Sample vendor security questionnaire covering the SOC 2 Trust Services Criteria areas most relevant when evaluating offshore accounting providers. Use during vendor selection, renewal review, or enterprise security team onboarding.
SOC 2 (System and Organization Controls 2) reports are issued by independent auditors attesting that a service provider's controls meet the AICPA Trust Services Criteria across five areas: Security, Availability, Processing Integrity, Confidentiality, and Privacy. For offshore accounting providers handling US firm and client data, SOC 2 Type II reports (covering a 6–12 month audit period) are the standard assurance most enterprise buyers ask for.
Reality: many offshore accounting providers don't have SOC 2 reports. SOC 2 is expensive to maintain ($75k–$250k annually all-in for a mid-size provider) and not every buyer requires one. Pure-play staffing providers often operate with documented internal controls that map to SOC 2 criteria without carrying the formal certification. For buyers in that situation, a vendor security questionnaire substitutes for the SOC 2 report – gathering the same underlying control information directly from the vendor.
The questionnaire below covers the five SOC 2 Trust Services Criteria categories. Adapt to your organization's specific risk tolerance and regulatory obligations. Review with your security team before use.
The questionnaire responses should give you a reasonable picture of the vendor's security posture. Specific areas to dig into further if answers feel thin:
For our published security infrastructure detail, see the security page. For related compliance templates see the compliance forms hub.
Related