Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

Vendor audits: verifying what the questionnaire claimed.

Third party vendor audit services start where the questionnaire stops. A supplier assessment tells you what a vendor says about itself. An audit tests it: sampling evidence, walking through the control, and establishing whether the practice matches the policy for the specific service you are buying.

Audits are expensive relative to questionnaires, which is exactly why they are reserved for the small number of suppliers whose failure would materially hurt you: the ones holding regulated data, holding privileged access to your network, or standing between you and your own customers. Tiering that population is part of third-party risk management; auditing the top of it is this service.

We audit against the framework your obligations demand and against the contract you actually signed, on site or remotely, and we report findings with severity, evidence and a remediation plan the vendor has agreed to. Where the vendor holds a SOC 2 report or an ISO 27001:2022 certificate, we validate its scope rather than accept it at face value.

Why you need it

01 / 06

Why audit rather than assess.

01

Self-assessment is a description, not evidence.

Questionnaires are completed by people with an interest in a good answer, frequently by a sales team rather than a security team. They are a reasonable filter and they are not verification. The difference matters for the handful of vendors that could actually hurt you.

02

Certificates have scopes, and scopes have edges.

An ISO 27001:2022 certificate may cover a head office and not the delivery centre that runs your service. A SOC 2 report may exclude the product you bought, or cover a period that ended fourteen months ago. Reading the scope properly is often the whole finding.

03

Contracts contain obligations nobody tracks.

Breach notification windows, sub-processor approval, data location, encryption standards, service levels and audit rights are negotiated carefully and then filed. An audit is where anyone checks whether the vendor has been meeting them.

04

Regulators expect oversight, not paperwork.

Financial and healthcare regulators increasingly ask what you did to verify a critical supplier, not what the supplier told you. A documented audit with findings tracked to closure is the answer to that question.

Instrument

02 / 06

Which suppliers earn an audit.

Ten typical vendors placed by what they can reach and how badly you depend on them. Audits belong to the top-right square, not to everyone.

What we deliver

03 / 06

What the audit covers.

01

Targeted control audit

A focused examination of specific control areas where your risk actually sits (access management, data handling, encryption, subcontracting) rather than a full-scope review. The proportionate choice for most critical vendors.

02

Comprehensive security audit

A full review of the vendor's security environment against ISO 27001:2022, SOC 2 criteria or your own control standard, covering governance, technical controls, operations and personnel security for the service you buy.

03

Certification and report validation

Reading what the vendor supplied properly: the scope statement and Statement of Applicability behind an ISO 27001:2022 certificate, and the system description, period, exceptions and complementary user entity controls in a SOC 2 report. The last of these lists obligations the report quietly transfers back to you.

04

Contractual compliance review

Testing the vendor against the agreement you signed: service levels, breach notification, data location and residency, sub-processor disclosure and approval, encryption commitments, retention and deletion, and audit rights.

05

Technical verification

Where the contract permits and the risk warrants, verifying rather than accepting: external security posture, evidence of penetration testing and its findings, patch and vulnerability management records, and access control configuration in the environment holding your data.

06

Findings and remediation tracking

Findings rated by severity with evidence attached, a remediation plan agreed with the vendor and dated, follow-up verification, and a report written for both your risk committee and your regulator.

How we run it

04 / 06

Six steps, from notice to closure.

  1. 01

    Scope and audit rights

    Confirming your contractual right to audit, agreeing scope and framework with the vendor, and setting the schedule. Where the contract is silent, we help negotiate access, which is considerably easier at renewal than mid-term.

    Weeks 1-2
  2. 02

    Document request and review

    Policies, certificates and their scopes, prior audit and penetration test reports, network and data-flow documentation, sub-processor list and incident history, reviewed before fieldwork so that time on site is spent testing rather than reading.

    Weeks 2-3
  3. 03

    Fieldwork

    On site or remote: interviews with the people who operate the controls, walkthroughs of the process, and evidence sampled across a period rather than at a point. Where the vendor delivers from multiple locations, the one serving you is the one we visit.

    Weeks 3-4
  4. 04

    Control testing

    Design effectiveness first, then operating effectiveness through sampling: access provisioning and review records, change approvals, backup and restoration evidence, incident records, and training completion.

    Weeks 3-4
  5. 05

    Findings and reporting

    Findings rated by severity with the evidence behind each, a management response from the vendor, and a report written to be read by your risk committee, your customer or your regulator.

    Week 5
  6. 06

    Remediation and follow-up

    An agreed remediation plan with owners and dates, verification that fixes were made, and where a vendor will not remediate, a documented compensating control or accepted risk with a named owner on your side.

    Weeks 6-12

Key benefits

05 / 06

What changes after.

You know what the certificate covers

Scope statements, report periods and exceptions read properly, so assurance documents are evidence rather than decoration.

Contract terms get enforced

Notification windows, data location and sub-processor obligations tested against practice, while there is still leverage to correct them.

Oversight is demonstrable

A documented audit with findings tracked to closure is what a regulator or an enterprise customer means when they ask how you oversee critical suppliers.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Audit frameworks

  • ISO 27001:2022 Annex A
  • SOC 2 Trust Services Criteria
  • CSA CAIQ
  • SIG Core

Evidence review

  • SOC 2 report and exception analysis
  • ISO certificate and scope verification
  • Penetration test report review

Technical verification

  • Shodan
  • Censys
  • Certificate Transparency logs
  • External posture review

Contract testing

  • Service level evidence
  • Sub-processor register
  • Breach notification records

Reporting

  • Findings register with severity ratings
  • Remediation tracker
  • Risk committee report pack

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about vendor audits.

Do we have the right to audit our vendors?
Only if the contract says so, which is why audit rights belong in the agreement at signature. Where a contract is silent, some vendors will still cooperate, particularly at renewal, or where the relationship matters to them. Where they will not, the fallback is evidence-based review of their existing reports and certifications plus external technical verification, documented as the limited assurance it is.
How many vendors should we audit?
Very few, deliberately. In a typical population only a handful hold regulated data at volume, carry privileged network access or would stop your operation if they failed. Those merit an audit, usually annually or every two years. Everyone else is served by tiered assessment and continuous external monitoring under third-party risk management. Auditing broadly is how the programme runs out of budget before it reaches the vendors that mattered.
The vendor gave us a SOC 2 report. Do we still need an audit?
Often not, and reading it properly is what tells you. Check that the scope covers the service you buy, that the period is recent and continuous, and that the exceptions do not sit in the control areas you depend on. Then read the complementary user entity controls, which list the things the report assumes you are doing. If all of that holds, a validation review is proportionate. If the scope excludes your service, the report is not about you.
On site or remote?
Remote works well for cloud and software vendors, where the evidence is documentary and the controls are in systems we can be shown. On site matters where physical security is part of the control set, where the vendor operates a facility handling your data or your customers, or where prior findings suggest a gap between documentation and practice. For a vendor delivering from multiple locations, the site serving you is the one worth visiting.
What if the audit finds something serious?
It is reported with evidence and a severity rating, and the vendor is given a management response and a remediation plan with dates. Most findings are remediated, because vendors would rather fix an issue than lose an account. Where one will not, your options are compensating controls on your side, contractual escalation, or exit, and the audit gives you the documented basis for whichever you choose, including for the decision to accept the risk.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.