Right-to-Audit Clause
Definition
A contractual provision that gives the organisation the right to audit or assess the vendor's security controls, either directly or through a third-party assessor, during the term of the contract. This clause is required by many regulatory frameworks including PCI-DSS and is considered a baseline expectation in ISO 27001 supplier agreements.
- Purpose
- Contractual right to audit vendor security controls
- Audit route
- Directly or via a third-party assessor
- Required by
- PCI-DSS and similar frameworks
- Standard reference
- Baseline expectation in ISO 27001 supplier agreements
Common questions
What typically triggers invoking a right-to-audit clause?+
A security incident involving the vendor, a scheduled periodic review, a significant change in the vendor's environment, or a regulatory requirement can all trigger the organisation exercising its audit rights under the clause.
Does a right-to-audit clause guarantee the audit actually happens?+
No, having the contractual right does not by itself verify security posture; the organisation must still schedule, resource and follow through on the audit, which is why many programmes track audit completion as a separate compliance metric.
Related terms
- Due Diligence Questionnaire (DDQ)
- A structured questionnaire sent to a prospective vendor before onboarding, asking the vendor to describe its security controls, certifications, incident history, subprocessor...
- Offboarding Controls
- The set of actions taken when a vendor relationship ends: revoking access credentials, recovering or destroying shared data, terminating network connectivity, and...
- Subprocessor
- A third party engaged by a vendor (the processor) to perform part of the service that involves the organisation's data. Under GDPR...
- Third-Party Risk
- The information security, operational, legal, or reputational risk introduced to an organisation by its relationships with external parties including vendors, suppliers, cloud...
- Vendor Tiering
- The classification of vendors into risk tiers, typically Tier 1 (critical), Tier 2 (significant), and Tier 3 (low), based on factors such...