In this guide
- Ask for a bounded package
- Distinguish the report from the conclusion
- Translate customer responsibilities into work
- Use incidents as a process question
- Make uncertainty visible to the decision-maker
- Revisit evidence when the relationship changes
- Map one real data flow on paper
- Method and boundaries
- Source record
A security claim becomes useful when you can identify what was examined, over which period, for which systems and with what limitations. “Audited” on a website is a reason to ask for the appropriate evidence, not the end of diligence.
The DOL’s service-provider cybersecurity guidance recommends asking about standards, practices, independent audit results, incident history, insurance and contract protections. It applies in the benefit-plan context described by DOL. Our worksheet turns those questions into an employer-side evidence review; it does not attest to Resourcing Edge or any other provider.
Ask for a bounded package
Identify the proposed services, legal entities, systems and data flows first. A report about a corporate network may not cover the platform that will hold payroll data. An affiliate’s report may not cover the contracting entity. Ask the provider to explain the boundary in writing, then have a qualified reviewer assess whether the evidence matches the relationship.
Use a secure route for restricted reports. Do not ask a sales representative to send confidential audit materials to an unapproved personal account. A nonpublic report may have access or distribution conditions that your organization must review before accepting or circulating it.
| Question | Evidence requested | Employer action |
|---|---|---|
| What was assessed? | Report title/type, system description and period | Match it to contracted services and actual data flows |
| What was excluded? | Boundary, subservice treatment and limitations | Identify gaps needing separate evidence |
| What did testing find? | Relevant findings and management responses | Assess materiality with qualified security reviewers |
| What must we do? | Customer/user-entity control responsibilities | Assign internal implementation and verification owners |
| What happens during an incident? | Notification and cooperation terms | Connect provider commitments to the internal response plan |
Distinguish the report from the conclusion
Different report types answer different questions. AICPA’s SOC overview distinguishes SOC 1 financial-reporting control work from the trust-services subjects addressed by SOC 2. Do not treat the phrase SOC 1 as a universal cybersecurity certification or proof that every product is secure. Ask the reviewer to explain the actual report’s objective, covered controls, period and exceptions in terms relevant to your decision.
If the report period ended months before your planned start, ask what evidence addresses the intervening period and any material changes. A supplemental statement may be useful context; it is not automatically equivalent to independent testing. Record the limitation rather than silently extending the report’s date.
Translate customer responsibilities into work
Some provider controls depend on customer behavior, such as maintaining authorized users, reviewing outputs or using secure channels. Make a task list for those responsibilities. Assign an owner, evidence and review trigger. A strong provider control can still be undermined by an unmanaged administrator account on the employer side.
CISA recommends using the strongest available multifactor authentication and prioritizing privileged access. Ask what is actually supported for your assigned platform and how recovery is controlled. Do not infer availability from another product under the same brand.
Use incidents as a process question
Ask how the provider detects, assesses and communicates incidents affecting your services or data. Review notification triggers, contact channels, cooperation expectations and what information you can receive. Avoid reducing the conversation to “Have you ever had a breach?” A yes or no without scope and context is a poor account of operational readiness.
The provider’s contractual notification commitment and the employer’s legal obligations may not be identical. Have appropriate legal and privacy reviewers assess that relationship. This publication does not supply a universal reporting deadline or decide whether a particular incident is legally notifiable.
Make uncertainty visible to the decision-maker
Summarize each material question as evidenced, partly evidenced or unresolved. Identify who reviewed it and what decision depends on it. If a report is unavailable, record the explanation and proposed alternative evidence; do not describe the missing report as clean.
For example, a fictional review might find that the core processing service is within scope but an optional integration is not clearly addressed. The next action is to understand that integration’s data flow and evidence, or reconsider whether it belongs in the initial scope. A broad green vendor score would hide the actual decision.
Revisit evidence when the relationship changes
Use renewal, new services, new integrations, material incidents and platform changes as review triggers. Keep a dated evidence index and update the employer controls as well as the provider documents. Security diligence is incomplete if last year’s report is current but this year’s administrator list is not.
Continue with the capability-based access review and incident tabletop. Both turn the evidence request into operating work the organization can actually perform.
Map one real data flow on paper
Before approving an optional integration, draw where the data originates, which service receives it, what fields are sent, why they are needed and where results return. Use field categories rather than actual employee values. Include the employer’s own export folder or integration service if it is part of the flow.
Then place the evidence beside each boundary. Which organization operates that component? Which agreement governs it? Which security review covers it? Where does the provider’s responsibility end? The exercise can reveal that a well-reviewed core service is connected to an employer-managed process that has not been assessed.
Reduce the flow to the minimum justified scope before adding controls around unnecessary data. A nightly file containing every employee field may be convenient, but convenience alone does not explain why each recipient needs every field. The responsible privacy and security owners should assess the actual proposed transfer. This publication does not authorize it or collect a sample.