A critical vendor is being onboarded. The vendor risk appetite policy requires SOC 2 Type II reports for critical vendors. The vendor has provided a SOC 2 Type I report. What should the risk manager do?
Correct: the policy requires Type II for critical vendors.
Why this answer
SOC 2 Type II covers controls over a period, providing more assurance than Type I. The requirement is Type II, so the vendor should be asked to provide it.