While evaluating a SaaS case-management vendor for public health, the procurement team reviews SOC reports and summaries of the vendor's recent internal audits. What is the team primarily doing?
Select an answer to reveal the explanation.
Short Explanation
SOC reports and internal-audit evidence are the vendor's report cards from outside (and inside) graders. Reading them during selection is how you grade the grader before you hand over case data.
Full Explanation
Third-party risk assessment includes reviewing independent assessments and evidence of audits to judge control effectiveness. SOC-type reports and internal audit results are common assurance inputs during vendor selection. Ignoring evidence or substituting marketing materials weakens selection rigor.