A regional bank is preparing to onboard a new SaaS provider that will host a customer-facing loan origination workflow. The procurement team has signed a master services agreement, and the vendor has produced a current SOC 2 Type II report with no exceptions. The CISO is asked to approve the integration before go-live next quarter. What should the CISO do FIRST?
- AApprove the onboarding on the strength of the clean SOC 2 Type II report and require annual re-attestation thereafter.
- BCommission an independent penetration test of the vendor's production environment before any data is exchanged.
- CRequire the vendor to add the bank as a named additional insured on its cyber liability policy and proceed.
- DDefine the bank's minimum security requirements for the workflow and map the SOC 2 controls and contractual obligations against them to identify gaps. Correct
Why A is wrong: A clean SOC 2 report is useful evidence but it reflects the vendor's chosen control set against AICPA criteria, not the bank's minimum security requirements for a loan origination system. Approval without mapping the report to the bank's own control baseline transfers unmeasured risk.
Why B is wrong: A penetration test is a useful technical assurance activity, but it tests a point-in-time configuration and is meaningless without first establishing what the bank requires the provider to protect and to what standard. It also typically requires the vendor's consent and scope agreement, which presupposes the baseline conversation.
Why C is wrong: Insurance is a financial risk transfer mechanism that addresses residual loss, not control adequacy. Naming the bank on the policy does nothing to confirm that the vendor meets the minimum security requirements for processing loan applicant data.
Why D is correct: SCRM expects the acquiring organisation to set its own minimum security requirements driven by the data classification and business process, then evaluate the provider's evidence and contract terms against that baseline. Gaps drive remediation, compensating controls, or risk acceptance before go-live.