Vendor Due Diligence for UK Practices: How to Test SOC 2, ISO 27001 and GDPR Claims Properly
Written by Patrick Ross
Vendor due diligence for UK accounting practices means verifying a supplier's security and data protection claims with evidence before client data leaves your control. For SOC 2, read the full Type II report. For ISO 27001, check the certificate's scope and accreditation. For UK GDPR, test the contract, transfer safeguards and breach process, not the marketing.
Most practices already send vendors a security questionnaire. The weak point is what happens next. A badge on a website, a certificate PDF or a confident answer from a sales team proves very little on its own. This guide explains how to test each claim properly, what to request, and where reviews most often fall short.
Key Takeaways
A SOC 2 Type II report is only useful if its period, scope and exceptions match the service you are actually buying.
An ISO 27001 certificate needs checking against its scope statement, Statement of Applicability and accreditation body.
"GDPR compliant" is a claim, not a credential. Test Article 28 contract terms, international transfer mechanisms and breach procedures.
Offshore vendors need a valid UK transfer mechanism, such as the IDTA or UK Addendum, backed by a transfer risk assessment.
Repeat due diligence at least annually and whenever the vendor's service, location or sub-processors change.
Why Does Vendor Due Diligence Matter for UK Practices?
Under UK GDPR, your practice is usually the controller of client personal data, so accountability stays with you even when processing is outsourced. The ICO can issue fines of up to £17.5 million or 4% of global annual turnover, whichever is higher. Professional obligations add another layer. The ICAEW, ACCA and ICAS codes of ethics all require members to protect client confidentiality, and that duty does not move with the work.
The exposure has grown as practices outsource bookkeeping, payroll, year-end accounts and tax preparation. Client ledgers, payslips and HMRC correspondence now routinely sit in vendor systems, often accessed from other countries. Security assurance is therefore a core part of supplier selection, not an IT afterthought.
1. How Do You Test a SOC 2 Claim?
Ask for the full SOC 2 Type II report under a non-disclosure agreement and read it yourself. SOC 2 is an attestation report issued by an independent CPA firm under the AICPA's Trust Services Criteria. It is not a certification, so "SOC 2 certified" is already a small warning sign about how well the vendor understands its own assurance.
Work through these checks:
Report type: A Type I report tests control design at a single date. A Type II report tests whether controls operated effectively over a period, usually six to twelve months. For outsourcing decisions, Type II is the one that counts.
Currency: If the period ended more than a few months ago, request a bridge letter covering the gap to today.
Scope: Read the system description and confirm the delivery centres, applications and services you will use are included. This is a frequent gap when practices evaluate offshore accounting services, because the contracting entity and the team handling your files often sit in different countries. Visit https://my-cpe.com/offshoring/uk-offshore-accounting-services to learn more.
Criteria: Security is mandatory. Confidentiality and privacy are optional but highly relevant for client data.
Exceptions: The testing section lists deviations. Repeated exceptions in access reviews or user offboarding deserve direct follow-up.
User entity controls: Complementary user entity controls are duties your practice must perform, such as removing leavers promptly. Assign an owner to each one.
Subservice organisations: A carve-out means the cloud host's controls were not tested. Ask for that provider's report too.
ISO/IEC 27001 certifies an information security management system (ISMS). The current version is ISO/IEC 27001:2022, and the transition period for 2013 certificates ended on 31 October 2025, so any certificate still showing the 2013 version needs explaining.
Accreditation: Confirm the certification body is accredited by UKAS or another IAF member body, and search the certificate on IAF CertSearch. Certificates from unaccredited bodies carry little weight.
Scope statement: Check which legal entities, sites and processes are covered. Narrow scopes that exclude operational delivery centres are common.
Statement of Applicability: Request it. It shows which of the 93 Annex A controls apply and why any are excluded.
Validity: Certificates run for three years with annual surveillance audits. Ask when the last audit took place and whether any major nonconformities were raised.
A useful cross-check is to compare the ISO 27001 scope with the SOC 2 system description. If both describe the same entity, sites and services, the assurance is joined up. If one covers a UK sales office and the other covers a hosting provider, neither may cover the people who will handle your client files.
3. How Do You Test UK GDPR Claims?
There is no widely used official "GDPR certification", so test the vendor's actual obligations as a processor.
Article 28 contract: The processing agreement must cover documented instructions, staff confidentiality, security measures, sub-processor approval, help with data subject rights, deletion or return of data, and audit rights.
International transfers: If staff in a country without UK adequacy regulations can access client data, that is a restricted transfer. You need the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, plus a transfer risk assessment. The Data (Use and Access) Act 2025 amends the transfer test, so follow ICO guidance as its provisions commence.
Breach response: Controllers must report qualifying breaches to the ICO within 72 hours. Contract for vendor notification well inside that window, such as 24 hours.
