nerdexam
EC-Council

712-50 · Question #185

How often should the SSAE16 report of your vendors be reviewed?

The correct answer is C. Annually. Reviewing a vendor's SSAE 16 (Statement on Standards for Attestation Engagements No. 16) report annually aligns with standard third-party risk management best practices and most regulatory frameworks (SOC 2, PCI-DSS, ISO 27001). SSAE 16 reports are themselves issued on an…

Strategic Planning, Finance, Procurement, and Vendor Management

Question

How often should the SSAE16 report of your vendors be reviewed?

Options

  • AQuarterly
  • BSemi-annually
  • CAnnually
  • DBi-annually

How the community answered

(32 responses)
  • A
    16% (5)
  • B
    3% (1)
  • C
    75% (24)
  • D
    6% (2)

Explanation

Reviewing a vendor's SSAE 16 (Statement on Standards for Attestation Engagements No. 16) report annually aligns with standard third-party risk management best practices and most regulatory frameworks (SOC 2, PCI-DSS, ISO 27001). SSAE 16 reports are themselves issued on an annual basis (typically covering a 12-month period), so reviewing them more or less frequently than that cycle doesn't map to the report's own cadence.

  • A (Quarterly) is too frequent - vendors don't produce new SSAE 16 reports every quarter, so there's nothing new to review.
  • B (Semi-annually) is too frequent for the same reason; the report lifecycle is annual.
  • D (Bi-annually / every two years) is too infrequent - a two-year gap creates significant risk blind spots, especially given how quickly vendor environments change.

Memory tip: Tie the review cadence to the report cadence - SSAE 16 reports cover one year, so you review them once a year. Think "annual report = annual review."

Topics

#SSAE16 audits#Vendor auditing#Compliance frequency#Audit controls

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice