Due Diligence Depth vs Vendor Tier
SOC 2: Confirmed Exists. Fourteen Controls Tested by Policy Review Only. Due Diligence: Checked the Box.
4 min read · 31 May 2026 · Third-party oversight
The principle that due diligence depth should scale with vendor risk tier sounds straightforward. The operational challenge is that many TPRM programmes interpret 'deeper due diligence' as 'longer questionnaire' or 'additional document collection' rather than 'more rigorous analysis of the evidence collected.' An enterprise whose TPRM team collects a SOC 2 report, notes its existence in the vendor record, and marks the relevant control domain as satisfied has performed the motion of due diligence without the substance. The enterprise whose TPRM team reads the SOC 2 report , specifically the description of tests performed for each control , understands not just that controls exist but how they were tested and what the test actually confirmed. SOC 2 reports that describe controls tested by reviewing policy documentation are materially weaker assurance than controls tested by observation or technical validation. The difference is not visible from the existence of the report. It is only visible from reading it.
Due diligence depth in the TPRM context means asking harder questions about the evidence collected, not just collecting more evidence. For a critical-tier vendor, deep due diligence means understanding the scope limitations of their SOC 2 , what systems were in scope and what were excluded. It means understanding which controls were tested by inquiry only versus observation and re-performance. It means asking follow-up questions when the evidence collected reveals gaps or ambiguities. It means recognising when a vendor's responses are consistent with their SOC 2 and when they are not. Depth is an analytical capability, not a collection capacity.
The questionnaire response quality problem is the second depth dimension. Vendors complete TPRM questionnaires with varying degrees of accuracy, specificity, and honesty. Generic, template-like responses that could have been written for any vendor , 'We employ industry-standard encryption' , provide minimal assurance. Specific, detailed responses that reference actual configurations, tools, and processes , 'We use AES-256 encryption at rest managed through AWS KMS with customer-managed keys, key rotation every 90 days' , provide meaningful assurance. A TPRM team that does not distinguish between these response quality levels is collecting responses without extracting intelligence.
Why this matters
Due diligence depth matters because the risk a vendor represents is not reduced by collecting evidence that confirms the vendor's controls are documented , it is reduced by understanding whether those controls are effectively implemented. A SOC 2 that confirms controls exist provides weaker risk reduction than a SOC 2 review that reveals the controls were tested by policy document review only , because the second analysis produces an accurate picture of residual risk that the first does not.
- SOC 2 existence noted without content analysis
- Test methodology in SOC 2 not reviewed , inquiry-only testing versus observation
- Questionnaire response quality not assessed , generic versus specific responses treated equally
- Scope limitations in audit reports not identified
- Follow-up questions not asked when evidence reveals gaps
What good looks like
Mature due diligence programmes read the evidence they collect , specifically reviewing SOC 2 bridge letters for currency, reviewing the description of tests performed for inquiry-only versus observation methodology, asking follow-up questions when responses are generic or inconsistent, and requesting additional evidence when the collected evidence is insufficient for the vendor's risk tier.
- SOC 2 content analysis , tests performed methodology, scope inclusions and exclusions
- Questionnaire response quality assessment , specific versus generic responses flagged
- Bridge letter currency verification , SOC 2 report date and bridge letter coverage
- Follow-up questions triggered by gaps in evidence
- Supplemental evidence requests when standard evidence is insufficient for tier
Tooling
Due Diligence , Venminder for SOC 2 analysis, TPRM platforms with response quality scoring
Specialised due diligence platforms that include SOC 2 analysis capabilities , identifying inquiry-only controls, flagging scope exceptions, and surfacing material weaknesses , provide systematic depth that questionnaire review alone cannot achieve. For critical-tier vendors, SOC 2 specialist review services can provide the technical depth that in-house TPRM teams may not have the bandwidth to apply consistently.
Governance challenges
The governance challenge with due diligence depth is the expertise bottleneck. Reading a SOC 2 with genuine analytical depth requires understanding what the tests performed descriptions mean , which requires familiarity with SOC 2 audit methodology that most TPRM analysts do not have. The governance resolution is training, tooling, or specialist support that closes the analytical gap.
- Require SOC 2 analysis training for TPRM analysts reviewing critical-tier vendors
- Implement response quality scoring , flag generic responses for follow-up
- Establish minimum evidence standards for each tier , what constitutes adequate evidence
- Use specialist review services for critical-tier SOC 2 analysis
- Document analysis rationale , not just evidence collection but evidence interpretation
If you are a small team
For your top ten vendors by inherent risk tier, read their most recent SOC 2 report , specifically the 'description of tests performed' section for each control. Identify how many controls were tested by inquiry only versus observation or re-performance. Controls tested only by reviewing policy documents provide weaker assurance than controls tested by direct observation. That analysis will tell you more about your actual residual risk from those vendors than the fact that the SOC 2 exists.
- Read the tests performed section of top-tier vendor SOC 2 reports
- Identify inquiry-only versus observation-tested controls
- Flag scope exclusions and exceptions
- Ask follow-up questions for inquiry-only critical controls
What to require
Ask directly:
"In your most recent SOC 2 report , for your encryption at rest and access control domains, were those controls tested by observation and technical validation or by reviewing policy documentation? And are there any systems or environments excluded from the SOC 2 scope that process our data?"
Expect as evidence
- SOC 2 report with tests performed descriptions
- Scope inclusions and exclusions clarification
- Bridge letter for currency if report is more than six months old
- Clarification on inquiry-only controls
A vendor who provides a SOC 2 should be asked what the report's tests confirmed. Existence confirms the report was issued. Test methodology describes what the controls actually demonstrate.
How to evidence it
- SOC 2 content analysis records
- Inquiry-only control identification
- Follow-up question records
- Supplemental evidence requests
Key Takeaway
SOC 2: exists, confirmed. Fourteen controls tested by policy review only. Encryption at rest tested by reviewing configuration documentation, not technical validation. Availability SLA tested against internal target, not actual uptime. The report existed. The assurance it provided was significantly weaker than what marking 'SOC 2 confirmed' implies. Due diligence depth means reading the evidence collected, not confirming it was received. Tests performed descriptions reveal what the controls actually demonstrate. Inquiry-only testing is weaker than observation. Policy document review is weaker than technical validation. The difference between these is not visible from the report's existence , it is only visible from reading it.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association