Complies
VR-08 VENDORS

Vendor risk management software that keeps your third parties audit-ready

Every vendor in one register, tiered by the data they touch, with security reviews, SOC 2 reports, and renewal dates tracked and owned, so a third-party question in your audit has an answer ready.

See pricing

Vendor risk management software gives you one register of every third party your company relies on, scores each vendor by the risk it introduces, and tracks the evidence that proves you are managing them, so your SOC 2 or ISO 27001 auditor sees a real program instead of a spreadsheet nobody has opened since onboarding. Your auditor holds you accountable for your vendors: SOC 2 criterion CC9.2 and ISO 27001 controls A.5.19 to A.5.22 both require it, and a critical vendor with no security review is a finding. Complies builds the register from the integrations you already connect, then helps you tier each vendor by the data it can reach, a payroll processor and an analytics widget are not the same risk, and sets a review cadence per tier. For each vendor you collect what actually matters: a current SOC 2 report or ISO certificate, a completed security questionnaire, a certificate of insurance, and a signed data processing agreement, each with an owner and a renewal date so nothing lapses silently. When a vendor review comes due, the owner gets reminded before it expires, not after the auditor asks. Vendor risk management is included from the Growth plan at $199 per month billed yearly, prices published on the site, with monthly billing available and no sales call. One honest limitation: Complies organizes, schedules, and documents the program, but a human still has to read the SOC 2 report and decide whether a vendor is acceptable. What changes is that the decision, and the proof you made it, live in one place your auditor can see.

It works alongside risk register software and compliance evidence collection, and plugs straight into soc 2 compliance software, iso 27001 compliance software on every plan from Growth up.

VR-08 VENDORS

What changes when it is in place

One register, every vendor tiered

Each vendor sits in one list scored by the data it touches and the access it holds, so a critical processor gets an annual review and a low-risk tool does not eat the same effort. Tiering is the difference between a program and a pile.

SOC 2 reports and reviews tracked

For each vendor you store the current SOC 2 report or ISO certificate, the security questionnaire, the certificate of insurance, and the DPA, each with an owner and an expiry date, so a lapsed review surfaces before the auditor finds it.

Built for CC9.2 and A.5.19

The register maps straight to SOC 2 CC9.2 and ISO 27001 A.5.19 to A.5.22, so the vendor evidence an auditor asks for is already collected, owned, and dated instead of assembled in a panic the week before fieldwork.

Renewals that chase themselves

Annual reassessments and expiring documents reschedule on the compliance calendar and remind their owner ahead of the deadline. The second review cycle costs a fraction of the first because last year the work is already there.

QUESTIONS

Common questions

It is software that keeps one register of your third-party vendors, scores each by the risk it introduces, and tracks the evidence that you are managing them: security reviews, SOC 2 reports, insurance certificates, and data processing agreements with owners and renewal dates. Complies builds the register from your connected stack and maps it to SOC 2 CC9.2 and ISO 27001 supplier controls, so the program doubles as audit evidence instead of being a separate chore.

Because your vendors can reach your data, so their weaknesses become yours. SOC 2 criterion CC9.2 requires you to assess and manage the risks from vendors and business partners, and ISO 27001 controls A.5.19 to A.5.22 cover supplier relationships and the security of what you buy. An auditor will ask for your vendor inventory and the reviews behind your critical vendors, and a critical vendor with no review on file is a common finding.

Start with the data the vendor can access, which sets how hard you look. For higher-risk vendors, request a current SOC 2 Type 2 report or ISO 27001 certificate and read the exceptions, send a security questionnaire, confirm a data processing agreement is signed, and track a certificate of insurance. Complies stores each artifact against the vendor with an owner and an expiry date, and reminds you when a review is due again.

Put vendor risk management on autopilot

All plans include it. Prices are public. Start today.