The Conduent breach exposed sensitive information of about 25 million individuals and cost the vendor roughly $25 million in response expenses. More importantly for your program, every organization relying on Conduent inherited parts of that crisis, despite never touching the compromised systems themselves.
You can't outsource responsibility for vendor risk, but you can build a systematic oversight process to catch deteriorating controls before they become incidents.
This checklist provides a framework for Ongoing Vendor Monitoring, the operational work that happens after due diligence is complete and the contract is signed.
Purpose of This Checklist
Most vendor risk programs focus heavily on initial assessments: security questionnaires, compliance documentation reviews, and contract negotiations. These activities matter, but they create a dangerous assumption, that vendors remain static after onboarding.
They don't.
Vendors update systems, change ownership, introduce new subprocessors, experience turnover in security teams, and shift their own risk appetites. Without ongoing monitoring, you're managing vendor risk with information that becomes outdated as soon as the contract is signed.
This checklist operationalizes continuous oversight. Use it to structure quarterly reviews, trigger ad-hoc assessments when conditions change, and document your monitoring activities for auditors and regulators who increasingly expect evidence of ongoing third-party oversight.
Prerequisites
Before implementing this checklist, confirm you have:
- A vendor inventory that includes criticality ratings, data classifications, and assigned risk owners
- Baseline security and compliance documentation from initial due diligence (SOC 2 reports, ISO 27001 certificates, penetration test summaries, or equivalent evidence)
- Defined Impact Tolerance thresholds for different vendor categories (critical vs. non-critical, high-data-volume vs. limited-access)
- Clear escalation paths when monitoring reveals control gaps or incidents
If you're starting from scratch, begin with your ten most critical vendors, those who store your most Special Categories of Data, operate your most essential systems, or support processes tied to regulatory obligations.
The Checklist
Quarterly Review Activities
Security Posture
- Request updated SOC 2 Type II or ISO 27001 certification (confirm issue date and scope)
- Review any new exceptions or qualifications in audit reports
- Verify penetration testing occurred within the past 12 months
- Confirm vulnerability management program remains active (request metrics on time-to-patch for critical findings)
- Check for changes to encryption standards or key management practices
Operational Changes
- Document any changes in vendor ownership, merger activity, or significant leadership turnover
- Identify new subprocessors or fourth-party relationships introduced since last review
- Confirm business continuity and disaster recovery tests occurred (request test results summary)
- Review any significant changes to data processing locations or infrastructure
Incident History
- Ask directly: "Have you experienced any security incidents, breaches, or unauthorized access events in the past 90 days?"
- Request copies of any incident notifications sent to other customers
- Review vendor's public disclosures for breach notifications or regulatory actions
- Check for new entries in vendor's Policy Exception Registry that might indicate control gaps
- Confirm vendor maintains current compliance with regulations applicable to your data (HIPAA, GDPR, Sarbanes-Oxley Act, state privacy laws)
- Request evidence of Data Subject Request handling capabilities if processing personal data
- Verify vendor's Data Processing Register includes your organization's data accurately
- Check for regulatory enforcement actions or consent orders affecting the vendor
Trigger-Based Reviews (Conduct When Conditions Change)
Immediate Assessment Required If:
- Vendor reports a security incident or breach
- Vendor undergoes merger, acquisition, or significant ownership change
- Vendor announces end-of-life for systems you depend on
- Regulatory action targets vendor's industry or specific practices
- Vendor fails to provide requested documentation within agreed timeframes
- Your organization expands the scope of data shared with vendor
- Vendor requests access to new systems or data categories
Annual Deep-Dive Activities
- Conduct on-site or virtual assessment of vendor's security operations center
- Review vendor's risk universe to understand how they assess their own third parties
- Request evidence of security awareness training completion rates
- Evaluate vendor's Remediation of Deficiencies process (how quickly do they close audit findings?)
- Assess vendor's financial stability (request audited financials or creditworthiness indicators)
- Re-evaluate criticality rating based on current business relationship
How to Customize It
For High-Risk Vendors
If a vendor stores special categories of data, operates systems tied to financial reporting, or supports processes subject to regulatory examination, increase monitoring frequency. Consider monthly check-ins for critical vendors rather than quarterly reviews.
Add these activities:
- Request monthly metrics on security incidents, access requests, and system availability
- Require notification within 24 hours of any security event affecting your data
- Establish direct communication channels with vendor's CISO or security operations team
- Include continuous monitoring through third-party risk intelligence platforms that track vendor security ratings
For Lower-Risk Vendors
If a vendor has limited access to Special Categories of Data and supports non-critical processes, you can reduce monitoring frequency to semi-annually or annually. However, never eliminate oversight entirely, risk conditions change.
Focus on:
- Annual compliance documentation refresh
- Trigger-based reviews when vendor announces significant changes
- Automated monitoring of public breach disclosures
For Vendors in Regulated Industries
Healthcare, financial services, and government contractors face heightened regulatory scrutiny. Customize your checklist to align with sector-specific requirements:
- Healthcare vendors: Add HIPAA Business Associate Agreement compliance reviews and breach notification protocol testing
- Financial services vendors: Include Sarbanes-Oxley Act control testing for vendors supporting ICFR processes
- Government contractors: Verify FedRAMP authorization status and NIST 800-171 compliance
Validation Steps
After implementing this checklist, validate that it's actually reducing risk rather than just generating documentation:
Test Your Escalation Process
Run a tabletop exercise: "Your critical vendor reports unauthorized access to systems containing customer data. Walk through your response using this checklist."
Does the checklist help you quickly determine:
- What data was potentially exposed?
- Which customers must be notified?
- What regulatory obligations are triggered?
- Whether your contract includes breach notification requirements?
If you can't answer those questions quickly, your checklist needs more operational context.
Measure Time-to-Detection
Track how long it takes your team to identify control gaps through this monitoring process. If you're consistently learning about vendor incidents from news reports rather than vendor notifications, your checklist isn't creating the visibility you need.
Audit Your Documentation
Can you demonstrate to auditors that you:
- Reviewed vendor security posture within the past 90 days?
- Documented changes to vendor risk profile?
- Escalated concerning findings to appropriate stakeholders?
- Took action when vendors failed to meet security expectations?
If your monitoring activities aren't creating an auditable record, you're not prepared for regulatory examination.
Review Vendor Response Rates
If vendors consistently ignore your information requests or miss deadlines, your checklist won't help, you have a contract enforcement problem. Track vendor responsiveness as a risk indicator itself. Vendors who can't provide basic security documentation on schedule probably can't execute effective security controls either.
The Conduent breach happened because continuous oversight failed somewhere in the chain of organizations that relied on the vendor. Your checklist won't prevent every incident, but it will ensure you're not managing third-party risk with stale assumptions about controls that may have deteriorated months ago.