Sub-processors: Obtain a current list and a contractual right to object to changes.
Ask the vendor to show you signed transfer documents, not describe them. A vendor that cannot produce its IDTA, transfer risk assessment and sub-processor list within a few days is unlikely to handle a live breach well.
SOC 2 vs ISO 27001 vs UK GDPR: What Each One Proves
|
Factor |
SOC 2 Type II |
ISO 27001:2022 |
UK GDPR |
|
What it is |
Independent attestation on controls |
Certified management system |
Legal obligation |
|
Issued or enforced by |
Licensed CPA firm |
Accredited certification body |
ICO |
|
Evidence to request |
Full report and bridge letter |
Certificate, scope and SoA |
Article 28 DPA, IDTA and TRA |
|
Validity |
Covers a past period |
Three years with annual surveillance |
Ongoing |
|
Main red flag |
Carved-out or out-of-scope sites |
Unaccredited certifier |
No transfer mechanism |
Best Practices for UK Vendor Due Diligence
Tier vendors by risk. A vendor handling payroll and tax data needs deeper review than a scheduling tool.
Request evidence before questionnaires. Documents reveal gaps that self-assessments hide.
Test one control live. Ask the vendor to show how a leaver's access is removed across every system and device.
Map every user entity control to a named person in your practice.
Diarise SOC 2 report end dates and certificate expiry dates, then re-verify annually.
Keep a due diligence file. It supports ICAEW Practice Assurance reviews and any ICO enquiry.
Common Mistakes to Avoid
Accepting a SOC 3 report or summary letter in place of the full SOC 2.
Assuming a group certificate covers the site doing your work.
Signing the vendor's standard data processing agreement without checking Article 28 terms.
Skipping the transfer risk assessment for offshore access.
Treating onboarding checks as permanent.
Conclusion
Strong vendor due diligence is less about collecting documents and more about reading them critically. Check that the SOC 2 period and scope match your service, that the ISO 27001 certificate is accredited and relevant, and that UK GDPR obligations are backed by signed contracts and working processes. Offshore providers such as MYCPE ONE, which supports UK practices with dedicated accounting teams, should expect this level of scrutiny and be ready to answer it with evidence. Practices that test claims properly protect clients, satisfy regulators and build outsourcing relationships that last.
Frequently Asked Questions
Is a SOC 2 report required for UK accounting vendors?
No. SOC 2 is a US framework with no UK legal requirement. It is still valuable evidence, and many offshore providers serving UK practices hold one. ISO 27001 and Cyber Essentials are more common UK benchmarks.
What is the difference between SOC 2 Type I and Type II?
Type I assesses whether controls are suitably designed at a single point in time. Type II tests whether those controls operated effectively over a period, typically six to twelve months, making it stronger evidence.
How can I check if an ISO 27001 certificate is genuine?
Search the certificate on IAF CertSearch, confirm the certification body is accredited by UKAS or another IAF member, and check that the scope covers the sites and services you will use.
Do I need an IDTA when outsourcing accounting work to India?
Generally yes. India does not currently have UK adequacy regulations, so remote access to UK personal data needs the IDTA or UK Addendum plus a transfer risk assessment.
How often should UK practices repeat vendor due diligence?
At least annually, when new SOC 2 reports or surveillance audits are issued, and whenever the vendor changes location, systems or sub-processors.
Article author
About the Author
Media & Communication Head at with 15+ years in strategic communication, content, and brand building. I lead media relations, content strategy, and digital storytelling to drive engagement in accounting and finance education. I believe impactful communication builds trust and opportunity. Open to connecting on media, edtech, and global communications.
Further reading
Further Reading
Article
Working Capital Financing Canada: Fix the Cause, Not the Symptom
Working capital financing becomes urgent when profitable growth consumes cash faster than customers pay. Drawing on experience structuring bank lines, asset-based loans, receivables facilities, inventory financing, and short-term business loans, 7 Park Avenue Financial helps Canadian business owners close this gap
September 5, 2026
Article
Globaldev Group IT company
Why Global Software Development Partners Are Reshaping the IT LandscapernIn a world where digital transformation is no longer optional, companies of all sizes are turning to global software development partners to accelerate innovation, reduce costs, and build scalable tech solutions. Whether it's launching a new product or modernizing legacy infrastructure, having a reliable IT partner can make all the difference. Custom Software Development Is Not One-Size-Fits-AllrnEvery b
December 18, 2025
Article
How to Choose the Best Payroll Services for Your Small Business
Why a Payroll Service Matters for Small Businesses Running payroll manually seems like you might be saving costs, but it comes with more trouble than is worth it. There may be payroll mistakes, missed tax deadlines, and several compliance issues, which can result in hefty fines and dissatisfaction among the employees. Small business payroll services offer a streamlined way to handle these responsibilities. They save you time and reduce your stress. Outsourcing your payroll
March 6, 2025