The Vendor Management Episode
Transcript
Introduction to the Guest and Topic:
Host Allie Krings introduces Bob Welch, an auditor at Kirkpatrick Price. The conversation focuses on vendor management, also known as vendor due diligence or third-party risk management. Bob shares his background in risk and compliance, explaining that before joining Kirkpatrick Price, he worked with both regional and national accounting firms, where he gained extensive experience in risk management, security, and vendor oversight.
What Is Vendor Management?:
Vendor management, sometimes referred to as vendor due diligence or third-party risk management, is the process of evaluating and monitoring the third parties an organization works with. The goal is to ensure vendors adequately protect data, maintain appropriate security controls, and manage risk effectively.
Organizations must understand the security posture of vendors, especially those handling critical business functions or sensitive information. Vendor management helps organizations determine whether a vendor’s controls align with their own security and compliance requirements.
What Does Vendor Management Look Like Up Close?:
For Organizations:
Organizations should identify which vendors have access to critical systems, sensitive data, or important business functions. They should obtain and review documentation, such as audit reports and security assessments, to verify that vendors have implemented appropriate controls.
For High-Risk Vendors:
Critical vendors, such as cloud service providers or email hosting platforms, require regular review. Organizations should examine audit reports annually and ensure security controls such as encryption, access controls, and data protection measures meet their requirements.
For Low-Risk Vendors:
Vendors that do not handle sensitive information or critical business processes may require less frequent review, such as during contract renewals or every few years.
What Questions Should Organizations Ask Before Working with a Vendor?:
What Data Will the Vendor Handle?
The first step is understanding whether the vendor will have access to sensitive, confidential, or business-critical information. The level of risk determines how thoroughly the vendor should be reviewed.
What Security Controls Are in Place?
Organizations should verify that vendors have implemented security controls such as encryption, access controls, and monitoring capabilities. These controls should be comparable to what the organization would expect if it hosted the data itself.
Can the Vendor Provide Independent Audit Reports?
Vendors should be able to provide audit reports or other independent assessments demonstrating that their controls have been reviewed by a qualified third party.
What Are the Biggest Gaps in Compliance?:
One of the biggest gaps is assuming a vendor is secure simply because they are well-known or have been used for a long time. Security changes constantly, and vendor reviews must be performed regularly.
Another common issue is treating vendor management as a one-time activity. Organizations often perform initial due diligence but fail to reassess vendors when new vulnerabilities, incidents, or changes occur.
Why Is Ongoing Vendor Monitoring Important?:
Vendor security is not static. Organizations receive updated audit reports each year, and those reports may reveal new findings, changes in controls, or areas requiring additional review.
For vendors managing critical systems or sensitive information, annual reviews help ensure their security practices continue to meet organizational expectations and compliance requirements.
What Happens If a Vendor Experiences a Breach?:
If an organization’s data is compromised through a vendor, the incident becomes everyone’s problem. While vendors may be responsible for remediating issues within their systems, the organization still faces the consequences associated with the exposed data.
Vendor management reduces risk by ensuring organizations choose vendors with strong security controls and regularly evaluate their security posture. However, organizations remain responsible for how they configure and use vendor services.
When Does a Vendor Become a Liability?:
A vendor may become a liability when a significant vulnerability, incident, or security failure is discovered. Organizations should reassess vendors whenever major security events occur and determine whether the vendor continues to meet their risk tolerance.
Bob highlights that major industry incidents should trigger a re-evaluation of the affected vendor rather than waiting for the next scheduled review cycle.
What Are Major Vendor Red Flags?:
Lack of Audit Reports
A vendor that cannot provide independent audit reports or security documentation may not be able to demonstrate that appropriate security controls are in place.
Lack of Transparency
If a vendor is unwilling to answer questions or participate in the review process, this should be treated as a significant warning sign.
Storing Data Overseas Without Proper Controls
Organizations should understand where their data is stored and whether it is being transferred internationally. Vendors that lack transparency about data storage locations may introduce additional risk.
Audit Reports That Do Not Cover the Intended Service
Some vendors may present audit reports that only cover certain systems while excluding the specific platform or service being purchased. Organizations should confirm that the audit scope includes the actual systems they will be using.
What Are Common Challenges in Vendor Management?:
Vendor management is often managed by IT teams, even though risk extends beyond technology. Risk includes operational, financial, environmental, and organizational considerations.
Many organizations struggle because they do not dedicate sufficient resources or personnel to vendor management. Reviewing questionnaires, audit reports, and risk assessments requires time, specialized knowledge, and ongoing effort.
How Can Companies Ensure Compliance?:
Compliance begins by establishing a consistent vendor management program. Every vendor should be assessed, categorized based on risk, and reviewed according to its level of importance to the organization.
Organizations should obtain audit reports, validate that appropriate security controls exist, review vendors regularly, and reassess them whenever significant risks emerge. Most importantly, they must remember that vendor due diligence does not eliminate risk—it helps organizations understand, monitor, and manage it more effectively.
Notes
In this episode, host Allie Krings sits down with Bob Welch, an auditor at KirkpatrickPrice with a background spanning large national accounting firms, banks, and risk and compliance work, to break down vendor management — and why it matters more than most organizations realize. What’s the difference between vendor management, vendor due diligence, and third-party risk management? (Spoiler: not much.) Bob walks through how to categorize your vendors, what to look for when reviewing their audit reports, and why the CrowdStrike incident is a perfect example of why annual re-evaluations aren’t optional. He also shares a real story of a vendor that had no documentation, no audit reports, and was storing client data overseas — and why that was an immediate deal-breaker. Whether you’re just starting to think about vendor risk or looking to tighten up a program you already have, this conversation is a practical reminder that if it’s your data, it’s your problem.
At KirkpatrickPrice, we’re on a mission to help 10,000 organizations raise the bar for cybersecurity and compliance. Join Our Cybersecurity Mission. If you’re going to invest in an audit, it should deliver real value. That’s why we partner with you from audit readiness to final report, ensuring you get the assurance you deserve.
Ready to strengthen your security and compliance posture? Connect with an expert today and learn how we can help you meet your toughest goals.
Send a Question
Do you have a question for our podcast? Send it to us here.
