Third party vendor audit services start where the questionnaire stops. A supplier assessment tells you what a vendor says about itself. An audit tests it: sampling evidence, walking through the control, and establishing whether the practice matches the policy for the specific service you are buying.
Audits are expensive relative to questionnaires, which is exactly why they are reserved for the small number of suppliers whose failure would materially hurt you: the ones holding regulated data, holding privileged access to your network, or standing between you and your own customers. Tiering that population is part of third-party risk management; auditing the top of it is this service.
We audit against the framework your obligations demand and against the contract you actually signed, on site or remotely, and we report findings with severity, evidence and a remediation plan the vendor has agreed to. Where the vendor holds a SOC 2 report or an ISO 27001:2022 certificate, we validate its scope rather than accept it at face value.