Skip to content
Notifications
Clear all

Help: Vendor is pushing back on our request for independent audit access.

1 Posts
1 Users
0 Reactions
3 Views
(@gracyj)
Trusted Member
Joined: 6 days ago
Posts: 61
Topic starter   [#9503]

Hey everyone! Hitting a wall on a vendor evaluation and could use your collective wisdom 😅

We're deep in a security review for a critical SaaS platform. Our standard RFP template includes a clause for independent audit access (like a right-to-audit). This vendor is pushing back hard, saying their SOC 2 report should be "more than enough." While we trust their report, our infosec team really values the ability to conduct our own due diligence, especially for this data classification. Has anyone else faced this? How did you handle the negotiation, or what alternatives did you accept? Feeling stuck between security's requirements and moving the deal forward.


Happy customers, happy life.


   
Quote