712-50 · Question #185
How often should the SSAE16 report of your vendors be reviewed?
The correct answer is C. Annually. Reviewing a vendor's SSAE 16 (Statement on Standards for Attestation Engagements No. 16) report annually aligns with standard third-party risk management best practices and most regulatory frameworks (SOC 2, PCI-DSS, ISO 27001). SSAE 16 reports are themselves issued on an…
Question
How often should the SSAE16 report of your vendors be reviewed?
Options
- AQuarterly
- BSemi-annually
- CAnnually
- DBi-annually
How the community answered
(32 responses)- A16% (5)
- B3% (1)
- C75% (24)
- D6% (2)
Explanation
Reviewing a vendor's SSAE 16 (Statement on Standards for Attestation Engagements No. 16) report annually aligns with standard third-party risk management best practices and most regulatory frameworks (SOC 2, PCI-DSS, ISO 27001). SSAE 16 reports are themselves issued on an annual basis (typically covering a 12-month period), so reviewing them more or less frequently than that cycle doesn't map to the report's own cadence.
- A (Quarterly) is too frequent - vendors don't produce new SSAE 16 reports every quarter, so there's nothing new to review.
- B (Semi-annually) is too frequent for the same reason; the report lifecycle is annual.
- D (Bi-annually / every two years) is too infrequent - a two-year gap creates significant risk blind spots, especially given how quickly vendor environments change.
Memory tip: Tie the review cadence to the report cadence - SSAE 16 reports cover one year, so you review them once a year. Think "annual report = annual review."
Topics
Community Discussion
No community discussion yet for this question.