specific deal, investment, or vendor event; findings that feed (not replace) the register.
- Handoff: After close or vendor approval, transfer accepted risks and mitigations to
security-risk-analystwith owners and review dates.
compliance-specialist
- Compliance owns: audit program, control matrices for attestation, continuous compliance operating model, approved questionnaire library maintenance.
- This skill owns: evaluating third-party or target responses during diligence/procurement; gap themes for deal terms; governance reporting on security posture.
- Handoff: Align questionnaire answers with compliance library where possible; escalate attestation scope changes to
compliance-specialist.
Roles and RACI
| Activity | Deal lead / Corp dev | Cyber diligence lead | Legal | IT / Security engineering | CISO / Security leadership |
|---|---|---|---|---|---|
| Diligence scope | A | R | C | C | I |
| Request list | C | R | C | C | I |
| Evidence review | I | R | C | C | C |
| Findings severity | C | R | C | C | A |
| IC / board brief | C | R | C | C | A |
| Deal protections (terms) | C | C | R | I | C |
| Post-close integration backlog | A | C | I | R | A |
R = responsible, A = accountable, C = consulted, I = informed. Adjust titles to your organization.
Lifecycle and cadence
| Phase | Typical activities |
|---|---|
| Plan | Scope memo, access plan (VDR, interviews), timeline vs signing |
| Execute | Requests, evidence triage, interviews, technical deep dives as needed |
| Synthesize | Findings register, red flags, valuation/integration implications |
| Decide | IC/board/deal committee; conditions, escrows, holdbacks (with legal) |
| Transition | Day 1 / 30 / 90 security backlog; identity and tooling integration |
| Operate | Quarterly governance pack; vendor renewals; exception expiry |
Review governance cadence at least quarterly; re-run diligence on material vendor or target changes.
Governance cadence and reporting
Table of contents
1. Governance forums 2. Standing agenda themes 3. Metrics and KRIs 4. IC and board packs 5. Exception and risk acceptance 6. Coordination with CISO and risk analyst
Governance forums
| Forum | Typical cadence | Primary audience |
|---|---|---|
| Security steering | Monthly | CISO, IT, engineering leads |
| Risk committee | Quarterly | Risk, legal, business owners |
| Deal / investment committee | Per transaction | Corp dev, finance, exec sponsors |
| Board / audit committee | Quarterly | Directors, audit committee |
This skill drafts content for these forums; chief-information-security-officer owns executive operating model and board relationship norms.
Standing agenda themes
Rotate focus to avoid static status slides:
1. Posture snapshot — top strengths and gaps vs prior quarter 2. Diligence pipeline — active M&A, major vendor assessments, status 3. Incidents and near-misses — material events, lessons, open actions 4. Program progress — remediation burndown, audit themes (high level) 5. Third-party risk — tier changes, concentration, expired certs 6. Integration — post-close backlog health (Day 30/90) 7. Decisions needed — exceptions, funding, policy exceptions
Keep compliance attestation narrative separate from risk and diligence narrative to avoid conflating audit readiness with deal risk.
Metrics and KRIs
Examples (tailor to organization):
| Metric | Use |
|---|---|
| Critical vendor assessments current | % within policy cadence |
| Open critical findings (diligence) | Count and age |
| Mean time to remediate diligence gaps | Post-close or vendor conditions |
| Questionnaire cycle time | Operational efficiency |
| Incidents with third-party root cause | TPRM signal |
| Admin MFA coverage | Integration / hygiene |
Pair activity metrics with outcome metrics where possible. Detailed KRI design → security-risk-analyst and chief-information-security-officer.
IC and board packs
Structure for deal or standing cyber brief:
1. Executive summary (≤1 page) — decision or ask 2. Context — deal/vendor/target, scope, access limitations 3. Top findings (3–7) — severity, evidence, business impact 4. Red flags — show-stoppers vs manageable gaps 5. Remediation / integration — cost, timeline, owners 6. Recommendations — proceed, conditions, pause, further diligence 7. Appendix — request tracker, detailed register (optional)
Use consistent severity labels across diligence and governance (see references/red_flags_and_remediation.md).
Avoid jargon walls; define acronyms once. Do not include privileged legal analysis without counsel review.
Exception and risk acceptance
For governance-approved exceptions (tooling, architecture, vendor):
| Field | Required |
|---|---|
| Exception ID | Stable identifier |
| Description | What is excepted and why |
| Owner | Business and technical |
| Expiry | Maximum 12 months unless re-approved |
| Compensating controls | Documented |
| Approver | Per policy (CISO, risk committee) |
Expired exceptions surface as standing agenda items. Transfer standing risks to security-risk-analyst register.
