- Before
- Spends most of a Tier-1 review reading the questionnaire and the SOC 2 before she can judge anything.
- Now
- Opens an assessment already mapped to the control framework, with the contradictions side by side and every finding cited to its page.
One Tier-1 renewal, from evidence pack to a signed decision
Velunda Trial Cloud runs clinical data capture and patient diaries for 14 active studies. Its renewal is due on November 15 and the decision on October 9. Here is that assessment, screen by screen, in the working solution.
- 01Morning
The whole vendor portfolio on one radar
Priya Raman · Third-party risk analystPriya sees 486 vendors in cyber scope, each placed by tier and by what it does for the business: 8 assessments open, 5 items that need her, 7 Tier-1 vendors at High residual, and a median of 9 days to decision. At the top of her list is Velunda: a contradiction on MFA, 6 findings, residual High, decision due in 2 days.
Fourth-party watch: “Nimbrel Cloud hosts 9 of our vendors.”
- 02Opened
The evidence pack, already read and mapped
Priya Raman · Third-party risk analystAssessment V-2417 has 9 of 10 documents in: the SIG Core 2026 questionnaire, the SOC 2 Type II report, the pen-test summary, the incident response plan, the regulatory compliance statement (21 CFR Part 11 and EU Annex 11), the BAA and DPA, the ISO 27001 certificate and the tiering form. The bridge letter is marked not received. Nimbrel Cloud’s SOC 2 is on file from an earlier assessment, so it was reused rather than requested again. Thirteen control domains show Met, Below our standard, Auditor exception or Missing evidence at a glance.
“6 findings to act on · 2 high · 1 contradiction · 640 answers and tests mapped to our framework.”
- 03Under two minutes
How the agents assessed it
The agentsOne link shows the run. The evidence classifier filed 9 documents and flagged 1 missing. The questionnaire reader read 611 of 627 answers. The SOC report reader went through 112 SOC 2 pages for exceptions, carve-outs and the controls left on Northwind’s side. The control mapper mapped 640 answers and tests and found 1 contradiction, and the risk rater put residual at High, 64.
The SOC report reader’s note: “read 112 pages · 2 exceptions · 7 controls on our side · 1 carved-out host.”
- 04The finding that matters
The questionnaire says MFA everywhere. The auditor disagrees.
Control mapper & gap finderOn the left, SIG H.4.2: “MFA is enforced for 100% of privileged accounts.” On the right, the SOC 2 test of CC6.1 on page 48: for 3 of 25 sampled privileged accounts, MFA was not enforced during the period. Management says it was fixed in February 2026 but gave the auditor no evidence. So the request asks for an identity-provider MFA policy export, dated after February 2026, covering every privileged account.
A contradiction needs both passages, and the SOC report reader never treats a management response as evidence.
- 05Next
What the auditor assumed Northwind would do
Priya Raman · Third-party risk analystThe SOC 2 lists 7 complementary user entity controls on page 24. Each one is matched to Northwind’s framework and has a named owner. Five are in place. Two need action. Access reviews for this system happen once a year, not every quarter (Dana Okafor, Identity & access), and the monthly audit-trail review runs in only 9 of 14 studies (Dr. Maya Chen). Priya assigns the first to Dana in one click.
- 06Rated
Critical inherent, High residual, and what would bring it down
Risk raterInherent risk is 88, Critical, from the tiering form: patient data including protected health information (+30), GxP trial data supporting submissions (+22), ~38,000 participants in 14 studies (+18) and 9–12 months to replace (+18). The vendor’s controls bring the base to 38, and six open findings add 26, for a residual of 64, High. If the conditions are met, it drops to 38, Moderate. Ticking the MFA evidence and the pen-test retest letter shows 47 straight away.
Every point has a reason: MFA evidence +9, retest letter for H-01 and H-02 +8, bridge letter +3, 24-hour notice +2, validation summary +2, HIPAA risk analysis +2.
- 07Drafted
One request per finding, and the clauses for the renewal
Request & clause writerThe remediation request to Marta Lindqvist, Velunda’s CISO, lists six items, each with the evidence that would close it and a due date set by severity. It covers the MFA export and a dated fix plan, both within 14 days, with the retest letter for H-01 and H-02 by December 15. Then a bridge letter for April 1 – September 30, 2026, a 24-hour initial notice, the validation summary and the HIPAA risk-analysis summary, all within 30 days. The contract clauses use approved wording and go to Sam Patel in procurement for the renewal paper.
Nothing goes to a vendor without the analyst.
- 08Decision
Approve with conditions, recommended and explained
Priya Raman · Third-party risk analystThe decision offers four choices: approve, approve with conditions, remediate before go-live or renewal, or do not approve. Approve with conditions is recommended, with six conditions tracked to closure. The full reassessment is set for October 2027 (Tier 1, every 12 months), and a triggered check for December 15, 2026, when the retest letter is due. Priya adds her note for the record.
“Residual High — Omar Haddad co-signs after you sign.”
- 09Signed · Oct 7
Signed, co-signed, sent and booked
Omar Haddad · Head of IT Risk & CompliancePriya signs: approved with conditions, 6 conditions. Because residual is High, Omar Haddad co-signs. The requests go to Marta Lindqvist and the clauses to Sam Patel, and the reassessment is booked for October 2027 with the triggered check on December 15. Every step lands on the assessment’s activity record, people and agents alike.
- 10Also today
A notice at the host, checked across nine vendors
The monitoring workflowOn October 5, Nimbrel Cloud reported credential-stuffing on its support portal. Nine of Northwind’s vendors run on Nimbrel, Velunda among them. The check asks each vendor’s file three questions: does it use Nimbrel’s support portal, with shared credentials, and is Northwind data in a Nimbrel environment? It found no impact for any of the nine, recorded the result on each file and asked Nimbrel for written confirmation.