Sample assessment

Explore the full output without uploading documents

This is a fictitious assessment of Acme Cloud Services. Every section, citation and follow-up question is what you would receive for a real vendor. Click any source citation to open the underlying document at the cited page. The requirements shown here are drawn from the Recommended Enterprise Baseline — one of three equal starting points alongside uploading your own or building from scratch.

Vendor Due Diligence Report

Acme Cloud Services

Acme Identity Platform (SaaS)

Report date
20 June 2026
Prepared for
Jane Doe · jane.doe@example.com
Reference ID
00000000

Confidential — for the recipient organisation's internal decision use only

Recommendation

Supports Approval with Conditions

This recommendation is evidence-based decision support. The final procurement decision remains with the recipient organisation.

Executive summary

Evidence partially supports the reviewed requirements. EU data-residency confirmation and a reconciled breach-notification SLA are required before the assessment can be closed; all other reviewed requirements are supported by independent evidence.

Acme Cloud Services provides strong evidence for the majority of reviewed security and privacy requirements. Independently verified SOC 2 Type II and ISO 27001 certifications support core control areas. Two requirements lack supporting evidence and one conflict between documents requires vendor clarification before final approval.

Supported
5
Needs attention
8
Missing
1

Supported — requirements the vendor's evidence clearly satisfies. Needs attention — partial coverage, unresolved conflicts or open follow-up questions. Missing — requirements with no supporting evidence provided.

Decision snapshot
Assessment status
Evidence partially supports the reviewed requirements.
Decision readiness
Additional Evidence Required

Ready = evidence is sufficient to decide. Partial = some material gaps remain. Not Ready = key evidence is missing or conflicting.

Risks requiring attention
  • Breach notification SLA
  • Data residency / processing region commitments for EU customers
  • Penetration test executive summary from the last 12 months
Strengths
  • Encryption controls
  • Access control governance
  • Business continuity testing
Recommended next actions
  1. 01
    Request written confirmation of EU data residency from vendor before contract sign-off.
    High priority
  2. 02
    Ask vendor to reconcile breach-notification SLA between DPA and Security Policy.
    Medium priority
  3. 03
    Obtain the latest penetration test executive summary and remediation status.
    Medium priority
  4. 04
    Schedule annual reassessment aligned with SOC 2 report refresh cycle.
    Low priority

Requirements assessment

Each reviewed requirement, mapped to the evidence the vendor provided.

Requirements mapping

8 requirements
  • REQ-02Evidence foundCritical priority
    All customer data must be encrypted at rest and in transit.

    AES-256 at rest, TLS 1.2+ in transit, documented in Security Whitepaper §3.2.

  • REQ-04No evidenceCritical priority
    Customer data processed within EU/EEA boundaries.

    No documentation found specifying processing regions or data residency commitments.

  • REQ-01Evidence foundHigh priority
    Vendor must hold a current independent security certification (SOC 2 / ISO 27001).

    SOC 2 Type II (BDO, 2025) and ISO 27001:2022 certificate provided.

  • REQ-03Evidence foundHigh priority
    Multi-factor authentication enforced for all administrative access.

    Confirmed in SOC 2 control CC6.1 and Access Control Policy §4.

  • REQ-05Partial evidenceHigh priority
    Security incidents notified to customers within agreed SLA.

    DPA states 24 hours; Security Policy states 72 hours. Conflict pending clarification.

  • REQ-06Manual reviewMedium priority
    Annual penetration testing performed by an independent third party.

    Reference to annual pentests in Security Whitepaper, but no recent report provided.

  • REQ-07Evidence foundMedium priority
    Documented Business Continuity and Disaster Recovery plan with annual testing.

    BCP / DRP document provided with 2024 test results.

  • REQ-08Evidence foundMedium priority
    Sub-processor list maintained and customers notified of changes.

    Sub-processor list provided; change notification process in DPA §6.

Detailed findings
1 high · 1 medium · 1 low
  • SOC 2 Type II report covers all in-scope trust criteria

    Independent auditor opinion (BDO, 2025) confirms operating effectiveness of controls for Security, Availability and Confidentiality over a 12-month review period with no exceptions.

    Low severity
  • Data residency commitments not documented

    Provided contracts and policies do not specify guaranteed processing regions for EU customer data. Required for GDPR data transfer assessment.

    High severity
  • Incident notification SLA inconsistency

    The DPA commits to 24-hour breach notification while the Security Policy references 72 hours. Vendor clarification required.

    Medium severity
Conflicting information
1
  • Breach notification SLA

    The Data Processing Addendum commits to 24-hour breach notification, while the Security Policy references 72 hours. The shorter commitment in the DPA should be confirmed as authoritative.

Evidence

The documents supplied, the requirements they support, and the gaps that remain.

Decision readiness Additional Evidence Required

Supporting evidence
3
TopicEvidence strengthSupporting documents
Encryption controls

Encryption at rest (AES-256) and in transit (TLS 1.2+) is confirmed independently in the SOC 2 Type II report and the Security Whitepaper.

Strong
Access control governance

Role-based access control with MFA for administrators is consistent across the Access Control Policy and SOC 2 control CC6.1.

Strong
Business continuity testing

Annual BCP/DRP testing is documented both in the BCP document and the SOC 2 report (control A1.2).

Strong
Requirements without supporting evidence
2
  • Data residency / processing region commitments for EU customers
  • Penetration test executive summary from the last 12 months
Recommended additional evidence
3
  • Data Processing Addendum with explicit processing regions
  • Most recent penetration test executive summary
  • Business continuity plan test results from the last 12 months
Follow-up questions for the vendor
5
  1. 01
    Can you confirm in writing that EU customer data is processed exclusively within the EU/EEA, and provide the relevant DPA addendum?

    Required for our GDPR transfer assessment.

    High priority
  2. 02
    Which SLA is authoritative for breach notification — 24 hours (DPA) or 72 hours (Security Policy)?
    High priority
  3. 03
    Please share the executive summary of your most recent independent penetration test and the remediation status of any findings.
    Medium priority
  4. 04
    Do you maintain a customer-facing trust portal where sub-processor changes are communicated proactively?
    Low priority
  5. 05
    Please confirm the retention period for customer data after contract termination.
    Medium priority

Methodology & reference

How this report was produced, and supplementary detail for review teams.

Methodology

Governly maps customer-supplied requirements to vendor evidence across Information Security, Data Protection & Privacy, Access Control & Identity, Business Continuity & Resilience, Vendor Governance, and Documentation Completeness. Each requirement is independently evaluated; the report highlights what is supported, what is missing, and what requires manual verification.

Numerical scoring (supplementary)
Composite score
78 / 100
Domain scoring
  • Information Security
    86 / 100
  • Data Protection & Privacy
    68 / 100

    Lowered by missing residency evidence.

  • Access Control & Identity
    84 / 100
  • Business Continuity & Resilience
    74 / 100
  • Vendor Governance
    80 / 100
  • Documentation Completeness
    76 / 100
Evidence strength basis
  • Independent SOC 2 Type II and ISO 27001 certifications provided
  • Two requirements without supporting evidence
  • One inter-document conflict identified

Numerical scores are supplementary. The primary assessment is the requirement-by-requirement evidence review above.

Disclaimer. This report is prepared as decision support for governance, risk and compliance reviews. It is not legal advice. Findings reflect the documents and context provided at the time of assessment and should be read alongside the recipient organisation's own risk judgement.