Coordination with CISO and risk analyst
| Need | Skill |
|---|---|
| Board operating model, risk appetite, crisis comms | chief-information-security-officer |
| Risk register rows, scoring methodology, treatment | security-risk-analyst |
| Audit program, control attestation | compliance-specialist |
| Deal process and timeline | transaction-manager |
Cyber diligence lead feeds risk analyst and CISO with transaction-specific findings; does not duplicate enterprise-wide register maintenance unless chartered.
M&A and investment diligence
Table of contents
1. Diligence objectives 2. Workstream setup 3. Request list themes 4. Evidence review 5. Interviews and technical sessions 6. Findings and deal implications 7. Integration planning
Diligence objectives
Clarify upfront:
| Question | Why it matters |
|---|---|
| Buyer role (strategic vs financial) | Depth of integration and control expectations |
| Deal structure (asset vs stock) | Liability for legacy incidents and contracts |
| Regulatory / sector overlay | Healthcare, finance, critical infrastructure, export |
| Known cyber events | Prior breaches, ransomware, regulatory actions |
| Material systems and data | PII, PHI, payment, IP, customer production |
Align objectives with deal lead and legal; coordinate timing with transaction-manager for VDR and Q&A hygiene.
Workstream setup
1. Charter — scope, exclusions, deliverables, deadline (signing vs close) 2. Access — VDR index, interview list, pen test reports (if available), policies 3. Tracker — request ID, owner, status, evidence link, follow-ups 4. SME map — identity, cloud, appsec, IR, privacy, IT general controls 5. Readout cadence — weekly steering; IC draft milestones
Do not duplicate process ownership held by transaction-manager; provide cyber content for their trackers.
Request list themes
Organize requests by control domain (adjust for target size):
| Domain | Example requests |
|---|---|
| Governance | Security policy set, org chart, board reporting, risk register summary |
| Identity | IdP/MFA, privileged access, joiner-mover-leaver, SSO footprint |
| Infrastructure | Cloud accounts, segmentation, CSPM summary, key management |
| Application | SDLC, secure coding, prod access, secrets management |
| Vulnerability | Scan cadence, critical open items, patch SLAs |
| Detection / IR | SIEM/EDR coverage, IR plan, tabletop date, prior incidents |
| Data protection | Classification, encryption, DLP, retention, subprocessors |
| Third parties | Critical vendors, SOC reports, concentration |
| Compliance | Certifications in scope, audit dates, open findings |
| Physical / OT | If applicable — separate workstream |
Prioritize material systems and customer data paths. Flag when target cannot produce evidence within timeline.
Evidence review
For each request:
1. Authenticate — date, scope, auditor/tester, version 2. Map — control intent vs artifact (policy alone ≠ operating effectiveness) 3. Test — sample consistency (e.g., access review ticket matches policy cadence) 4. Correlate — breach disclosures, customer churn, insurance claims, litigation mentions 5. Record — finding or clear pass with citation (document, page, date)
Use third-party reports (SOC 2, ISO) as starting points, not substitutes for targeted questions on gaps and incidents.
Interviews and technical sessions
| Audience | Focus |
|---|---|
| CISO / security lead | Program maturity, top risks, incidents, budget, key gaps |
| IT leadership | Infrastructure, migrations, technical debt, integration constraints |
| Engineering | SDLC, cloud footprint, secrets, prod access |
| Privacy / legal (security facts) | Breach history, regulatory inquiries (not legal advice) |
Prepare question trees; avoid leading assertions. Document quotes as attributed notes, not binding representations.
Findings and deal implications
Rate findings (see references/red_flags_and_remediation.md):
| Deal lever | When to consider (with legal) |
|---|---|
| Price adjustment | Quantified remediation cost or liability tail |
| Escrow / holdback | Unresolved critical gaps or unknown incident exposure |
| R&W / indemnity | Representation scope for security and privacy |
| Conditions precedent | Must-fix before close (e.g., MFA on admin, revoke compromised creds) |
| Post-close covenant | Milestones for integration or remediation |
Separate fact findings from legal recommendations; route terms to commercial-counsel.
Integration planning
Post-signing themes for security backlog:
| Workstream | Day 1 | 30 | 90 |
|---|---|---|---|
| Identity | Emergency access, disable risky integrations | SSO alignment, admin MFA | Full IAM integration plan |
| Tooling | EDR/SIEM visibility on combined estate | Consolidation decision | Decommission overlap |
| Data | Data map, legal hold awareness | Segregation / migration plan | Unified classification |
| Vendors | Critical subprocessor notice | Contract assignment | Renegotiate or replace |
| Culture | Comms to security teams | Policy harmonization | Training and attestations |
Hand engineering execution to information-security-engineer; program narrative to chief-information-security-officer where appropriate.
