Third-party and vendor risk management
- Program design
- Intake & risk tiering
- Vendor assessments
- SOC 1 / SOC 2 / ISO 27001 evidence review
- Remediation tracking
- Risk registers
The problem
Vendor review either blocks the business for months or waves things through on a questionnaire nobody reads.
The work
I design or rebuild the program end to end — intake that routes, tiering tied to data and access, assessment depth matched to tier — and run the assessments, reading SOC 1, SOC 2, and ISO 27001 reports for scope, exceptions, subservice organizations, and complementary user controls.
The outcome
A tiered portfolio, a register your auditor can follow, remediation with owners and dates, and decisions in days rather than quarters.

