They should prioritise operational evidence over badge collection. That means checking whether the vendor can demonstrate current access boundaries, reviewable audit trails, and effective offboarding for both human and non-human identities before accepting compliance claims as sufficient.
Why ISO 27001 and SOC 2 Type II should trigger a deeper vendor check
iso 27001 and soc 2 type ii are useful signals, but they are not the same as proof that access is well governed in practice. For IAM and IGA teams, the question is whether the vendor can show current access boundaries, timely recertification, and clean revocation paths, not whether it can present compliant documentation. That is especially important when both human and non-human access are in scope.
Operational evidence matters because certifications and attestations describe a control environment, while vendors can still drift between audit periods. A strong answer here usually comes from live access listings, recent review records, and offboarding evidence that shows who can still reach what today. The most relevant proof is the state of access, not the existence of a badge.
What evidence should be requested before accepting the compliance claim
Start with evidence that maps directly to the access lifecycle. Ask for current access inventories, review workflows, revocation timestamps, and examples of how dormant or excessive access was removed after joiner, mover, and leaver events. If the vendor supports service accounts, API credentials, or automation, the same standard should apply to those identities as well.
For deeper diligence, compare policy language to actual control operation. A vendor may have a good policy for access review, yet still allow stale entitlements, broad admin roles, or delayed deprovisioning. The practical test is whether the evidence shows access decisions being made, reviewed, and enforced on a recurring basis, not simply documented once for audit purposes. NHIMG’s IAM and IGA Basics is a useful reference point for that distinction.
When the vendor is a cloud or software provider, ask how it governs access to production systems, customer data, and support tooling. That includes whether privileged access is time-bound, whether role assignments are reviewed, and whether offboarding covers human administrators as well as non-human credentials. The most useful evidence is usually a small set of live samples that can be traced from grant to review to removal.
How IAM and IGA teams should translate the findings into vendor risk decisions
The decision should be driven by whether the vendor can demonstrate control effectiveness in the areas that create the largest blast radius. If access boundaries are vague, review cycles are slow, or offboarding is incomplete, treat the control environment as immature even if ISO 27001 and SOC 2 Type II are both in place. That is a signal to narrow access, add contractual controls, or require remediation before expansion.
Where the vendor handles credentials, tokens, certificates, or automation accounts, treat those as lifecycle-managed access objects, not just technical plumbing. A vendor that can explain how such material is issued, rotated, and removed will usually be easier to trust than one that only points to a certificate. NHIMG’s Lifecycle Processes for Managing NHIs is a strong fit for this part of the assessment.
For vendors with broad administrative reach or delegated support access, check whether SoD, review, and deprovisioning work in combination. A passing audit report does not eliminate the risk of excessive standing privilege or incomplete offboarding, especially where multiple teams share access paths. NHIMG’s Segregation of Duties (SoD) Guide helps frame that separation between documented control and actual privilege containment.
Risk and Threat Considerations
Certification can create a false sense of assurance if teams treat it as a substitute for operational verification. The main exposure is residual access, because stale accounts, broad entitlements, or uncleared non-human credentials can remain active after staff changes, incidents, or vendor transitions.
Failure mechanism: Control design may be sound on paper, but access is not fully revoked, reviewed, or scoped in practice, leaving standing privilege that survives the audit window and can be abused later.
Impact: A compromised or neglected vendor account can expose customer data, administrative functions, or connected environments, and weak offboarding can prolong that exposure well after the original business event.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while SOC 2 (AICPA) and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| SOC 2 (AICPA) | CC6.1 — Logical Access Security Software, Infrastructure, and Architectures | Access boundaries and reviewable controls are central to vendor assurance here. |
| Recommendation — Verify that vendor access controls are operating, not just documented. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question is about whether access boundaries are actually enforced by the vendor. |
| A.5.18 — Access rights | Offboarding and recertification depend on timely management of access rights. | |
| Recommendation — Require evidence that access control is implemented and reviewed in operation. Check that access rights are granted, reviewed, and revoked on a defined lifecycle. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | The vendor's account lifecycle and revocation process are the core due diligence concern. |
| IA-5 — Authenticator Management | The question includes credentials and their control as part of access evidence. | |
| Recommendation — Validate account provisioning, review, and removal across all user types. Verify that credentials and authenticators are managed, rotated, and revoked properly. | ||
Practitioner Guidance
What to prioritise: Ask first for proof of current access state, then for proof of control operation. Recent review evidence, offboarding records, and privileged access samples tell you more than a certificate alone.
What to verify: Confirm that the vendor can show revocation of human and non-human access within an expected timeframe, and that exceptions are tracked rather than explained away. If the vendor cannot produce live evidence, treat the attestation as incomplete for IAM and IGA purposes.
Practitioner takeaway: Use ISO 27001 and SOC 2 Type II as screening inputs, but make the final decision on whether access is observable, reviewable, and removable in practice.