Questionnaire and evidence review
Table of contents
1. Questionnaire types 2. Review process 3. Evidence standards 4. Consistency and stale answers 5. SME routing 6. Outbound vs inbound
Questionnaire types
| Type | Notes |
|---|---|
| SIG / CAIQ | Standardized; map to internal baseline and library |
| Custom Excel / portal | Watch for ambiguous questions; document interpretations |
| Customer security review | Outbound — align with compliance library |
| Target / vendor inbound | This skill’s primary review mode |
| Lightweight attestation | Accept only for low tier with spot checks |
Review process
1. Triage — due date, tier, repeating vs net-new, deal sensitivity 2. Assign — cyber diligence lead coordinates; SMEs own sections 3. Answer mapping — map each question to control theme and required evidence 4. Verify — attach evidence or flag “assertion only” 5. Gap list — partial/missing controls with severity 6. Approval — security delegate before external send (outbound) or internal sign-off (inbound summary) 7. Archive — version, date, approver, evidence links for reuse
Evidence standards
Acceptable evidence hierarchy (strongest first):
1. Independent third-party report (SOC 2, ISO) — check period, scope, exceptions, bridge letter 2. Test results — pen test executive summary, vuln scan with remediation status 3. Operational records — tickets, access reviews, change records (sampled) 4. Configuration / architecture — diagrams, screenshots with date and system ID 5. Policy / procedure — necessary but insufficient alone
Reject or downgrade when:
- Report is expired or wrong entity (parent vs subsidiary)
- Scope excludes material services
- Marketing PDF with no auditor or test metadata
- “Planned” or “roadmap” without committed date and owner
Consistency and stale answers
Before reusing library answers (outbound) or trusting target responses (inbound):
| Check | Action |
|---|---|
| Same question, conflicting answers | Resolve with SME; document final position |
| Post-incident | Block reuse until security lead refresh |
| Post-M&A / reorg | Update subprocessors, IdP, and data flows |
| Certification lapse | Do not cite old SOC; request updated report or bridge |
Mark answers stale if older than 6 months for critical tier (adjust per policy).
SME routing
| Section theme | Typical SME |
|---|---|
| Organizational / governance | Security leadership or GRC |
| Identity / access | IAM or iam-specialist patterns |
| Cloud / network | Cloud security or engineering |
| App / SDLC | Appsec or engineering leadership |
| IR / BC | IR lead; BCM references for recovery claims |
| Privacy / data | Privacy office; legal for legal interpretations |
| AI / ML use of data | ai-risk-governance for model-specific claims |
Cyber diligence lead integrates SME input into one findings narrative.
Outbound vs inbound
| Direction | Primary owner | This skill’s role |
|---|---|---|
| Outbound (you answer customer) | compliance-specialist + library | Support deep deals; ensure consistency with diligence findings |
| Inbound (you assess vendor/target) | Cyber diligence lead | Lead analysis and evidence review |
Never state technical controls that engineering has not validated. Route unvalidated claims to information-security-engineer before external submission.
Red flags and remediation
Table of contents
1. Severity rubric 2. Common red flags 3. Deal and procurement responses 4. Remediation planning 5. Acceptance and residual risk 6. Pentest and audit inputs
Severity rubric
| Level | Definition | Typical action |
|---|---|---|
| Critical | Imminent material harm, active compromise, or deal stopper | Escalate immediately; pause or condition close |
| High | Major gap vs baseline; regulatory or customer breach likely if exploited | Remediate before close or strong covenant; price/escrow |
| Medium | Meaningful gap with compensating controls or clear path | Timed remediation; monitor |
| Low | Improvement opportunity; minor documentation drift | Backlog |
| Informational | Observation; no action required | Note only |
Document evidence, affected systems, and business impact for each finding.
Common red flags
| Signal | Why it matters |
|---|---|
| Undisclosed or poorly documented breach | Liability, integration, trust |
| No MFA on admin or prod access | Account takeover path |
| Stale SOC 2 or scope mismatch | Unknown control state |
| Critical vulns open beyond policy SLA | Exploit window |
| Shared credentials or no PAM on critical systems | Non-repudiation failure |
| Missing IR plan or no recent tabletop | Recovery uncertainty |
| Shadow IT / unknown cloud accounts | Data exfiltration, compliance |
| Weak SDLC on revenue-facing apps | Supply chain to customers |
| Subprocessor sprawl without notice | Privacy/regulatory exposure |
| Aggressive AI data use without governance | Route AI depth to ai-risk-governance |
| Concentration on one hosting or IdP provider | Blast radius |
Corroborate red flags with evidence; distinguish confirmed vs suspected.
