HOMEPLATFORMPARTNERSPRICINGRESEARCH
Who we serve
Community BanksSponsor BanksFintechs
Blog · Third-Party Risk

SOC Report Review Isn't Vendor Oversight

SOC report review at banks is one control, not a vendor oversight program. What CUECs, bridge letters, and continuous monitoring require from your team.

By Canarie Team · April 20, 2026

Most banks treat the annual SOC report review as the centerpiece of vendor oversight: collect the report, have someone read it, file a review memo, done for the year. That is one control operating once — and examiners evaluating your third-party risk program are grading an oversight lifecycle, not a filing habit. A SOC report review is a necessary input to vendor oversight. It is not the program.

Key Takeaways:

  • The interagency third-party risk guidance frames ongoing monitoring as a continuous activity across the relationship lifecycle, not an annual document collection
  • SOC reports have coverage periods that leave gaps your program must bridge, and most assign complementary user entity controls (CUECs) that your bank must operate and evidence
  • Exceptions noted in a SOC report and carved-out subservice organizations both create follow-up work that a review memo alone does not discharge
  • Continuous oversight means a monitoring calendar per vendor risk tier, evidence for every cycle, and findings tracked to closure

Why Annual SOC Report Review Falls Short of Ongoing Monitoring

The interagency guidance on third-party relationships — issued jointly by the OCC, FDIC, and Federal Reserve as OCC Bulletin 2023-17 — organizes oversight around a lifecycle: planning, due diligence, contract negotiation, ongoing monitoring, and termination. Ongoing monitoring is described as a continuous activity calibrated to the risk of the relationship, covering performance, financial condition, control environment, and compliance with contractual obligations.

An annual SOC review addresses one slice of one stage. It says nothing about the vendor's performance against SLAs this quarter, the complaint trends in the product the vendor supports, the vendor's financial deterioration since the report was issued, or whether your own team performed the follow-up the last review identified. The FDIC's parallel adoption of the guidance in FIL-44-2023 makes the same point to state nonmember banks: monitoring is expected throughout the relationship, in proportion to risk.


The Coverage-Period Problem: Gaps and Bridge Letters

A SOC 2 Type II report covers a defined examination window — commonly six or twelve months — and it arrives weeks or months after that window closes. By the time your analyst reads it, the report may describe a control environment that ended half a year ago. The interval between the end of one coverage period and the start of the next is a blind spot.

Bridge letters (gap letters) partially address this: the vendor attests that controls have not materially changed since the report period ended. Your SOC 2 report review process should require them, log their receipt, and treat a vendor's failure to produce one as a finding. But a bridge letter is the vendor grading itself. For high-risk relationships, the gap period is exactly when your own monitoring — performance data, incident reports, financial checks — has to carry the load.


Complementary User Entity Controls: The Work the SOC Report Assigns to You

Buried in nearly every SOC report is a section that turns the document from something you read into something you owe: complementary user entity controls (CUECs). These are controls the service auditor assumed your institution operates — restricting and reviewing user access to the vendor's system, reconciling the vendor's output, configuring security settings, reporting incidents promptly. If your bank does not operate the CUECs, the vendor's control opinions do not hold for you.

This is the clearest illustration of review versus execution in all of vendor management. Reading the CUEC list is review; it takes twenty minutes. Operating the CUECs means each one gets an owner, a cadence, and evidence of performance — quarterly access recertifications that actually ran, reconciliations with dated records, configuration reviews with artifacts. When an examiner asks how you know a critical vendor's controls protect you, "we reviewed the SOC report" is half an answer. The other half is proof your side of the control bargain operated, every period. That is execution work, and it continues all year.


Subservice Organizations and SOC Report Exceptions

Two more items in the report create work that outlives the review memo.

Subservice organizations. Most SOC reports use the carve-out method: the vendor's own critical vendors — cloud hosting, data processors — are excluded from the audit's scope. Those fourth parties matter to your risk picture, and the guidance expects banks to understand and account for them. At minimum, your program should identify carved-out subservice organizations for critical vendors and decide, explicitly, how each is covered.

Exceptions. When the auditor notes testing exceptions or deviations, each one is a question addressed to you: does this exception affect our use of the service, and what did the vendor do about it? Exceptions relevant to your risk need tracked remediation — a documented vendor response, a due date, and closure evidence — not a sentence in the review memo saying "noted."


What Continuous Vendor Oversight Actually Looks Like

A program that would satisfy the lifecycle framing of the interagency guidance has a recognizable shape:

  • A monitoring calendar per risk tier — critical vendors get quarterly performance and financial reviews plus annual SOC review and on-site or virtual assessments; moderate-risk vendors get lighter, defined cadences
  • Named owners for every monitoring activity, including each CUEC the institution operates
  • Evidence captured for every cycle — dated records and artifacts, not a year-end reconstruction
  • Findings tracked to closure — SOC exceptions, SLA misses, and review findings each carry an owner, a deadline, and a closure artifact
  • Portfolio visibility — one view showing which vendors are current, which are overdue, and which have open findings

This is the standard examiners test against during third-party risk exam preparation, and it is what the TPRM metrics examiners care about are designed to measure.


How Modern Teams Run Vendor Oversight as a Program

Teams that have moved past the annual-review model run vendor oversight the way they run any other set of obligations. In Canarie, each vendor's requirements — SOC review, bridge letter collection, CUEC operation, performance reviews, exception remediation — exist as recurring work with owners and cadences set by risk tier. Evidence attaches when each cycle completes, and a portfolio view shows exactly which vendors are missing what. When the examiner asks for a year of monitoring on your core processor, the year of records already exists.

The SOC report gets read either way. The difference is whether everything it triggers actually happens, and whether you can prove it.

Answer the next vendor oversight request with records, not a scramble →


Frequently Asked Questions

Is an annual SOC report review enough to satisfy examiners?

No. Under the interagency third-party risk guidance, examiners evaluate ongoing monitoring proportionate to the risk of each relationship, which for critical vendors means recurring performance, financial, and control monitoring throughout the year. The SOC review is one expected control within that program. An oversight file containing only an annual SOC memo signals a point-in-time program, and examiners will probe exactly the gaps this article describes.

What are complementary user entity controls in a SOC report?

CUECs are controls the service auditor assumes the customer — your institution — operates in order for the vendor's own controls to achieve their objectives. Typical examples include managing user access to the vendor's system, reconciling vendor output, maintaining secure configurations, and reporting incidents. Because the audit opinion depends on them, your institution must actually operate each applicable CUEC on a cadence and retain evidence, not merely acknowledge the list.

What is a bridge letter and when should a bank request one?

A bridge letter is a vendor-issued attestation covering the gap between the end of a SOC report's coverage period and the present, stating whether the control environment has materially changed. Banks should request one whenever a decision or review relies on a SOC report whose period has lapsed — commonly at annual review time and during due diligence. It is a useful gap-filler but a self-attestation, so high-risk relationships still need independent monitoring during the gap.

How should banks handle exceptions noted in a vendor's SOC report?

Assess each exception for relevance to the services your institution consumes, obtain the vendor's remediation plan for the ones that matter, and track that remediation to closure with an owner, a due date, and evidence. Document the assessment even for exceptions judged irrelevant, because examiners ask how conclusions were reached. An exception acknowledged in a review memo but never followed up is a finding waiting to be written.

Topics:Third-Party RiskVendor ManagementExam Readiness

Ready to automate your compliance workflows?

See how Canarie transforms regulatory requirements into executed tasks with built-in evidence capture.

Explore the platform