SOC 2 · Vendor Due Diligence

SOC 2 vendor security questionnaire for offshore accounting providers.

Sample vendor security questionnaire covering the SOC 2 Trust Services Criteria areas most relevant when evaluating offshore accounting providers. Use during vendor selection, renewal review, or enterprise security team onboarding.

Purpose

When and why to ask for a SOC 2 report (and what to ask if they don't have one)

SOC 2 (System and Organization Controls 2) reports are issued by independent auditors attesting that a service provider's controls meet the AICPA Trust Services Criteria across five areas: Security, Availability, Processing Integrity, Confidentiality, and Privacy. For offshore accounting providers handling US firm and client data, SOC 2 Type II reports (covering a 6–12 month audit period) are the standard assurance most enterprise buyers ask for.

Reality: many offshore accounting providers don't have SOC 2 reports. SOC 2 is expensive to maintain ($75k–$250k annually all-in for a mid-size provider) and not every buyer requires one. Pure-play staffing providers often operate with documented internal controls that map to SOC 2 criteria without carrying the formal certification. For buyers in that situation, a vendor security questionnaire substitutes for the SOC 2 report – gathering the same underlying control information directly from the vendor.

When SOC 2 Type II is appropriate to require: large enterprise buyers, publicly-traded companies, or firms with end clients in regulated industries (financial services, healthcare). When a questionnaire is sufficient: mid-market firms, private businesses, engagement types that don't touch PHI or heavily regulated data.
Sample questionnaire

The 40-question vendor security questionnaire

The questionnaire below covers the five SOC 2 Trust Services Criteria categories. Adapt to your organization's specific risk tolerance and regulatory obligations. Review with your security team before use.

Security (19 questions)

  1. Does your organization maintain a documented information security policy approved by senior leadership?
  2. Do you maintain a SOC 2 Type II report or equivalent independent control attestation? If yes, what is the audit period?
  3. How is access to customer data granted, reviewed, and revoked? Provide documentation of your access management process.
  4. Do you enforce multi-factor authentication (MFA) for all workforce members accessing customer data?
  5. How are workstations used by offshore staff configured? (Company-managed, endpoint protection, disk encryption, no personal device use.)
  6. Are offshore workstations restricted from connecting to personal Wi-Fi networks, external USB devices, or personal email accounts during work hours?
  7. Describe your encryption-in-transit and encryption-at-rest standards.
  8. What network perimeter security is in place for offshore delivery centers? (Firewalls, IDS/IPS, network segmentation.)
  9. Do you maintain audit logs of all customer data access? What is the retention period?
  10. Describe your vulnerability management program. Frequency of scans, remediation SLAs, patching cadence.
  11. Do you conduct annual penetration testing? Provide the most recent test date and high-level results.
  12. What is your incident response process? Define severity levels, notification SLAs, escalation path.
  13. Describe your physical security controls at offshore delivery centers. (Access controls, visitor management, CCTV, data center separation.)
  14. What background check process is used for workforce members with access to customer data?
  15. Describe annual security awareness training for all staff with customer data access.
  16. Do workforce members sign individual NDAs beyond employment agreements?
  17. How is the removal of access on termination handled? Timing, confirmation, audit evidence.
  18. What subcontractors or fourth parties have access to customer data? How are they managed?
  19. Describe your risk assessment process. Frequency, methodology, escalation to executives.

Availability (5 questions)

  1. What is your published uptime SLA? Provide actual uptime for the past 12 months.
  2. Describe your business continuity and disaster recovery plans. RTO and RPO for customer-facing services.
  3. How often is the DR plan tested? Provide the date of the last test and summary of findings.
  4. What backup and recovery processes apply to customer data?
  5. Where are backups stored? Are they tested regularly? Encrypted?

Confidentiality (6 questions)

  1. What standard contractual confidentiality provisions bind your workforce?
  2. How is customer data segregated between different customer environments?
  3. Do you have the capability to isolate customer data in a defined geographic region on request?
  4. Describe your secure data destruction process at the end of an engagement.
  5. What sub-contractor flow-down confidentiality provisions exist?
  6. Have you had any confidentiality or data breach incidents in the past 24 months? If yes, describe.

Processing Integrity (4 questions)

  1. How are changes to processes, software, or systems tested and approved before production?
  2. Describe your quality control review process for customer-facing work product.
  3. What error correction and exception handling processes apply to customer data processing?
  4. How do you prevent unauthorized modification of customer data?

Privacy (6 questions)

  1. Are you subject to GDPR, CCPA, or other privacy regulations? Describe compliance.
  2. Do you maintain a published privacy policy? URL?
  3. How do you handle data subject rights requests (access, correction, deletion)?
  4. What data minimization principles apply to customer data collection?
  5. Describe your process for customer data return or destruction at the end of an engagement.
  6. Do you process customer data outside the originating country? If yes, what legal mechanisms apply to the cross-border transfer?
Using the results

How to evaluate the answers

The questionnaire responses should give you a reasonable picture of the vendor's security posture. Specific areas to dig into further if answers feel thin:

  • Workstation security. If the vendor allows offshore staff to use personal devices, connect to personal Wi-Fi, or access personal email during work hours, there's a meaningful data exfiltration risk. Require company-managed, hardened workstations.
  • Audit logs. If the vendor can't produce access logs for customer data on request, incident investigation becomes guesswork. Require documented audit trail retention of at least 12 months.
  • Subcontractors. Many offshore providers use subcontractors for specific service areas (particularly during peak seasons). If so, the same security standards should flow down to the subcontractor contractually.
  • Background checks. Verify the depth of background check (criminal, credit, education, employment). Entry-level "basic verification" doesn't meet most enterprise standards.
  • Incident history. Vendors who claim zero incidents ever are either lying or just getting started. A mature vendor has had incidents, learned from them, and can describe their response. A non-answer here is a yellow flag.

For our published security infrastructure detail, see the security page. For related compliance templates see the compliance forms hub.

Disclaimer: Not legal or compliance advice. Security questionnaire design and evaluation should be tailored to your specific risk profile and regulatory obligations. Consult qualified security and compliance professionals.

Related

Related compliance resources

Compliance layer sorted – ready to scope the engagement.

Book my call →