Deal and procurement responses
| Response | When |
|---|---|
| Further diligence | Access or time insufficient; material unknowns |
| Conditions precedent | Fix before close (specific, testable) |
| Post-close covenant | Milestones with dates and verification |
| Escrow / holdback | Quantified remediation or liability tail |
| Price adjustment | Documented cost to remediate |
| Walk away | Critical unresolved exposure |
Coordinate legal mechanisms with commercial-counsel and deal process with transaction-manager. This skill supplies security fact pack and recommended posture, not binding legal advice.
Remediation planning
For each High/Medium finding:
1. Root cause — people, process, technology 2. Remediation action — specific, measurable 3. Owner — named role 4. Target date — aligned to Day 1 / 30 / 90 or vendor contract 5. Verification — how completion is proven 6. Dependency — budget, integration, vendor
Track in shared backlog; review in governance cadence (references/governance_cadence_and_reporting.md).
Acceptance and residual risk
When remediation before close is infeasible:
1. Document residual risk in business terms 2. Define compensating controls and monitoring 3. Obtain risk acceptance per policy with named approver and expiry 4. Register in security-risk-analyst risk register when material
Do not accept Critical findings without executive and legal alignment.
Pentest and audit inputs
| Source | Use in diligence |
|---|---|
| Third-party pen test | Validate scope, dates, retest status; do not re-run tests here |
| Vuln scans | Trend and SLA adherence |
| SOC/ISO reports | Control coverage; read exceptions and CARs |
| Internal audit | Thematic gaps |
Commission new testing via penetration-tester when deal risk justifies fresh validation; incorporate results into findings register.
Vendor and TPRM assessments
Table of contents
1. Assessment triggers 2. Vendor tiers 3. Depth of review by tier 4. Assessment workflow 5. Concentration and fourth parties 6. Renewal and offboarding 7. Alignment with compliance-specialist
Assessment triggers
Run or refresh assessment when:
- New vendor processes sensitive or regulated data
- Production access, source code, or customer-facing dependency
- Material contract (revenue, exclusivity, multi-year)
- M&A introduces new subprocessors
- Incident, breach notification, or certification lapse at vendor
- Change in processing location, subprocessors, or AI/ML use of customer data
Vendor tiers
| Tier | Criteria | Review cadence |
|---|---|---|
| Critical | Sensitive data, prod access, or single-point failure | Annual + contract events |
| High | Material subprocessors in customer/audit scope | Annual |
| Medium | Limited data, no prod access | Every 2 years |
| Low | No sensitive data, commodity SaaS | Onboarding questionnaire only |
Document tier rationale in vendor record. Align with compliance-specialist subprocessors list for audit scope.
Depth of review by tier
| Tier | Typical artifacts |
|---|---|
| Critical | SIG/CAIQ + SOC 2 Type II (in date) + pen test summary + interview + architecture diagram |
| High | Questionnaire + SOC/ISO + incident attestation |
| Medium | Short questionnaire + certification or public trust page |
| Low | Security page + DPA template check |
Escalate to full diligence (M&A-style) when acquiring vendor technology or assuming their infrastructure.
Assessment workflow
1. Intake — business owner, data types, integrations, contract value 2. Tier — apply criteria; security lead confirms 3. Collect — questionnaire, reports under NDA, supplemental questions 4. Analyze — gaps vs baseline; red flags (see references/red_flags_and_remediation.md) 5. Decide — approve, approve with conditions, reject, or escalate 6. Record — assessment date, approver, conditions, re-review date 7. Monitor — cert expiry, breach news, subprocessors change
Legal terms (indemnity, liability, audit rights) → commercial-counsel.
Technical validation (encryption, logging claims) → information-security-engineer or cloud-security-engineer.
Concentration and fourth parties
Track:
- Shared IdP, cloud, CDN, or payment processor across critical vendors
- Fourth parties listed in vendor SOC reports
- Geographic concentration (residency, sanctions exposure — coordinate with legal/compliance)
Report concentration in governance packs when it affects blast radius of a single supplier failure.
Renewal and offboarding
| Event | Action |
|---|---|
| Renewal | Re-tier; refresh questionnaire if >12 months or post-incident |
| Scope change | New data or prod access → re-assess at higher tier |
| Offboarding | Data return/deletion attestation, access revocation checklist, key rotation |
Feed residual vendor risk into security-risk-analyst register when material.
Alignment with compliance-specialist
- Use approved response library and evidence pointers maintained under GRC program where they exist
- Do not invent certification scope; match SOC/ISO report period and trust criteria
- For customer-facing questionnaires (your company as vendor), coordinate outbound responses with
compliance-specialistworkflow incompliance-specialist/references/vendor_and_continuous_compliance.md - This skill emphasizes inbound evaluation of others and deal-time depth; compliance-specialist owns program rhythm and audit alignment