Every outsourcing decision carries a quiet fiction: that handing a function to a vendor also hands over the liability attached to it. It does not. When an examiner sits down across the table, the vendor is not in the room. The company is. That gap between who performs the work and who answers for it is where most partner selection processes fail, and it is the gap that Jim Cavellier, who leads technology at Cass Information Systems, spends his time closing. His argument is unsentimental and worth the attention of any leader signing contracts with third parties: the criteria that determine audit outcomes are structural, they are set before anyone meets a vendor, and they keep operating long after the ink dries.

The Test That Costs Nothing

Cavellier’s screening method is disarmingly cheap to run. Ask for the full System and Organization Controls (SOC) report. Not the badge on the vendor’s website, not the sanitized executive summary, but the complete document including exceptions, management’s responses, and the bridge letter covering the period between the report date and today. The point is less the document than the reaction to the request. “How a partner responds to that request tells you more than the report does itself,” he says. “The ones who send it the same day, with context, are the ones who will be easy to work with when you’re in the middle of an exam. The ones who route it through legal and return a redacted summary three weeks later have told you what audit season is going to feel like.”

Underneath the test sits a harder standard. Cavellier wants partners willing to treat his regulatory exposure as their own, and he wants that written into the agreement: audit rights, regulator access, evidence on demand, and incident notification timelines that function under real pressure. Cass sits on both sides of this equation as a federally and state-regulated bank holding company examined by multiple independent organizations, with internal controls over financial reporting tested annually under Sarbanes-Oxley. The firm issues SOC 1 Type 2 and SOC 2 Type 2 reports annually and bridge letters monthly, rather than quarterly or on request. “Our clients don’t have to chase us for evidence,” he says. “If a partner can’t meet the bar our clients hold us to, they don’t come into our environment.” The reciprocity is the point. A buyer who cannot produce evidence on demand has no standing to demand it.

Sequencing Beats Willpower

Almost every organization calls compliance non-negotiable. Almost every organization discovers, under deadline pressure or in the presence of a business sponsor’s favorite vendor, that the requirement quietly converts into a risk acceptance. Cavellier’s diagnosis cuts at the design rather than the people. “If the evaluation process relies on someone having to hold the line under pressure, then it’s really not non-negotiable.” Two mechanisms make it real. The first is sequencing. Compliance requirements get defined before anyone looks at vendors. Run it backward—shortlist first and send the security questionnaire after—and by then there is a champion, a budget, and a timeline. “The review becomes an exercise in justifying a decision that’s already been made.” Written into the selection criteria up front, those requirements filter the candidate pool automatically, without anyone having to fight for them.

The second mechanism is a gate that genuinely blocks procurement. At Cass, no contract is signed without an in-depth security and compliance review and sign-off, a formally documented control jointly owned by the IT security function and third-party risk. Two independent owners, Cavellier notes, means there is no single person to lean on. The design detail matters more than it sounds, because pressure in most organizations finds the one individual authorized to say yes. The proof of any control is what happens when it delivers unwelcome news, and Cass has walked away from vendors that could not meet its standards. “Our clients are handing over their payment operations to us,” he says. “The discipline we apply around who we let into our environment is the same discipline they’re buying when they choose us.”

Vendors Are a Portfolio, Not an Event

The most common failure Cavellier sees among chief information officers and business leaders is treating selection as the finish line. Rigorous questionnaires, SOC reviews, reference calls, legal negotiation, and then the contract closes the file. Twelve to eighteen months later, an examiner asks when the vendor’s control environment was last validated, and the answer is: when we bought them. “This is not a people failure, but rather a control failure,” he says. Selection has a deadline. Monitoring has none, so it does not happen. Meanwhile, control environments degrade in silence. Vendors get acquired, re-platform their systems, offshore support, or return a SOC report with exceptions nobody reads. Each of those is a material change to an environment for which the buying company remains accountable.

The remedy is to stop treating vendor risk as an event. Tier the portfolio first, because a critical processor handling client invoices or funds does not present the same risk as a marketing tool, and reviewing both at the same depth means overspending on one and under-reviewing the other. Defaulting to uniform annual reviews, Cavellier warns, results in every review being done poorly at the same interval. Cass reassesses on a defined cadence tiered by vendor risk, with critical vendors reviewed more frequently and the cadence documented so it does not depend on anyone remembering. The payoff is structural rather than heroic. “Audit readiness isn’t something we prepare for. The evidence is current because the reviews are current.” That sentence describes the whole philosophy. Readiness is not a season. It is a byproduct of controls that run whether or not an examiner is expected.

Follow Jim Cavellier on LinkedIn for more insights on third-party risk, audit readiness, and partner compliance strategy.

Written in partnership with Tom White